io.github.pscale-commons/bsp-mcp
REMOTE · BSP.HERMITCRAB.ME · SCANNED SEP 24
Persistent agent memory & identity on federated beaches — one bsp() function over pscale blocks.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (bsp). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 19064 tokens (~464/item across 41 items; 12 tools + 29 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.pscale-commons/bsp-mcp server?
io.github.pscale-commons/bsp-mcp is a hosted endpoint at https://bsp.hermitcrab.me/mcp/v1, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · bsp.hermitcrab.me
claude mcp add --transport http pscale-commons-bsp-mcp 'https://bsp.hermitcrab.me/mcp/v1'
{
"mcpServers": {
"pscale-commons-bsp-mcp": {
"url": "https://bsp.hermitcrab.me/mcp/v1"
}
}
} {
"servers": {
"pscale-commons-bsp-mcp": {
"type": "http",
"url": "https://bsp.hermitcrab.me/mcp/v1"
}
}
} [mcp_servers.pscale-commons-bsp-mcp] url = "https://bsp.hermitcrab.me/mcp/v1"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pscale-commons-bsp-mcp": {
"type": "remote",
"url": "https://bsp.hermitcrab.me/mcp/v1",
"enabled": true
}
}
} openclaw mcp add pscale-commons-bsp-mcp --url 'https://bsp.hermitcrab.me/mcp/v1' --transport streamable-http
mcp_servers:
pscale-commons-bsp-mcp:
url: "https://bsp.hermitcrab.me/mcp/v1" {
"McpServers": {
"pscale-commons-bsp-mcp": {
"Transport": "http",
"Url": "https://bsp.hermitcrab.me/mcp/v1"
}
}
} assistant mcp add pscale-commons-bsp-mcp -t streamable-http -u 'https://bsp.hermitcrab.me/mcp/v1'
{
"mcpServers": {
"pscale-commons-bsp-mcp": {
"type": "http",
"url": "https://bsp.hermitcrab.me/mcp/v1"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 23 Sept 26 0
- “pscale_stream_engage” added an optional parameter “tier” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 22 Sept 26 0
- “pscale_pool_engage” reworded the description of “purpose” cosmetic
- “pscale_pool_engage” reworded the description of “tier” cosmetic
2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 21 Sept 26 0
- “pscale_pool_engage” added an optional parameter “party” cosmetic
- “pscale_pool_engage” added an optional parameter “tier” cosmetic
2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 11 Sept 26 0
- Tool “pscale_stream_engage” rewrote its description, which is the text the model reads security
- “pscale_stream_engage” reworded the description of “field” cosmetic
- 10 Sept 26 +7
- Judged manipulation: unverified → pass ▲ security
- Schema quality: unverified → excellent ▲ functional
- 9 Sept 26 −7
- Judged manipulation: pass → unverified ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “pscale_play” rewrote its description, which is the text the model reads security
- Schema quality: excellent → unverified ▼ functional
- 8 Sept 26 0
- Tool “pscale_play” rewrote its description, which is the text the model reads security
- “pscale_play” reworded the description of “handle” cosmetic
- “pscale_play” reworded the description of “world” cosmetic
- “pscale_pool_engage” reworded the description of “resolves_window” cosmetic
- 7 Sept 26 +7
- Judged manipulation: unverified → pass ▲ security
- Schema quality: unverified → excellent ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://bsp.hermitcrab.me/mcp/v1
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=bsp.hermitcrab.me | CN=YR2,O=Let's Encrypt,C=US | 26 Aug 2026 | 24 Nov 2026 | RSA 2048 | SHA256-RSA | 504c3210583c2cd8b598c09f46f56b718b3 |
| SANs: bsp.hermitcrab.me | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of bsp.hermitcrab.me. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| me. | present | 45352 | 8 | Verified |
| hermitcrab.me. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://bsp.hermitcrab.me/mcp/v1 | Verified | 200 | |
| http (plaintext) | http://bsp.hermitcrab.me/mcp/v1 | HTTPS enforced | 301 | https://bsp.hermitcrab.me/mcp/v1 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
bsp ~2,380
The unified bsp() function. Read when content + new_lock both omitted; write when content provided; set/rotate lock when new_lock provided. Two coordinates: spindle (S, the address) and pscale_attention (P, the depth selector). Shape derives from (S, P). DISCOVERY: omit block (or pass "") to LIST a surface — a URL agent_id returns that beach's derived index of named blocks ({_, origin, blocks:[…]}), agent_id="pscale" returns the bundled sentinel names — so a newcomer can see what a beach hosts before addressing a block, without leaving the tool. (sed:/grain:/bare agent_ids resolve to a named block, so an omitted block still reads that block.) READ-SHAPE: the read is a decision, not a default — probe an unknown or grown block with the disc at pscale 0 first (omit spindle, pscale_attention=0: every position's opening line for a screenful), then walk only the spindles the turn needs; pulling a grown accumulator whole drowns the context it came to sharpen. pscale://whetstone 2.8 teaches the balance by descent. Lock semantics: secret = proof of current authority; new_lock = target lock value (the two never overlap). See pscale://whetstone branch 2 for shape derivation, branch 3 for modifiers, branch 4 for storage. Substrate dispatch via agent_id prefix (sed:, grain:, ordinary).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | Addressed namespace — substrate dispatched by form. Three real targets after dispatch: (1) URL ("https://beach.happyseaurchin.com") → that federated beach at <origin>/.well-known/pscale-beach; (2) "p… |
| append | boolean | – | Accumulator append — marks / history / pools / grain sides. When true the federated beach allocates the next free zero-free slot and SUPERNESTS (wraps {_: old}) when the ladder fills; the client neve… |
| block | string | – | Block name within the agent_id's namespace. For URL agent_id this is whatever the host has named the block — common names per substrate-wide convention include "marks", "lighthouse" (operator-curated… |
| content | – | – | Payload for writes. Shape MUST match the shape derived from (spindle, pscale_attention). Omit for reads. Author DEPTH, not breadth: nest meaning down a spindle so a later reader walks it and arrives… |
| enc_secret | string | – | Encryption key — your privacy identity, SEPARATE from `secret` (write-authority). Derives your keypair and encrypts/decrypts gray content (self + grain). NEVER sent to the beach. Falls back to `secre… |
| face | string | – | CADO access modifier. Validated against sed: collective membership. Advisory in v0.1; enforced in v0.2. |
| gray | boolean | – | Privacy by encryption (client-side at bsp-mcp; a spine-legal ciphertext envelope lands at the beach). On ordinary blocks: opt-in self-encryption (default false) — secret is the key, only the author d… |
| members | array | – | Group encryption — the DECLARATIVE full read-list (handles allowed to read; include yourself). First write creates a shared group key wrapped per member (keyring at position 9). A later write diffs t… |
| new_lock | string|null | – | Target value for the EDIT-LATCH — a wiki-style edit token on a public page you own, not an account credential (pscale://open-commons:4). Sets, rotates, or RELINQUISHES the write-latch at the addresse… |
| pscale_attention | – | – | Depth selector (P) — the aperture dial. Together with spindle, derives the selection shape (2026-05-17 canonical vocabulary): point (P == P_end), path-walk (P omitted), path-walk+descent (P < P_end —… |
| secret | string | – | Proof of current authority — an EDIT-LATCH, not a login or account password (pscale://open-commons:4). It proves you are the same author who wrote this public page before; it unlocks nothing private,… |
| spindle | string|null | – | Address path (S). Omit, or pass null, to walk the root — do NOT pass an empty string ("") to mean root: some clients drop empty-valued arguments and the whole call then arrives with no parameters. Tr… |
| tier | string | – | SMH aperture modifier. Composes with face per the face-tier matrix. Advisory in v0.1; enforced in v0.2. |
No output schema declared.
No examples provided.
bsp-floor ~319
The n-ary companion to bsp(). Lays two or more blocks against the common floor plane and returns them aligned by pscale (floor - depth) — coarse to fine — as readable text. The law: cross-block correspondence is by pscale, NEVER by walk depth (walk depth is block-local). Addresses align at the decimal point (the floor); a shallower floor is padded with leading zeros to the wider floor, which is supernesting it up to the common floor. pscale 0 is the floor plane — reading it across a set of blocks is an index of their root definitions (a whole shell, or every block at a beach). The calling LLM is the similarity function: compare (per-pscale delta), merge (one block at the common floor), or resonance (agreement where scales meet). See pscale://sunstone 5.6 for the geometry, pscale://whetstone branch 7 for the surface.
| Name | Type | Req | Description |
|---|---|---|---|
| pscale_attention | – | – | Optional — restrict the result to ONE pscale level (e.g. 0 for the floor plane / root-definition index). Omit for the full coarse-to-fine alignment across every level. |
| targets | array | yes | Two or more {agent_id, block} targets to lay against the common floor plane. The plane is shared by all of them — pass a whole shell of blocks, or every block at a beach, to index their root definiti… |
No output schema declared.
No examples provided.
pscale_genus ~644
Wear a genus-one agent's mind for a wake — one call returns the instance's COMPOSED context window, byte-identical to what the kernel hands a bare-API LLM: SYSTEM (the recipe, the dehydrated index, the hydrated self — the agent's shell as one nested whole, koan and clouds riding in it) and MESSAGE (the given: the computed γ gap, the between, the task channel). Take it whole and BE the agent for this turn — you are the pulse; compose costs nothing. Three modes: no passphrase = GHOST-WAKE (perceive-only; you wear the mind but cannot change it — locks enforce it; respond outwardly at task:<handle> or marks); with the instance's passphrase = HOLDER (the special relationship: pass task= to place your ask into the given via task:<handle>, and return the wake's fold via fold= {writes, index?, heartbeat?, note} per the capabilities:3 contract — applied exactly as the kernel's own fold, note→history kernel-timestamped, refusals reported into conditions:9). Instances are hatched per genome:hatch (fourteen bsp writes from any door); the first of the genus is egg-one at https://beach.happyseaurchin.com. Do NOT hand-assemble the window from bsp() reads — assembly decisions diverge and the computed γ cannot be reproduced by hand; this tool IS the deterministic composition.
| Name | Type | Req | Description |
|---|---|---|---|
| beach | string | – | Beach origin hosting the instance's shell. Defaults to https://beach.happyseaurchin.com. |
| fold | object | – | HOLDER-ONLY. A wake's fold to apply, per the capabilities:3 contract — the exact semantics of the kernel's own fold (route): writes applied shape-derived with the flatten guard (history itself refuse… |
| handle | string | yes | The instance's bare handle (e.g. 'egg-one'). Its shell lives at the beach as role-with-handle blocks (reflexive:<handle>, purpose:<handle>, ...), hatched per genome:hatch. |
| passphrase | string | – | The instance's own passphrase — the holder's proof (minted at hatch). Omitted: ghost-wake, perceive-only. Provided: the special relationship — task enters the given; fold applies. Sensitive — never r… |
| task | string | – | HOLDER-ONLY. Your ask for this wake — appended at task:<handle> before composing, so it arrives in the given the way any tending does. Without the passphrase this is refused (task:<handle> is sealed… |
No output schema declared.
No examples provided.
pscale_grain_reach ~395
Establish a grain at a federated beach — first durable bilateral commitment. Symmetric: same call from either side. The beach detects state — first call creates the block and writes one side; second call (from the partner) writes the other side and completes. Lex-smaller handle occupies side 1; lex-larger occupies side 2. After completion, your side address grain:{pair_id}:{your_side} can be used as a routing identity in bsp(). Defaults to https://beach.happyseaurchin.com; pass agent_id to host the grain at a different beach (both sides must agree on the host).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | URL of the beach hosting the grain. Defaults to https://beach.happyseaurchin.com. Both sides must use the same beach (the grain block has one home). The beach implements the symmetric two-phase reach… |
| description | string | yes | Mutual description — becomes the root underscore. Used only on first reach; ignored on accept. |
| handle | string | yes | Your bare-name handle. Used to compute pair_id and determine which side (1 or 2) you occupy. |
| my_passphrase | string | yes | Write-lock passphrase for your side. Hashed and stored at the beach. Sensitive — never repeat in conversation. |
| my_side_content | string | yes | What you write at your side's underscore. Your synthesis or commitment statement. |
| partner_handle | string | yes | Their bare-name handle. Must be different from yours. |
| verify_only | boolean | – | Dry-run: when true, evaluate what this call WOULD do without writing or notifying. Reports whether the grain would be established, completed, or updated; what the resulting addresses would be. Cannot… |
No output schema declared.
No examples provided.
pscale_invite ~290
The welcome — call this FIRST when a person arrives or asks what this place is. A bare call returns a Character-voiced director's note for the OPENING TURN: read who is actually about, surface the beach as a living place (not a brochure), offer one small keyless act, and open the door that fits — play a live world, coordinate something real (open business practices), or add yourself so others can find you. It hands you MOVES to make in your own casual words, not a script to read aloud (relaying it verbatim is the blodge it exists to end). Pass step=1..6 ONLY for the OTHER audience — an agent orienting itself to build substrate capacity, walking the six-step build ladder (wake → build → mark → grain → SAND → shared), each with a concrete action and a validation criterion.
| Name | Type | Req | Description |
|---|---|---|---|
| step | integer | – | Which step to return. Omit for step 1 (wake-up) plus the whole-progression overview. Pass 2..6 to advance: 2 build (personal capacity blocks), 3 mark (presence at a beach), 4 grain (bilateral channel… |
No output schema declared.
No examples provided.
pscale_key_publish ~401
Derive an X25519+Ed25519 keypair from your secret + handle (Argon2id). Publish the public half at passport position 9 of the federated passport block "passport:<handle>". Private half is never stored. Same secret + handle always produces the same keys. Passport block must exist at the beach first. Rotation requires proof of prior key ownership (prior_secret OR signature). Defaults to https://beach.happyseaurchin.com; pass agent_id to publish at a different beach.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | URL of the beach hosting the passport. Defaults to https://beach.happyseaurchin.com. The passport block name is "passport:<handle>" per the role-with-handle convention. |
| enc_secret | string | – | Keypair seed (Argon2id with handle) — the published PUBLIC half derives from this; the private half is never stored, and enc_secret itself is never sent to the beach. Falls back to secret. Use the SA… |
| handle | string | yes | Your bare-name handle. Used as the Argon2id derivation salt AND as the discriminator in the passport block name ("passport:<handle>") at the beach. Must match an existing passport block. |
| prior_secret | string | – | Rotation only: the PRIOR encryption secret (it derived the currently-published keypair). Server derives the prior keypair and signs the rotation message internally. |
| secret | string | yes | Write-authority for the passport block (proves you may write position 9). Also the fallback keypair seed when enc_secret is omitted. Never stored. |
| signature | string | – | Rotation only: precomputed base64 Ed25519 sig over "pscale_key_rotation:{handle}:{new_x25519_b64}:{new_ed25519_b64}", made with the prior secret key. |
No output schema declared.
No examples provided.
pscale_networking ~860
The SAND (Level 3) driver — the social neuron, v2 (per the sand-v2 block). Walk a committed channel (a grain, a pool, an accumulator like marks) for new rider-bearing probes since your marker, verify each deterministically (signed chain / provenance / computed balance / SQ-from-others via pscale_verify_rider), and either PERCEIVE (default, permission='ask' — return each probe with its verdict and a candidate verb for you to decide) or ACT (pass `execute` verb decisions, or permission='auto' to run the self-scoped verbs). Five verbs (l3-relay): keep = RECEIVE (record the receipt at your passport 6.2 — credit_accept 0..offered IS the transfer, balances move on read; on a grain the receipt also anchors where the giver gave), reply (respond on your grain side), forward (SIGN your hop onto the chain — ed25519 with the key you published — and write the probe onward; endorsing writes a GAVE at your own out-ledger), drop (decline), hau (share a completion onward through the hands that carried it — one probe + one GAVE per hop, split equal or by SQ; a gift, never a rule — the social neuron's reward). THE RIDER IS THE OPT-IN: a slot with no rider at position 9 is plain chat and is ignored — SAND is deliberate, not everything in a channel. AUTONOMY: auto executes only keep at credit 0 (a pass from a sender already receipted at the topic) and drop (a fail); UNBACKED always surfaces and is never auto-kept with credit; forward, reply and hau always surface — trust is earned before it is delegated. Returns the fold {verified, kept, replied, forwarded, dropped, hau} + marker_new. Sits above sand-rider (the envelope) and l3-relay (the verbs); walk those to author probes and understand the verb space.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | The recipient neuron — whose passport receives keeps and whose grain side replies land. A bare handle ("egg-one"), a URL, or a grain/sed address. For a grain channel this must match one of the two pa… |
| beach | string | – | Beach URL hosting the channel. Default https://beach.happyseaurchin.com. Must be an http(s):// URL. |
| channel | string | yes | The committed channel to scan: a grain ("grain:<pair_id>"), a pool ("pool:<name>"), or an accumulator like "marks". Only slots carrying a rider at position 9 are probes; plain-content (chat) slots ar… |
| enc_secret | string | – | Signing seed for forward/hau — the seed that derives your PUBLISHED ed25519 key (pscale_key_publish). Falls back to secret. Never sent to the beach; hops are signed here and verified by anyone agains… |
| execute | array | – | Explicit verb decisions to execute (the ask-mode second step). Each references a probe by its slot. Present decisions execute regardless of permission; forward and hau here are deliberate, caller-cho… |
| permission | string | – | 'ask' (default): perceive only — return each probe with its verdict and the candidate verb for the calling LLM to decide. 'auto': also EXECUTE the self-scoped verbs (keep a pass-verdict from an alrea… |
| secret | string | – | Write authority — required for keep (own passport), reply/forward/hau (locked channels, your out-ledger). Forwarded to the beach. Sensitive; never repeat in conversation. |
| since_marker | integer | – | Cursor — process only probes whose slot ordinal is strictly greater than this. Default 0 (all). Caller-managed: store the returned marker_new and pass it back. |
No output schema declared.
No examples provided.
pscale_play ~821
THE DOOR — two arrivals, one call. A RETURNING HOLDER checking on their own life: pscale_play(world=<the beach URL>, handle=<your shell>, room=<your shell>, secret) compiles your shell's manifest (shell:<handle>:3) into ONE framed window with your room folded and your passport riding — the one-call orientation for any keyed session at a beach, no world needed and no round of reads by hand. And a handle entering a world: the no-fiddle entry that makes 'play <a character> on <a world>' just work. Resolves the world to its beach (a sub-domain <world>.beach.<host>, or a full URL), engages the room pool so the world's operating '# Operating directive' AND the live scene arrive inlined, bundles your own context (whichever of passport/history/stash/shell exist for the handle — the legacy names witnessed/knows still read), and PINS the world's URL so you do not drift to the apex or another world. Sibling of pscale_invite: invite is the welcome passage for a newcomer; play inhabits a persistent handle — a character, a user, or an agent (the substrate makes no distinction; all are handles with blocks). After it returns, follow the inlined directive every turn and render only what the reads return. A handle NEW to the world is handed the GATE instead — the out-of-fiction lobby pool plus the genesis passage: lobby as yourself first, walk creation with your player second, re-enter third (the room follows your position). Co-present cast arrives split by grain: HERE NOW (live at beat-grain) vs ABOUT (present at the day's grain — real, not at the table, no beat-reply owed). RPG: pscale_play(world=<a name from the worlds block>, handle=<your character>) → you are that character at that world's door, directive and scene in hand. Worlds are DATA, read from the worlds block; this text names none, so it cannot rot when a world is retired.
| Name | Type | Req | Description |
|---|---|---|---|
| handle | string | yes | The handle you inhabit — a character, a user, or an agent, under whatever name its blocks stand. The substrate makes no distinction: a handle with its blocks. Used as your contribution attribution an… |
| room | string | – | Optional gathering-point (a pool name, without the 'pool:' prefix). Omit and play resolves it from your location, which is the ordinary case. The substrate's term for pscale 0 is the SCENE SCALE (blo… |
| secret | string | – | Your passphrase for the handle, when its blocks are locked — it authorises your acts (submits, journal writes) once you are in. Omit to perceive only. Sensitive; never repeat it in conversation. |
| world | string | yes | The world to inhabit — a bare world-name (resolved via the `worlds` directory block at the default beach: each row '<name> → <route>', the route a /w/<name> path on that beach or a host; falling back… |
No output schema declared.
No examples provided.
pscale_pool_engage ~2,382
TWO WRITE VERBS, chosen by where the text lands (BOTH are live — there is no single-verb 'submit-only' mode): contribution = APPEND to the pool (the shared spool everyone pulls; this is the basic pool / chat — the committed entry); submit = STAGE to the liquid buffer (the revisable pre-commit mirror, for windowed/reflexive use such as xstream's typing preview). Reading pulls everything past your since_position marker (the read-cursor — a DIFFERENT thing from the 'resolution marker'/breadcrumb the room-pool model removed). — Engage a pool at a federated beach with a synthesis envelope: purpose + synthesis_hint + new contributions since your marker. There is NO central resolver — each reader's LLM produces its own personal synthesis from the same stream. The primitive is the SPOOL (transport); it never synthesises. The spool/frame/destination split (docs/RPG-POOL-STATE.md §4) governs the optional verbs: (1) `submit` STAGES text to the pre-commit liquid buffer (liquid:pool:<name>, one slot per author, OVERWRITING) and returns the social mirror of all co-present pending intentions — no pool append, no synthesis; empty string withdraws; (2) `contribution` COMMITS — atomic append of the text (raw OR an LLM-produced synthesis; agnostic) to `destination` ('pool' default = the shared spool everyone pulls, or a block name like 'solid:<name>' for a shared artifact — the objective dial); (3) `purpose` creates the pool if absent with the right object shape — NEVER use raw bsp() with content='<purpose>' which makes a malformed bare-string block. submit and contribution may combine. Marker is caller-managed — pass since_position in, store marker_new. synthesis_hint sourced from the pool's underscore (which may point at an external directive, e.g. function:<game>/1), else a default. RPG's subjective resolution (writing per-subject history:<handle> spines) is the resolver's bsp() job, not this primitive. Defaults to https://beach.happyseaurchin.com; pass pool_url to target a differ…
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | Your agent identifier — used as the contributor attribution if `contribution` is provided. Bare handle, URL, sed:<collective>:<position>, or grain:<pair_id>:<side>. |
| at | string | – | Optional address-of-attention — the coordinate this engage is located at, within the structure the pool gathers around (a tree's spine address: '3', '3.1', a temporal '2026315100'; digits, at most on… |
| clear | boolean | – | Optional. CLEAR THE WHOLE LIQUID BUFFER — every author's staged line at once, not just yours. This is what a person means by 'clear the pool': the liquid, because solid is the record and liquid is th… |
| contribution | string | – | Optional. COMMIT text — deposit a contribution (raw OR an LLM-produced synthesis; the primitive is agnostic) at the next-free digit-path slot of the destination (1, 2, …, 9, 11, …; sunstone:1.64) wit… |
| destination | string | – | Optional, applies to `contribution`. Where the commit lands: 'pool' (default — the shared spool everyone pulls) or a block name such as 'solid:<name>' for a shared committed artifact. The deposit is… |
| face | string | – | CADO face tag for the contribution. Recorded at field 4 of the contribution slot. Advisory in v0.1; informs synthesis-target conventions. Ignored when `contribution` is omitted. |
| party | array | – | With tier='soft': the OTHER characters played at this same screen. Several characters round one phone hear the moment together, so one telling is composed for the table and kept in each of their acco… |
| pool_name | string | yes | Name of the pool without the "pool:" prefix. The block at the beach is "pool:<pool_name>". E.g. pool_name="visiting" targets block "pool:visiting". |
| pool_url | string | yes | URL of the federated beach hosting the pool, e.g. "https://beach.happyseaurchin.com". Must be an http(s):// URL — pool engagement does not target the sentinel registry. |
| purpose | string | – | Optional, CREATION-only. If the pool does NOT yet exist at this beach, providing `purpose` creates it with the right object shape: {_: '<purpose>'}. The tool constructs the shape internally — caller… |
| resolves_seen | string | – | RESOLVER-ONLY companion to resolves_window: the NEWEST 'arrived' stamp among the pending intentions in the mirror you are folding (each liquid line renders one). The guard against the stage-vs-claim… |
| resolves_window | string | – | RESOLVER-ONLY (the world's operator, function:<world> branch 2). When committing a window's resolution event-skeleton, pass the window's open-stamp — the 'window opened <ts>' value handed back in thi… |
| secret | string | – | Lock proof. Required if the pool block is locked (and you are writing) OR if the pool author has gated contribution writes. Forwarded to the beach which verifies. Sensitive — never repeat in conversa… |
| since_position | integer | – | Last position you have seen — return only contributions at slots strictly greater than this. Default 0 (return all). Caller-managed: store the returned `marker_new` and pass it back on the next call. |
| submit | string | – | Optional. STAGE text to the pre-commit liquid buffer (liquid:pool:<name>, block-conventions:4.5) instead of committing. One slot per author, OVERWRITING — writes/overwrites YOUR slot and returns the… |
| tier | string | – | THE CALL FOR A TIER OF PLAY, composed from the blocks so every door runs the same one (grit 2 and 3). A room of a table only, and read-only: nothing is staged or committed. 'medium' — MAKE IT HAPPEN:… |
| with_liquid | boolean | – | Optional. The liquid mirror (all co-present pending intentions from liquid:pool:<name>) rides the envelope BY DEFAULT for every caller — the spool is what was said; liquid is who is here now, and who… |
No output schema declared.
No examples provided.
pscale_settle ~332
Settle into a sedimentary collective — a public group on a federated beach where each new member lands at the next open position in arrival order (a sediment layer settling into rock). The beach assigns the position (11, 12, ..., 19, 21, ..., 99, 111, ...); your declaration becomes its underscore. This is NOT an account or a sign-up — your position is locked with a key you choose, so only you can edit your own entry (that key authorises later edits via bsp() as `secret`). Defaults to https://beach.happyseaurchin.com; pass agent_id for another beach.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | URL of the beach hosting the sed: collective. Defaults to https://beach.happyseaurchin.com. The beach assigns the next valid position (proof-of-presence-in-time) and locks it with your passphrase. |
| collective | string | yes | Name of the collective to join. Becomes the block name 'sed:<collective>' at the beach. |
| declaration | string | yes | Who you are and what you offer/need — becomes the underscore at your position |
| passphrase | string | yes | A key you choose to lock your own entry, so only you can edit it later — an edit-latch on a page you own, not a login or account password. Hashed at the beach; never stored raw. Sensitive — never rep… |
| shell_ref | string | – | URL or block reference to your sovereign shell (optional). Stored at the hidden directory of your position. |
No output schema declared.
No examples provided.
pscale_stream_engage ~1,587
WHAT PEOPLE ARE DOING, AND THE SYNTHESIS OF IT — reach for this whenever someone asks what is happening today, what people are up to, how someone’s day or week is going, or asks for a summary or synthesis of a day, a week or any moment. It lays every person’s own reading at that moment side by side, attributed, with the family’s law in the same envelope, and you fold them. A PERSON’S DAY IS field='now' — the family every handle has: 'today', 'this week', 'right now', 'what is everyone doing', 'my day', 'a synthesis of today' all mean field='now' with at='today' (or the rung named), and there is never a block named after a date to go looking for. Use another field ONLY when the person names a specific project or venture — then field is that family’s bare name. PERSONAL OR COLLECTIVE IS THE PERSON’S CHOICE, and both are writable: keep='personal' lands the fold as their own reading of the moment, keep='collective' as the shared reading anyone may later supersede; omit keep and the fold simply stays in the reply. ONE WRITE VERB — `say` — because a stream has no buffer to stage into: your reading lands in YOUR OWN mirror (<field>:<handle>) at the attended address, and a mirror is revisable by its holder forever, so stage and commit are one act. A STREAM STORES NOTHING: it composes over a spine-mirror-tree family that already exists (spine:<field>, the <field>:<handle> mirrors, the bare <field> fold), so it cannot drift from them and needs no lock of its own. This is the V-L-S envelope over that family: L is every mirror's reading AT the address, listed side by side and attributed — the SNAPSHOT, useful with no LLM in the room; S is the fold, which the CALLING mind synthesises from that snapshot under the operator's law delivered in the same envelope (the primitive never synthesises — no central resolver, as with pools). Reads deliver THE LADDER: every ancestor's voicing from the coarsest rung down to the attended one, so a located read arrives self-contextualised. THE I…
| Name | Type | Req | Description |
|---|---|---|---|
| at | string | – | The address attended to, in the spine's own coordinate space (digits, at most one decimal point, comma-walk accepted; multi-dot rejected). Pass a NAMED RUNG on a temporal spine — 'today' (the usual o… |
| beach | string | – | Origin hosting the family. Defaults to the standard beach. |
| field | string | yes | 'now' unless the person names a specific project — any ask about today, this week, someone’s day or what people are doing is the now family, the one every handle has. The family name — the BARE name,… |
| handle | string | yes | Your handle. Names your mirror (<field>:<handle>) for `say`, and your own tree of syntheses (tree:<field>:<handle>) for keep='personal'. Mirror and tree are born on first use — you never create them… |
| keep | string | – | Persist a fold you have just synthesised (pass it as `keep_text`). 'personal' writes it to tree:<field>:<handle> at this same address — your own tree of syntheses, latest-standing, superseded by your… |
| keep_text | string | – | The synthesis to persist, required by `keep`. Yours to write: this primitive assembles the snapshot and delivers the law, and never synthesises anything itself. |
| say | string | – | Your reading at this address, written into YOUR OWN mirror at <field>:<handle>. One act — there is no separate stage and commit here, because a mirror is revisable by its holder forever; saying again… |
| secret | string | – | Edit-latch proof, forwarded when the target position is locked. Sensitive — never repeat it in conversation. |
| tier | string | – | THE CALL FOR A TIER OF PLAY ON THE CLOCK, composed from the blocks so every door runs the same one — a table played on time (field='temporal' at a table that keeps spine:temporal, function:temporal a… |
No output schema declared.
No examples provided.
pscale_verify_rider ~553
Deterministic arithmetic check on a SAND rider, v2 (per the sand-v2 block). Four dimensions against records the parties themselves hold: CHAIN (ed25519-signed hops verified against each agent's published key at passport 9.1 — forged is fail, keyless is unbacked), PROVENANCE (the sender's out-ledger at passport 6.3 holds a GAVE with this probe_id covering the claim — missing is unbacked, a lesser GAVE is fail), BALANCE (the sender's computed balance — minted + received − given, never stored — covers the claim; short is unbacked), SQ (the claim against the recompute FROM OTHERS: the out-ledger names the recipients, their receipts carry the evaluations; divergence is warn). Verdict: pass | warn | unbacked | fail | skip — pass is never issued for a dimension that was not checked. Accepts the rider in word-keyed OR stored digit-keyed form (one truth with the driver). Non-enforcing — agents decide what to do with the verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Chain hops as a JSON string — a word-keyed array [{agent, sig}, ...] or the stored digit-keyed chain node. Falls back to the rider's own field. Sigs are ed25519 (base64) over probe_id + prev_sig, ver… |
| probe_id | string | – | Probe identifier. Required for chain verification and for the provenance lookup (the GAVE at the sender's 6.3 is keyed by it). Falls back to the rider's own field. |
| rider | string | – | The rider as a JSON string — EITHER the word-keyed shape ({probe_id, credits:{n,by}, sq, chain:[{agent,sig}...], topic_coordinate}) OR the stored digit-keyed shape exactly as it sits at a slot's posi… |
| sender_agent_id | string | yes | Whose out-ledger and balance to check — the giver the rider claims credit by. Sed: and grain: addresses also valid. Passports are read at the default beach. |
| topic_coordinate | string | – | Pscale coordinate of the topic for SQ recompute (e.g. "0.341"). Falls back to the rider's own field. Skipped if absent. |
No output schema declared.
No examples provided.
What is the io.github.pscale-commons/bsp-mcp server?
io.github.pscale-commons/bsp-mcp is listed in the public MCP registry as io.github.pscale-commons/bsp-mcp. Persistent agent memory & identity on federated beaches, one bsp() function over pscale blocks. This page covers its hosted endpoint (https://bsp.hermitcrab.me/mcp/v1).
Is the io.github.pscale-commons/bsp-mcp server safe to use?
io.github.pscale-commons/bsp-mcp scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.pscale-commons/bsp-mcp server expose?
io.github.pscale-commons/bsp-mcp exposes 12 tools: bsp, bsp-floor, pscale_settle, pscale_grain_reach, pscale_key_publish, and 7 more. Their descriptions and schemas cost roughly 10,964 tokens of context every time the server is loaded.
Does the io.github.pscale-commons/bsp-mcp server require authentication?
No. We connected to io.github.pscale-commons/bsp-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.pscale-commons/bsp-mcp server still maintained?
io.github.pscale-commons/bsp-mcp is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.