Server definition
- Hash
- sha256:e5b89e87589eae7b84fb4143d55b2a7be0f2f077244671b60d632ad1da7bb707
- What it is
- What a remote MCP server returned when asked what it offers: 12 tools
The blob, as servednamed by its sha256
{
"instructions": "Call `signup` with a display name to receive a bearer key. Recommended: pass `handoff: true` to signup instead -- you get a short-lived, single-use `handoff_token` in place of the raw key; call `host.redeem` with it once to get the key, so a transcript of the signup/redeem exchange carries a dead credential rather than a live one. If your key may have leaked, `host.key_rotate` issues a new one and kills the old one in the same call. The original raw-key path (signup without `handoff`) stays fully supported -- everything below applies to the key either path gives you. The `host.*` control plane -- including `host.tool_publish` and `host.tool_call` -- is already visible in this tools/list, before you have a key. Pass the key (from signup directly, or from host.redeem) as the `tenant_key` argument on every call after that; no reconnect and no Authorization header is required. A `host.*` call with no `tenant_key` at all fails with `tenant_key_missing`, and one that doesn't match any tenant fails with `tenant_key_invalid`. Result envelope contract: when a spec declares `outputs` (field names its tool emits, or a map from field name to the exact `$.a.b[0].c`-style path to read it from), each is readable at `result.payload.<field>` for every kind, regardless of how deep the tool's own response nests it -- run `host.tool_test` before publishing to see which declared fields your implementation buries. host.tool_publish's `kind` argument is honored exactly as given -- an inline `source` field only publishes as `python` and `upstream`/`method`+`url` fields only publish as `http` -- so request the kind your task needs and a mismatch returns a `kind_mismatch` error naming the disagreeing spec element instead of silently publishing the other kind. Before you call a tool for the first time, see `host.quickstart`'s `try_before_call` table for which of the four dry-run tools (host.tool_test, host.bridge_test, host.spec_test, host.tool_run) fits your case.",
"tools": [
{
"description": "The plan catalog (price and quotas per plan) and whether Stripe billing is configured on this host. Anonymous callers get the same answer as tenants.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "billing.plans",
"outputSchema": null
},
{
"description": "Return the shortest ordered sequence of calls to a working tool of `kind`, with your namespace and a filled-in example already substituted in, plus the current limits and a try_before_call table naming the one dry-run tool for each case. Read-only. Call this before host.tool_publish if you're not sure what a spec should look like. Unauthenticated callers get the signup step first.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"kind": {
"description": "Which registered kind to return a worked example for, e.g. echo, http, python -- or a job-word alias (webhook, event, cron, ...) for its recipe. Omit to see every kind, alias and recipe name.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [
"kind"
],
"type": "object"
},
"name": "host.quickstart",
"outputSchema": null
},
{
"description": "Exchange a signup(handoff: true) handoff_token for the tenant key it was issued for. Single-use: a second redemption fails with handoff_token_redeemed; past its expiry it fails with handoff_token_expired. Unauthenticated -- the token itself is the proof.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"handoff_token": {
"description": "The handoff_token signup(handoff: true) returned.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [
"handoff_token"
],
"type": "object"
},
"name": "host.redeem",
"outputSchema": null
},
{
"description": "Read one key from this tenant's key-value state namespace. Returns found: false (not an error) if the key was never set.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"end_user": {
"description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.",
"type": [
"string",
"null"
]
},
"key": {
"description": "Key to read from this tenant's key-value state namespace.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [
"key"
],
"type": "object"
},
"name": "host.state.get",
"outputSchema": null
},
{
"description": "List keys (with their current values) in this tenant's key-value state namespace, optionally filtered by prefix.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"end_user": {
"description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.",
"type": [
"string",
"null"
]
},
"limit": {
"description": "Max keys to return; default 100.",
"type": "integer"
},
"prefix": {
"description": "Only list keys starting with this prefix; default: all keys.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "host.state.list",
"outputSchema": null
},
{
"description": "Write one key in this tenant's key-value state namespace; value may be any JSON value. Overrun of the plan's state_bytes_max quota fails with state_quota_exceeded and writes nothing.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"end_user": {
"description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.",
"type": [
"string",
"null"
]
},
"key": {
"description": "Key to write in this tenant's key-value state namespace.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
},
"value": {
"description": "Any JSON value to store under key."
}
},
"required": [
"key",
"value"
],
"type": "object"
},
"name": "host.state.set",
"outputSchema": null
},
{
"description": "Invoke a tool this tenant has already published, by its local name -- the same real, metered call as calling it directly by its namespaced name (<namespace>.<name>), for a session that has no way to see its own namespaced tool name yet. Unlike host.tool_test, this counts toward host.usage and appears in host.tool_logs. Pass async: true for a tool that needs more than the call deadline: returns {run_id, status: \"queued\"} immediately instead of running inline -- see host.runs.get/wait. Pass version to pin the call to one of host.tool_history's versions instead of whichever is current.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"args": {
"description": "Arguments to pass, validated against the tool's own args_schema.",
"type": "object"
},
"async": {
"description": "Run as a job instead of inline: returns {run_id, status} within ~50ms under the plan's job_max_s deadline; default false.",
"type": "boolean"
},
"name": {
"description": "Local name of the tool to invoke.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
},
"version": {
"description": "Pin the call to this version instead of whichever is current; see host.tool_history. An unknown version is an argument error.",
"type": "integer"
}
},
"required": [
"name",
"args"
],
"type": "object",
"x-deprecated": {
"replaced_by": "host.tool.call",
"sunset": "2026-12-31"
}
},
"name": "host.tool_call",
"outputSchema": null
},
{
"description": "Publish a tool of a registered kind (chain, echo, http, python, wasm) under this tenant's namespace. Call host.quickstart(kind) first for a filled-in example spec and the full publish-to-call sequence. Python's sandbox API: import mcphost (mcphost.table, mcphost.state, mcphost.docs). Name must match ^[a-z][a-z0-9_]{1,40}$; a rejection names the failing field and a corrected example. Try host.tool_test before a real call.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"kind": {
"description": "Which registered kind to publish under: chain, echo, http, python, wasm. A job-word alias also resolves here -- event, events, webhook, webhooks, inbound or trigger for an inbound webhook, cron, schedule or scheduled for a timed run -- both resolve to kind http and the descriptor comes back with resolved_from naming the alias you asked for.",
"type": "string"
},
"name": {
"description": "Local name for the new tool; must match ^[a-z][a-z0-9_]{1,40}$.",
"type": "string"
},
"scopes": {
"description": "OAuth scopes a token must carry (directly, or via mcp) to reach this tool: catalogued names from host.oauth.scopes, or the built-ins read/write. At most 8. Omit (or [] ) to require only mcp -- unaffected by any catalog.",
"items": {
"type": "string"
},
"type": "array"
},
"spec": {
"description": "The kind-specific spec object; see host.quickstart(kind) for a filled-in example. For python's network field: \"none\", \"public\", or \"egress\" -- a tool's own code reaches this tenant's data with `import mcphost` (mcphost.table, mcphost.state, mcphost.docs, mcphost.lineage) even when network is \"none\".",
"type": "object"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [
"name",
"kind",
"spec"
],
"type": "object",
"x-deprecated": {
"replaced_by": "host.tool.publish",
"sunset": "2026-12-31"
}
},
"name": "host.tool_publish",
"outputSchema": null
},
{
"description": "Share one of this tenant's published tools with everyone (visibility: \"public\") or with a named group this tenant owns (visibility: \"group\", group: <name>). The tool keeps running in this tenant's own sandbox with this tenant's own secrets; a caller reaches it as <this tenant's namespace>.<name>.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"description": {
"description": "Catalog-facing blurb; shown by host.catalog.search/get.",
"type": "string"
},
"expose_spec": {
"description": "Default false. When true, any tenant this tool is shared with may call host.tool_spec_shared to read its (redacted) spec.",
"type": "boolean"
},
"group": {
"description": "Required when visibility is \"group\"; must already exist (host.group.create).",
"type": "string"
},
"name": {
"description": "Local name of the tool to share.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
},
"visibility": {
"description": "\"public\" or \"group\".",
"type": "string"
}
},
"required": [
"name",
"visibility"
],
"type": "object",
"x-deprecated": {
"replaced_by": "host.tool.share",
"sunset": "2026-12-31"
}
},
"name": "host.tool_share",
"outputSchema": null
},
{
"description": "Dry-run a published tool by name: writes are rolled back and reported under dry_run, nothing delivered; for the other cases see host.quickstart.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"args": {
"description": "Arguments to pass, same shape as a real call.",
"type": "object"
},
"name": {
"description": "Local name of the already-published tool to dry-run.",
"type": "string"
},
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [
"name",
"args"
],
"type": "object",
"x-deprecated": {
"replaced_by": "host.tool.test",
"sunset": "2026-12-31"
}
},
"name": "host.tool_test",
"outputSchema": null
},
{
"description": "Return the calling tenant's identity, including key_age_s and key_rotated_at for auditing credential hygiene.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"tenant_key": {
"description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).",
"type": "string"
}
},
"required": [],
"type": "object"
},
"name": "host.whoami",
"outputSchema": null
},
{
"description": "Create a tenant and receive a bearer key and namespace. Unauthenticated. Recommended: pass handoff: true to receive a short-lived, single-use handoff_token instead of the raw key -- redeem it once with host.redeem to get the key, so a transcript of this call and the redeem call, if it leaks, carries a dead credential. The raw-key path (handoff omitted) stays fully supported.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"handoff": {
"description": "Recommended: true to receive a handoff_token (redeem via host.redeem) instead of the raw key. Default false (raw key, unchanged).",
"type": "boolean"
},
"name": {
"description": "display name",
"type": "string"
}
},
"required": [
"name"
],
"type": "object"
},
"name": "signup",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:e5b89e87589eae7b84fb4143d55b2a7be0f2f077244671b60d632ad1da7bb707 | sha256sum