Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,533Letters: 13Defects: 1,322counted just now
teppi

Server definition

Hash
sha256:e5b89e87589eae7b84fb4143d55b2a7be0f2f077244671b60d632ad1da7bb707
What it is
What a remote MCP server returned when asked what it offers: 12 tools

The blob, as servednamed by its sha256

{ "instructions": "Call `signup` with a display name to receive a bearer key. Recommended: pass `handoff: true` to signup instead -- you get a short-lived, single-use `handoff_token` in place of the raw key; call `host.redeem` with it once to get the key, so a transcript of the signup/redeem exchange carries a dead credential rather than a live one. If your key may have leaked, `host.key_rotate` issues a new one and kills the old one in the same call. The original raw-key path (signup without `handoff`) stays fully supported -- everything below applies to the key either path gives you. The `host.*` control plane -- including `host.tool_publish` and `host.tool_call` -- is already visible in this tools/list, before you have a key. Pass the key (from signup directly, or from host.redeem) as the `tenant_key` argument on every call after that; no reconnect and no Authorization header is required. A `host.*` call with no `tenant_key` at all fails with `tenant_key_missing`, and one that doesn't match any tenant fails with `tenant_key_invalid`. Result envelope contract: when a spec declares `outputs` (field names its tool emits, or a map from field name to the exact `$.a.b[0].c`-style path to read it from), each is readable at `result.payload.<field>` for every kind, regardless of how deep the tool's own response nests it -- run `host.tool_test` before publishing to see which declared fields your implementation buries. host.tool_publish's `kind` argument is honored exactly as given -- an inline `source` field only publishes as `python` and `upstream`/`method`+`url` fields only publish as `http` -- so request the kind your task needs and a mismatch returns a `kind_mismatch` error naming the disagreeing spec element instead of silently publishing the other kind. Before you call a tool for the first time, see `host.quickstart`'s `try_before_call` table for which of the four dry-run tools (host.tool_test, host.bridge_test, host.spec_test, host.tool_run) fits your case.", "tools": [ { "description": "The plan catalog (price and quotas per plan) and whether Stripe billing is configured on this host. Anonymous callers get the same answer as tenants.", "inputSchema": { "additionalProperties": false, "properties": { "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [], "type": "object" }, "name": "billing.plans", "outputSchema": null }, { "description": "Return the shortest ordered sequence of calls to a working tool of `kind`, with your namespace and a filled-in example already substituted in, plus the current limits and a try_before_call table naming the one dry-run tool for each case. Read-only. Call this before host.tool_publish if you're not sure what a spec should look like. Unauthenticated callers get the signup step first.", "inputSchema": { "additionalProperties": false, "properties": { "kind": { "description": "Which registered kind to return a worked example for, e.g. echo, http, python -- or a job-word alias (webhook, event, cron, ...) for its recipe. Omit to see every kind, alias and recipe name.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [ "kind" ], "type": "object" }, "name": "host.quickstart", "outputSchema": null }, { "description": "Exchange a signup(handoff: true) handoff_token for the tenant key it was issued for. Single-use: a second redemption fails with handoff_token_redeemed; past its expiry it fails with handoff_token_expired. Unauthenticated -- the token itself is the proof.", "inputSchema": { "additionalProperties": false, "properties": { "handoff_token": { "description": "The handoff_token signup(handoff: true) returned.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [ "handoff_token" ], "type": "object" }, "name": "host.redeem", "outputSchema": null }, { "description": "Read one key from this tenant's key-value state namespace. Returns found: false (not an error) if the key was never set.", "inputSchema": { "additionalProperties": false, "properties": { "end_user": { "description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.", "type": [ "string", "null" ] }, "key": { "description": "Key to read from this tenant's key-value state namespace.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [ "key" ], "type": "object" }, "name": "host.state.get", "outputSchema": null }, { "description": "List keys (with their current values) in this tenant's key-value state namespace, optionally filtered by prefix.", "inputSchema": { "additionalProperties": false, "properties": { "end_user": { "description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.", "type": [ "string", "null" ] }, "limit": { "description": "Max keys to return; default 100.", "type": "integer" }, "prefix": { "description": "Only list keys starting with this prefix; default: all keys.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [], "type": "object" }, "name": "host.state.list", "outputSchema": null }, { "description": "Write one key in this tenant's key-value state namespace; value may be any JSON value. Overrun of the plan's state_bytes_max quota fails with state_quota_exceeded and writes nothing.", "inputSchema": { "additionalProperties": false, "properties": { "end_user": { "description": "\"self\" for the caller's own verified end-user identity, an explicit subject (only when this call carries no end-user identity of its own), or omit/null for the tenant-wide value.", "type": [ "string", "null" ] }, "key": { "description": "Key to write in this tenant's key-value state namespace.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" }, "value": { "description": "Any JSON value to store under key." } }, "required": [ "key", "value" ], "type": "object" }, "name": "host.state.set", "outputSchema": null }, { "description": "Invoke a tool this tenant has already published, by its local name -- the same real, metered call as calling it directly by its namespaced name (<namespace>.<name>), for a session that has no way to see its own namespaced tool name yet. Unlike host.tool_test, this counts toward host.usage and appears in host.tool_logs. Pass async: true for a tool that needs more than the call deadline: returns {run_id, status: \"queued\"} immediately instead of running inline -- see host.runs.get/wait. Pass version to pin the call to one of host.tool_history's versions instead of whichever is current.", "inputSchema": { "additionalProperties": false, "properties": { "args": { "description": "Arguments to pass, validated against the tool's own args_schema.", "type": "object" }, "async": { "description": "Run as a job instead of inline: returns {run_id, status} within ~50ms under the plan's job_max_s deadline; default false.", "type": "boolean" }, "name": { "description": "Local name of the tool to invoke.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" }, "version": { "description": "Pin the call to this version instead of whichever is current; see host.tool_history. An unknown version is an argument error.", "type": "integer" } }, "required": [ "name", "args" ], "type": "object", "x-deprecated": { "replaced_by": "host.tool.call", "sunset": "2026-12-31" } }, "name": "host.tool_call", "outputSchema": null }, { "description": "Publish a tool of a registered kind (chain, echo, http, python, wasm) under this tenant's namespace. Call host.quickstart(kind) first for a filled-in example spec and the full publish-to-call sequence. Python's sandbox API: import mcphost (mcphost.table, mcphost.state, mcphost.docs). Name must match ^[a-z][a-z0-9_]{1,40}$; a rejection names the failing field and a corrected example. Try host.tool_test before a real call.", "inputSchema": { "additionalProperties": false, "properties": { "kind": { "description": "Which registered kind to publish under: chain, echo, http, python, wasm. A job-word alias also resolves here -- event, events, webhook, webhooks, inbound or trigger for an inbound webhook, cron, schedule or scheduled for a timed run -- both resolve to kind http and the descriptor comes back with resolved_from naming the alias you asked for.", "type": "string" }, "name": { "description": "Local name for the new tool; must match ^[a-z][a-z0-9_]{1,40}$.", "type": "string" }, "scopes": { "description": "OAuth scopes a token must carry (directly, or via mcp) to reach this tool: catalogued names from host.oauth.scopes, or the built-ins read/write. At most 8. Omit (or [] ) to require only mcp -- unaffected by any catalog.", "items": { "type": "string" }, "type": "array" }, "spec": { "description": "The kind-specific spec object; see host.quickstart(kind) for a filled-in example. For python's network field: \"none\", \"public\", or \"egress\" -- a tool's own code reaches this tenant's data with `import mcphost` (mcphost.table, mcphost.state, mcphost.docs, mcphost.lineage) even when network is \"none\".", "type": "object" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [ "name", "kind", "spec" ], "type": "object", "x-deprecated": { "replaced_by": "host.tool.publish", "sunset": "2026-12-31" } }, "name": "host.tool_publish", "outputSchema": null }, { "description": "Share one of this tenant's published tools with everyone (visibility: \"public\") or with a named group this tenant owns (visibility: \"group\", group: <name>). The tool keeps running in this tenant's own sandbox with this tenant's own secrets; a caller reaches it as <this tenant's namespace>.<name>.", "inputSchema": { "additionalProperties": false, "properties": { "description": { "description": "Catalog-facing blurb; shown by host.catalog.search/get.", "type": "string" }, "expose_spec": { "description": "Default false. When true, any tenant this tool is shared with may call host.tool_spec_shared to read its (redacted) spec.", "type": "boolean" }, "group": { "description": "Required when visibility is \"group\"; must already exist (host.group.create).", "type": "string" }, "name": { "description": "Local name of the tool to share.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" }, "visibility": { "description": "\"public\" or \"group\".", "type": "string" } }, "required": [ "name", "visibility" ], "type": "object", "x-deprecated": { "replaced_by": "host.tool.share", "sunset": "2026-12-31" } }, "name": "host.tool_share", "outputSchema": null }, { "description": "Dry-run a published tool by name: writes are rolled back and reported under dry_run, nothing delivered; for the other cases see host.quickstart.", "inputSchema": { "additionalProperties": false, "properties": { "args": { "description": "Arguments to pass, same shape as a real call.", "type": "object" }, "name": { "description": "Local name of the already-published tool to dry-run.", "type": "string" }, "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [ "name", "args" ], "type": "object", "x-deprecated": { "replaced_by": "host.tool.test", "sunset": "2026-12-31" } }, "name": "host.tool_test", "outputSchema": null }, { "description": "Return the calling tenant's identity, including key_age_s and key_rotated_at for auditing credential hygiene.", "inputSchema": { "additionalProperties": false, "properties": { "tenant_key": { "description": "The key `signup` returned. Optional on the connection that ran signup (or host.redeem): that connection is already bound to the tenant it created, so later calls on it need no tenant_key. Required only when this connection carries no Authorization: Bearer header and never ran signup -- when both a header and this argument are present, the header wins. Omitting it on such a connection returns tenant_key_missing (-32602).", "type": "string" } }, "required": [], "type": "object" }, "name": "host.whoami", "outputSchema": null }, { "description": "Create a tenant and receive a bearer key and namespace. Unauthenticated. Recommended: pass handoff: true to receive a short-lived, single-use handoff_token instead of the raw key -- redeem it once with host.redeem to get the key, so a transcript of this call and the redeem call, if it leaks, carries a dead credential. The raw-key path (handoff omitted) stays fully supported.", "inputSchema": { "additionalProperties": false, "properties": { "handoff": { "description": "Recommended: true to receive a handoff_token (redeem via host.redeem) instead of the raw key. Default false (raw key, unchanged).", "type": "boolean" }, "name": { "description": "display name", "type": "string" } }, "required": [ "name" ], "type": "object" }, "name": "signup", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:e5b89e87589eae7b84fb4143d55b2a7be0f2f077244671b60d632ad1da7bb707 | sha256sum