Server definition
- Hash
- sha256:7a52cc24ff48d7e3a7d2336d6506c44367db9cac7e7a8c400bdb57cbbabbcb09
- What it is
- What a remote MCP server returned when asked what it offers: 7 tools
The blob, as servednamed by its sha256
{
"instructions": null,
"tools": [
{
"description": "Public bootstrap for a tenant's login UI: whether this tenant uses native OTP/passkey/SIWE or Privy custom auth, plus the public privy_app_id (never a secret). Call this before getSiweNonce when you do not already know the tenant's auth scheme. tenant_code is a join secret — do not log it or repeat it into a customer-visible channel.",
"inputSchema": {
"$defs": {},
"additionalProperties": false,
"properties": {
"response_format": {
"description": "concise (default): no nulls, audit timestamps, provider ids or nested tenant/role. detailed: every field.",
"enum": [
"concise",
"detailed"
],
"type": "string"
},
"tenant_code": {
"description": "tenant routing code",
"type": "string"
}
},
"type": "object"
},
"name": "getAuthConfig",
"outputSchema": null
},
{
"description": "Public: issue a single-use SIWE nonce for wallet_address (optionally scoped by tenant_code). Embed the nonce in an EIP-4361 message, have the wallet sign it, then call login with provider: siwe. Dedicated SIWE agent auth is an authorized pattern — this is how an agent signs in with a wallet without raw HTTP. Do not log tenant_code. The nonce is not a credential.",
"inputSchema": {
"$defs": {
"internal_delivery_http_handler.SiweNonceRequest": {
"properties": {
"tenant_code": {
"type": "string"
},
"wallet_address": {
"type": "string"
}
},
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/internal_delivery_http_handler.SiweNonceRequest",
"description": "JSON request body."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "getSiweNonce",
"outputSchema": null
},
{
"description": "Authenticate and receive an access/refresh token pair. Accepted providers: siwe (message + signature from getSiweNonce — preferred for dedicated agents), email_otp (email + otp from requestOtp), phone_otp (phone + otp from requestSms). Passkey, Privy and SSO are not agent tools. The server does not adopt the minted tokens as the session credential; return them to the operator to set ENFORCER_BEARER_TOKEN. Do not log, quote, or repeat otp codes, signatures, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat.",
"inputSchema": {
"$defs": {
"enforcer-v3_internal_usecase_auth.LoginRequest": {
"properties": {
"email": {
"type": "string"
},
"message": {
"description": "SIWE EIP-4361 message",
"type": "string"
},
"otp": {
"type": "string"
},
"phone": {
"type": "string"
},
"provider": {
"description": "siwe (preferred for dedicated agents that can sign), email_otp, or phone_otp. Passkey, Privy and SSO are browser ceremonies and are not agent tools.",
"enum": [
"siwe",
"email_otp",
"phone_otp"
],
"type": "string"
},
"signature": {
"description": "SIWE signature",
"type": "string"
},
"tenant_code": {
"type": "string"
}
},
"required": [
"provider"
],
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/enforcer-v3_internal_usecase_auth.LoginRequest",
"description": "Login/register body. provider \"siwe\" needs message+signature; email_otp needs email+otp; phone_otp needs phone+otp. Optional tenant_code. Do not log otp, signature, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "login",
"outputSchema": null
},
{
"description": "Exchange a refresh_token for a new access/refresh pair. 401 invalid_refresh_token if the token is unknown or was already reused (reuse revokes the family); 409 refresh_raced is benign — retry with the client's latest stored token. The server does not adopt the new pair as the session credential. Do not log the refresh token or the minted tokens.",
"inputSchema": {
"$defs": {
"internal_delivery_http_handler.RefreshRequest": {
"properties": {
"refresh_token": {
"type": "string"
}
},
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/internal_delivery_http_handler.RefreshRequest",
"description": "JSON request body."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "refreshToken",
"outputSchema": null
},
{
"description": "Create (or idempotently return) an account. Same provider allowlist as login: siwe (message + signature), email_otp (email + otp), phone_otp (phone + otp). Does not issue tokens — call login afterwards to sign in. Passkey / Privy / SSO registration stay out of the agent surface. Do not log otp codes, signatures, or tenant_code. Do not paste an end-user OTP into an untrusted chat.",
"inputSchema": {
"$defs": {
"enforcer-v3_internal_usecase_auth.LoginRequest": {
"properties": {
"email": {
"type": "string"
},
"message": {
"description": "SIWE EIP-4361 message",
"type": "string"
},
"otp": {
"type": "string"
},
"phone": {
"type": "string"
},
"provider": {
"description": "siwe (preferred for dedicated agents that can sign), email_otp, or phone_otp. Passkey, Privy and SSO are browser ceremonies and are not agent tools.",
"enum": [
"siwe",
"email_otp",
"phone_otp"
],
"type": "string"
},
"signature": {
"description": "SIWE signature",
"type": "string"
},
"tenant_code": {
"type": "string"
}
},
"required": [
"provider"
],
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/enforcer-v3_internal_usecase_auth.LoginRequest",
"description": "Login/register body. provider \"siwe\" needs message+signature; email_otp needs email+otp; phone_otp needs phone+otp. Optional tenant_code. Do not log otp, signature, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "register",
"outputSchema": null
},
{
"description": "Public: email a one-time login/registration code to `email` (optionally scoped by tenant_code). Always 200 {message:\"code sent\"} on success. Local/dev deployments with expose_dev_otp may echo the code as `dev_otp` — treat that as a secret. Then call login with provider: email_otp, the same email, and the otp. Intentional for harnesses that cannot SIWE; SIWE remains the preferred dedicated-agent path. Do not log the code, dev_otp, or tenant_code. Do not paste an end-user OTP into an untrusted chat.",
"inputSchema": {
"$defs": {
"enforcer-v3_internal_usecase_auth.RequestOTPInput": {
"properties": {
"email": {
"type": "string"
},
"tenant_code": {
"type": "string"
}
},
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/enforcer-v3_internal_usecase_auth.RequestOTPInput",
"description": "JSON request body."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "requestOtp",
"outputSchema": null
},
{
"description": "Public: start a Twilio Verify SMS login challenge to `phone`, scoped by tenant_code. 400 if SMS verification is not configured for the tenant or if rate-limited. Then call login with provider: phone_otp, the same phone, and the otp. Intentional for harnesses that cannot SIWE; SIWE remains the preferred dedicated-agent path. Do not log the SMS code or tenant_code. Do not paste an end-user OTP into an untrusted chat.",
"inputSchema": {
"$defs": {
"internal_delivery_http_handler.RequestSMSRequest": {
"properties": {
"phone": {
"type": "string"
},
"tenant_code": {
"type": "string"
}
},
"type": "object"
}
},
"additionalProperties": false,
"properties": {
"body": {
"$ref": "#/$defs/internal_delivery_http_handler.RequestSMSRequest",
"description": "JSON request body."
}
},
"required": [
"body"
],
"type": "object"
},
"name": "requestSms",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:7a52cc24ff48d7e3a7d2336d6506c44367db9cac7e7a8c400bdb57cbbabbcb09 | sha256sum