com.aleeth/authority-mcp
Other MCP servers expose tools. This one governs them. Every call is risk-checked by Rail Guard before it runs and sealed with a signed L7 receipt after. Denied and halted calls never execute. Anonymous POST returns 401. That is the product, not an error.
Tools
51
26 read · 16 write · 9 control
Registry
com.aleeth/authority-mcp
version from /healthz
Endpoint
mcp.aleeth.com
streamable HTTP · TLS
Auth
OAuth 2.0
anonymous calls return 401
Connect
No scan. No theater. A bearer token, or nothing.
# Remote MCP · production
https://mcp.aleeth.com/mcp
# Discovery
https://mcp.aleeth.com/.well-known/oauth-protected-resource
# Registry
com.aleeth/authority-mcp
The catalog · 51 tools
| Tool | What it is | Scope |
|---|---|---|
list_frameworks | List Regulatory Frameworks | frameworks:read |
list_active_halts | List Quarantined Agents | agent:read |
list_governed_apis | List Governed APIs | catalog:read |
verify_receipt | Verify Receipt | ledger:read |
get_capability_matrix | Capability-Control Matrix | matrix:read |
get_agent_registry | Agent Registry | registry:read |
get_academy_file | Academy File by DID | registry:read |
list_skills_and_tools | Tools & Skills Registry | curriculum:read |
get_catalog_entry | Registry Entry | curriculum:read |
get_atc_incidents | ATC Incidents | incidents:read |
get_atc_coverage | ATC Sensor Coverage | coverage:read |
get_atc_health | ATC Engine Health | coverage:read |
get_atc_signals | ATC Raw Signals | incidents:read |
get_atc_overview | ATC Overview (fan-out) | incidents:read |
get_ledger_entries | Ledger Entries | ledger:read |
get_trust_score | Trust Score | ledger:read |
verify_receipt_chain | Verify Receipt Chain | ledger:read |
get_authority_uses | Authority Usage Log | authority:read |
get_authority_violations | Authority Violations | authority:read |
get_agent_scope | Agent Authority Scope | authority:read |
get_incident_lifecycle | Incident Lifecycle | incidents:read |
get_governance_fingerprint | Governance Fingerprint | governance:read |
simulate_governed_call | Simulate Governed Call | governance:simulate |
get_task_contract | Get Task Contract | task:read |
list_holds | List Holds | hold:read |
get_payment_case | Get Payment Case | payments:read |
| Tool | What it is | Scope |
|---|---|---|
run_l7_audit | Run L7 Self-Audit | audit:run |
equip_agent | Equip Agent | academy:equip |
graduate_agent | Graduate Agent | academy:graduate |
intake_recruit | Intake Recruit | academy:intake |
issue_receipt | Attest to Ledger | ledger:write |
triage_incident | Triage Incident | incident:manage |
contain_incident | Contain Incident | incident:manage |
disclose_incident | Record Incident Disclosure | incident:manage |
close_incident | Close Incident | incident:manage |
ratify_finding | Ratify Finding | disposition:manage |
dismiss_finding | Dismiss Finding | disposition:manage |
suppress_finding | Suppress Finding | disposition:manage |
escalate_finding | Escalate Finding | disposition:manage |
approve_rule_candidate | Approve Rule Candidate | rule:govern |
reject_rule_candidate | Reject Rule Candidate | rule:govern |
open_task_contract | Open Task Contract | task:write |
| Tool | What it is | Scope |
|---|---|---|
stop_agent | STOP Agent (Halt) | agent:control |
release_agent | RELEASE Agent | agent:control |
execute_governed_payment | Execute Governed Payment | payment:execute |
proxy_downstream_tool | Proxy Downstream Tool | downstream:proxy |
approve_hold | Approve Hold | hold:approve |
reject_hold | Reject Hold | hold:approve |
request_destination_change | Request Destination Change | payments:destination |
reconcile_payment_intent | Reconcile Payment Intent | payment:reconcile |
lift_payment_freeze | Lift Payment Freeze | freeze:lift |