Endpoints: 30,862MCP servers: 18,583Payout addresses: 2,106Paid calls: 1,607Letters: 14Defects: 1,351counted 4 min ago
teppi

Server definition

Hash
sha256:e687cc6dc06e28739e9970d2aeda85fa49059951f8d94f34286cc465b9caf945
What it is
What a remote MCP server returned when asked what it offers: 18 tools

The blob, as servednamed by its sha256

{ "instructions": null, "tools": [ { "description": "**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensures **`client_redirect_uri`** is allowlisted for **`app_id`** (same rules as `validate-redirect`).\n3. **Create vs renew:** If **`session_token`** is absent, **reuses the newest active session** for\n **`(workspace_name, Firebase UID, app_id)`** or **creates** one (`get-or-create`). Optional\n **`payload`** (URL-encoded JSON **object**, default `{}`) is stored **only on create** — ignored when\n reusing an existing session. If **`session_token`** is present (previous session JWT, may be expired),\n **renews** that session; **`payload`** must **not** be sent on the same request. Optional\n **`ttl_seconds`** applies to both paths (default **0** = unlimited; otherwise **60–604800**). When the\n Firebase token includes **`email`**, the server best-effort persists or backfills it on the workspace\n end-user row (audit display only).\n4. Responds with **`302 Found`** to `client_redirect_uri` with query params **`sessionToken`**\n and, if provided, **`state`**.\n\nIf **`client_redirect_uri`** is not allowed for **`app_id`**, responds **`400`** and does **not**\nredirect (open-redirect mitigation). Other failures return an HTTP error status with a JSON\n**`{\"status\", \"error\"}`** body and do **not** redirect.\n\nSource: GET /api/v1/auth/callback\nNo Authorization header is required.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": {}, "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": { "app_id": { "type": "string" }, "client_redirect_uri": { "format": "uri", "type": "string" }, "firebaseToken": { "type": "string" }, "payload": { "description": "JSON object as a string (e.g. `{\"a\":1}`), URL-encoded. Must parse to a JSON object (not an array or primitive).\nDefault when omitted is `{}`. Must not be combined with `session_token` on the same request.\n", "type": "string" }, "session_token": { "description": "Previous session JWT (may be expired); signature must validate. When present, the server renews this\nsession instead of creating a new one. Must not be combined with `payload` on the same request.\nURL-encode the value; very long URLs may exceed browser or proxy limits.\n", "type": "string" }, "state": { "type": "string" }, "ttl_seconds": { "description": "Session lifetime in seconds (default 0 = unlimited; allowed values: 0 or 60–604800)", "maximum": 604800, "minimum": 0, "type": "integer" }, "workspace_name": { "type": "string" } }, "required": [ "firebaseToken", "client_redirect_uri", "workspace_name", "app_id" ], "type": "object" } }, "required": [ "connection", "query" ], "type": "object" }, "name": "auth_session_callback", "outputSchema": null }, { "description": "Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": { "key": { "description": "Payload key to delete", "type": "string" } }, "required": [ "key" ], "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "params" ], "type": "object" }, "name": "delete_sessions_delete_key", "outputSchema": null }, { "description": "Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clear-Site-Data` is applied in a\n**first-party** context on `secure-flows.com`, making cookie/session clearing reliable even when\nthird-party cookies are blocked.\n\n**Critical client rules:**\n- Clear your in-app `sessionToken` state **before** navigating.\n- **Never** include `session_token` inside `redirect_uri` (that would silently renew and defeat logout).\n\nThis endpoint (best-effort / idempotent for browser UX):\n- Invalidates the provided `session_token` by incrementing `tokenRevision` when the token still\n matches an **active** session (no new token is issued).\n- If the session is already expired/revoked or the revision was superseded by renew, still\n completes logout UX (does **not** return 401 solely for that reason).\n- Revokes Firebase refresh tokens for the session’s stored Firebase UID when known.\n- Sets `Clear-Site-Data: \"cookies\"`.\n- Redirects the browser to `redirect_uri`.\n\nSource: GET /api/v1/auth/logout\nNo Authorization header is required.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": {}, "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": { "redirect_uri": { "description": "Where to redirect after logout completes", "format": "uri", "type": "string" }, "session_token": { "description": "SESSION JWT to invalidate (URL-encoded)", "type": "string" } }, "required": [ "session_token", "redirect_uri" ], "type": "object" } }, "required": [ "connection", "query" ], "type": "object" }, "name": "get_auth_logout", "outputSchema": null }, { "description": "Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1/docs/search\nNo Authorization header is required.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": {}, "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": { "limit": { "description": "Maximum hits to return (server caps at 20)", "maximum": 20, "minimum": 1, "type": "integer" }, "q": { "description": "Natural-language question or keywords", "type": "string" } }, "required": [ "q" ], "type": "object" } }, "required": [ "connection", "query" ], "type": "object" }, "name": "get_docs_search", "outputSchema": null }, { "description": "Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSource: GET /api/v1/sessions\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection" ], "type": "object" }, "name": "get_sessions", "outputSchema": null }, { "description": "Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSource: GET /api/v1/sessions/get/{key}\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": { "key": { "description": "Payload key to read", "type": "string" } }, "required": [ "key" ], "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "params" ], "type": "object" }, "name": "get_sessions_get_key", "outputSchema": null }, { "description": "Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a stable, opaque identifier for this person across sessions and logins — it is\n**not** derived from Firebase. Use it as the correlation key when your own backend needs to\nlink an external event (e.g. a billing provider webhook you receive and verify yourself)\nback to this user. Do not use the session token or session id for this — sessions expire and\nrotate, `userId` does not.\n\nEmail is best-effort from hosted login (Firebase `email` claim persisted on the user row).\nWhen unknown, `email` is `null`. Browser SDK: **`secureflows-js`** **`fetchSessionIdentity(token)`** (≥ 0.1.15 for `userId`).\n\nSource: GET /api/v1/sessions/identity\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection" ], "type": "object" }, "name": "get_sessions_identity", "outputSchema": null }, { "description": "Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**.\nPayload is included only for rows whose computed status is active.\nSort keys match the admin workspace session list; `pageSize` is clamped to 1–200 (default 20).\n\nSource: GET /api/v1/sessions/my\nRequires `auth.userToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "userToken": { "description": "secureFlows USER token", "type": "string" } }, "required": [ "userToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": { "app_id": { "description": "Filter by client app id, or `all`.", "type": "string" }, "dir": { "enum": [ "asc", "desc" ], "type": "string" }, "page": { "maximum": 9007199254740991, "minimum": 0, "type": "integer" }, "pageSize": { "description": "Page size (server clamps to 1–200; 0 or invalid uses default 20).", "maximum": 200, "minimum": 1, "type": "integer" }, "q": { "description": "Search by session id, app id, or user identifier (own uid)", "type": "string" }, "sort": { "enum": [ "id", "user", "app", "created", "expires", "status", "lastActivity", "updated" ], "type": "string" }, "status": { "description": "Computed session lifecycle filter (`all` or same values as admin session list).", "enum": [ "all", "active", "expired", "revoked" ], "type": "string" } }, "type": "object" } }, "required": [ "connection", "query" ], "type": "object" }, "name": "get_sessions_my", "outputSchema": null }, { "description": "Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\nis not a reliable way to clear hosted-login cookies. For browser apps (especially localhost), prefer the\nredirect helper `GET /api/v1/auth/logout?session_token=...&redirect_uri=...`.\n\nBehavior:\n- **Invalidates** the current `sessionToken` by incrementing `tokenRevision` (no new token is issued).\n- Calls Firebase `revokeRefreshTokens(firebaseUid)` using the session’s stored Firebase UID.\n- Sets `Clear-Site-Data: \"cookies\"` to clear browser cookies (including Firebase session cookie).\n\nSession payload and session row are **not** deleted or modified (other than `tokenRevision`).\n\nSource: POST /api/v1/auth/logout\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection" ], "type": "object" }, "name": "post_auth_logout", "outputSchema": null }, { "description": "Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessionToken`** (JWT; subject = internal session id).\nDefault server-side TTL is **1 hour** (implementation detail).\n\nIf the Firebase token includes **`email`**, the server best-effort persists it on the workspace\nend-user row (for audit display). Prefer **`POST /sessions/get-or-create`** for hosted-login-style\nflows that should reuse an active session.\n\nSource: POST /api/v1/sessions\nRequires `auth.firebaseToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "firebaseToken": { "description": "Firebase ID token", "type": "string" } }, "required": [ "firebaseToken" ], "type": "object" }, "body": { "properties": { "app_id": { "anyOf": [ { "description": "Optional app id (must belong to the workspace). Used for per-app session policy and auditing.", "type": "string" }, { "type": "null" } ] }, "payload": { "additionalProperties": {}, "description": "Arbitrary payload object stored in the session. Optional; omitted or null is stored as `{}`.", "propertyNames": { "type": "string" }, "type": "object" }, "workspaceName": { "description": "Workspace name to scope the session", "type": "string" } }, "required": [ "workspaceName" ], "type": "object" }, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "body" ], "type": "object" }, "name": "post_sessions", "outputSchema": null }, { "description": "Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT for the **most\nrecently created** matching row (touches activity; does not create a duplicate session). The request\n**`payload` is ignored on reuse** — it is applied only when a new session row is created. Prefer a\ndedicated `app_id` per integration surface, or revoke old sessions, if you need a fresh payload.\n\nOtherwise behaves like **`POST /sessions`** (new row + default **1 hour** TTL).\n\nIf the Firebase token includes **`email`**, the server best-effort persists or backfills it on the\nworkspace end-user row (including when reusing an existing session). Intended for integrators that\nmirror hosted login session reuse.\n\nSource: POST /api/v1/sessions/get-or-create\nRequires `auth.firebaseToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "firebaseToken": { "description": "Firebase ID token", "type": "string" } }, "required": [ "firebaseToken" ], "type": "object" }, "body": { "properties": { "app_id": { "anyOf": [ { "description": "Optional app id (must belong to the workspace). Used for per-app session policy and auditing.", "type": "string" }, { "type": "null" } ] }, "payload": { "additionalProperties": {}, "description": "Arbitrary payload object stored in the session. Optional; omitted or null is stored as `{}`.", "propertyNames": { "type": "string" }, "type": "object" }, "workspaceName": { "description": "Workspace name to scope the session", "type": "string" } }, "required": [ "workspaceName" ], "type": "object" }, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "body" ], "type": "object" }, "name": "post_sessions_get_or_create", "outputSchema": null }, { "description": "Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SESSION` are still validated). Loads the\nsession by id from the token subject; the Firebase UID must match the session owner.\nIncrements **`tokenRevision`** on the server so **previous session JWTs** (same session id,\nolder revision) are no longer accepted for `GET/POST/DELETE /sessions/...`.\nReturns a **new `sessionToken`** (with the new `tokenRevision` claim) and the current decrypted\n**payload**; extends server-side session expiry by **1 hour**.\n\nIf the Firebase token includes **`email`**, the server best-effort backfills it on the session owner\nwhen the user row has no email yet (audit display only).\n\nUse the path form `POST /api/v1/sessions/renew/{sessionToken}` — **URL-encode** the JWT (e.g. `encodeURIComponent` in JS).\n\nSource: POST /api/v1/sessions/renew/{sessionToken}\nRequires `auth.firebaseToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "firebaseToken": { "description": "Firebase ID token", "type": "string" } }, "required": [ "firebaseToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": { "sessionToken": { "description": "Previous SESSION JWT (may be expired); URL-encoded in the path", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "params" ], "type": "object" }, "name": "post_sessions_renew_session_token", "outputSchema": null }, { "description": "Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restored. This is NOT sign-out: to sign a user out and keep their data, use POST /api/v1/auth/logout (or, in a browser, the redirect helper GET /api/v1/auth/logout). Call revoke only when the user or an admin deliberately wants the session and its data deleted, for example on account deletion.\n\nSource: POST /api/v1/sessions/revoke\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": {}, "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection" ], "type": "object" }, "name": "post_sessions_revoke", "outputSchema": null }, { "description": "Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; this is not sign-out.\nRequires workspace **`enableSelfService: true`**.\n\nSource: POST /api/v1/sessions/revoke/{sessionId}\nRequires `auth.userToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "userToken": { "description": "secureFlows USER token", "type": "string" } }, "required": [ "userToken" ], "type": "object" }, "body": {}, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": { "sessionId": { "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" } }, "required": [ "sessionId" ], "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "params" ], "type": "object" }, "name": "post_sessions_revoke_session_id", "outputSchema": null }, { "description": "Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores `<x>` directly.\n\nSource: POST /api/v1/sessions/set/{key}\nRequires `auth.sessionToken` and forwards it as a Bearer token.\nPrefer connection.workspaceName and connection.appId as stable config instead of generating identity fields dynamically.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "auth": { "properties": { "sessionToken": { "description": "secureFlows session token", "type": "string" } }, "required": [ "sessionToken" ], "type": "object" }, "body": { "anyOf": [ { "properties": { "value": {} }, "required": [ "value" ], "type": "object" }, { "type": "string" }, { "type": "number" }, { "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, { "type": "boolean" }, { "items": {}, "type": "array" }, { "additionalProperties": {}, "propertyNames": { "type": "string" }, "type": "object" }, {} ], "description": "JSON body can be either `{ \"value\": <x> }` (preferred) or a raw JSON value.\n" }, "connection": { "properties": { "appId": { "description": "Optional secureFlows app id used as a default for hosted login tools", "type": "string" }, "host": { "description": "secureFlows base URL, for example https://api.example.com", "format": "uri", "type": "string" }, "workspaceName": { "description": "Optional workspace name used as a default for tools that need it", "type": "string" } }, "required": [ "host" ], "type": "object" }, "params": { "properties": { "key": { "description": "Payload key to set", "type": "string" } }, "required": [ "key" ], "type": "object" }, "query": { "properties": {}, "type": "object" } }, "required": [ "connection", "params", "body" ], "type": "object" }, "name": "post_sessions_set_key", "outputSchema": null }, { "description": "Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phase most secureFlows integration mistakes happen in.\n\nAlways targets /app/sessions/login (session apps). Never builds the legacy /app/login console URL,\nwhich returns a firebaseToken your SecureFlowsCallback handler cannot consume and causes an infinite redirect loop.\n\nUse this instead of hand-building the URL with URLSearchParams — hand-built login URLs are the #1 source of the\nlogin-loop and stale-renewal bugs documented in SKILL.md.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "appId": { "description": "App id from the human prompt (\"appId = ...\")", "type": "string" }, "expiredToken": { "description": "The old sessionToken to renew. Only read when intent=renew_expired_token. Setting this after an explicit sign-out is the \"send a dead JWT into hosted login\" anti-pattern — it breaks renewal when the underlying identity changed.", "type": "string" }, "intent": { "default": "fresh_login", "description": "fresh_login: normal sign-in, or app-load restore with no prior token (default — almost always correct, including after an explicit sign-out). renew_expired_token: ONLY when resuming the SAME still-intended user after a soft token expiry (401/410) while staying logged in — never after Sign out.", "enum": [ "fresh_login", "renew_expired_token" ], "type": "string" }, "origin": { "default": "https://www.secure-flows.com", "description": "secureFlows origin — always https://www.secure-flows.com in production", "format": "uri", "type": "string" }, "redirectUri": { "description": "The app's unguarded /callback URL, built from the published/allowlisted app origin — never from an iframe or editor chrome origin.", "format": "uri", "type": "string" }, "workspaceName": { "description": "Workspace name from the human prompt (\"workspace = ...\")", "type": "string" } }, "required": [ "workspaceName", "appId", "redirectUri" ], "type": "object" }, "name": "secureflows_build_login_url", "outputSchema": null }, { "description": "Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA callback handlers treat the tokenless return as a failed login and loop),\nand a redirect_uri that itself embeds session_token (silently renews the old session instead of signing out).\n\nThe result always instructs top-level navigation, never fetch/XHR — cross-site fetch() to this endpoint gets a 200 but\nbrowsers silently ignore its Clear-Site-Data header on cross-site responses, so the hosted-login cookie survives and the\nuser silently re-authenticates on the next login redirect. This tool never builds a revoke request: revoke permanently\ndestroys the user's data and must only run on an explicit \"delete my account\" action, never on ordinary sign-out.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "origin": { "default": "https://www.secure-flows.com", "description": "secureFlows origin — always https://www.secure-flows.com in production", "format": "uri", "type": "string" }, "postLogoutRedirectUri": { "description": "Where the browser lands after logout completes — allowlisted, must NOT be /callback, and must NOT itself contain session_token.", "format": "uri", "type": "string" }, "sessionToken": { "description": "The current sessionToken to invalidate.", "type": "string" } }, "required": [ "sessionToken", "postLogoutRedirectUri" ], "type": "object" }, "name": "secureflows_build_logout_url", "outputSchema": null }, { "description": "Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-related file in one call — some checks are evaluated across the whole set.\n\nTwo kinds of findings:\n • scope \"file\" — a forbidden construct is present (localStorage token, legacy /app/login, fetch-based logout,\n client-side JWT decode, empty catch, restore non-auth errors clearing session UI, Continue CTA gated on null session, ...), reported at an exact file:line.\n • scope \"project\" — REQUIRED handling is missing everywhere you passed in: detecting 401/410 but never clearing the\n token, never handling 403, or handling 403 without the BILLING_GRACE_LOCK carve-out. These are the defects that\n actually dominate real generated apps, and no \"forbidden pattern\" check can see them, because the bug is an absence.\n\nHeuristic text analysis, not a parser or a type checker. It can miss things it has no rule for, and a project check can\nbe satisfied by the right keyword in the wrong place. It is a fast first pass — not a substitute for the Agent\nimplementation checklist in SKILL.md, and specifically not for the checks that need a running app (auth-guard mount\nraces, the fresh-reload check). Fix every \"error\" before calling an integration done; treat \"needs_review\" as a lead.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": { "files": { "additionalProperties": { "type": "string" }, "description": "Map of relative file path -> full file source to scan, e.g. { \"src/lib/secureflows.js\": \"...\" }", "propertyNames": { "type": "string" }, "type": "object" } }, "required": [ "files" ], "type": "object" }, "name": "secureflows_lint_integration", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:e687cc6dc06e28739e9970d2aeda85fa49059951f8d94f34286cc465b9caf945 | sha256sum