KYE™ MCP Server
Integration surface for agents, IDEs, AI assistants, and developer tools. Read-only by default; decision and admin tools require explicit gating.
KYE™ MCP Server
KYE™ MCP Server™ exposes the protocol to Claude, GPT. And any MCP-compatible agent. Signed tool calls. Scoped evidence.
You learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.
Accounts-payable agent pays a supplier invoice
permission_granted
Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917
In-appWebhook
Procurement agent orders above its approval threshold
approval_threshold_breach
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
App pushIn-appWebhook
Clinical summarisation agent asks to read records for marketing
permission_missing
Read 1,200 patient records to build a marketing list (demo)
In-appWebhook
HR operations agent acts on a revoked delegation
delegation_revoked
Change a staff member's contracted hours (demo)
In-appWebhook
Drafting agent prepares a disclosure letter, with redaction
permission_granted
Draft a disclosure letter for matter M-2207 (demo)
In-appWebhook
Credit agent acts outside its jurisdiction
jurisdiction_unsupported
Approve a £4,200 credit line for an applicant in the US (demo)
In-appWebhook
You learn: How it works, one stage at a time. You can: Run it end to end.
Install
KYE Protocol™
npm i @kye/mcp-server (v1.1)
Configure tenant auth, gateway URL, and the tool allowlist (read-only / decision / admin…
KYE Protocol™
Start the server
KYE Protocol™
npx @kye/mcp-server --config kye-mcp.json
Connect from an MCP client (Claude Desktop, Cursor, internal AI platform)
KYE Protocol™
Discover resources, tools, and prompts.
Verify with the included conformance suite
KYE Protocol™
npx @kye/mcp-server conformance
When v1.1 ships, the KYE™ MCP Server exposes KYE Protocol™ schemas, dictionaries, authority checks, Decision Maps™. And evidence packs through a controlled Model Context Protocol interface — read-only resources, decision tools that round-trip through the gateway, gated admin tools. Auth, idempotency, audit binding all enforced.
Plain Q&A
Short questions. Short answers.
Plain take
Plug KYE™ into Claude, GPT, or any MCP agent. Signed tools. Scoped proof.
The boundary
Integration surface for agents, IDEs, AI assistants, and developer tools. Read-only by default; decision and admin tools require explicit gating.
The enforcement surface. Production decisions for agent actions, payment authorisations, and capability invocations land here — never on MCP alone.
An MCP tool call should not bypass the runtime gateway for any production-affecting action. The MCP server's decision tools call through the gateway, log the call as an audit event. And return the gateway's signed response. Treat MCP as a typed, controlled query and proposal layer.
Read-only tools
Read-only tools never mutate state, never publish events, never affect production. They are safe to enable for any MCP client.
kye.resolve_entity — resolve an entity URN to its canonical recordkye.get_entity_state — current six-dimensional state vectorkye.get_authority_grant — lookup a grant by idkye.get_delegation_chain — walk the chain from actor to root principalkye.get_capability_manifest — manifest for a named capabilitykye.get_decision_map — signed Decision Map™ for a decision idkye.get_evidence_pack — signed evidence pack by idkye.verify_evidence_pack — verify a pack offline using the published JWKSkye.list_reason_codes — full reason-code dictionarykye.explain_decision — human-readable rendering of a Decision Map™Decision tools
Decision tools propose an action and ask the runtime gateway for a verdict. They never decide locally. the gateway decides, signs. And audits.
kye.decide_authority — ask "may this actor exercise this authority right now?"kye.decide_capability_invocation — ask "may this capability be invoked with these parameters?"kye.check_payment_authority — ask "is this delegated payment authority valid for this transaction?"kye.check_agent_purchase — ask "may this agent buy this basket from this merchant on this instrument?"kye.check_scope — ask "does this action fit inside the named scope?"Every decision tool returns the standard decision codes (allow / allow_with_constraints / require_approval / require_step_up / require_human_review / require_recovery / quarantine / deny) plus a Decision Map™ reference. The MCP client cannot bypass the gateway.
Admin / write tools · gated by default
Admin tools are off by default. When enabled, every call MUST present tenant authentication, MUST pass policy checks, MUST carry an idempotency key, MUST emit an audit event. And MAY require step-up approval depending on the policy binding. Treat MCP write paths as a high-risk surface.
kye.create_entity — create a new entity recordkye.create_delegation — create a delegation between actor and principalkye.grant_authority — grant scoped authority to a delegationkye.revoke_authority — revoke an authority grantkye.quarantine_entity — quarantine an entity (state mutation)kye.rotate_credential — rotate signing credentials for an entitykye.create_capability_manifest — register a new capability manifestkye.create_webhook_endpoint — register a new subscriber endpointHard requirements per call: tenant auth (mTLS or OAuth2 client-credentials) · per-tool capability check via the runtime gateway · idempotency key in the request · reason code in the request · full audit event emitted before response · step-up approval per policy binding.
MCP resources
MCP resources are URI-addressable, read-only data exposed to the client. The KYE™ MCP Server exposes a uniform kye:// URI scheme.
kye://schemas/core · kye://schemas/entity · kye://schemas/authority-grant · kye://schemas/capability-manifestkye://dictionaries/reason-codes · kye://dictionaries/decision-codes · kye://dictionaries/event-typeskye://profiles/payment-authority · kye://profiles/agent-purchasing · kye://profiles/{profile-id}kye://decision-maps/{id} · kye://evidence-packs/{id}kye://entities/{id} · kye://capabilities/{id} · kye://delegations/{id}MCP prompts
What it is. Why it matters. What to do next.
review_authority_chain — structured review of a delegation chain for attenuation correctnessexplain_decision_map — render a Decision Map™ in natural language for a non-technical audiencedraft_authority_grant — help an operator draft a scoped authority-grant requestmodel_agent_purchasing_flow — sketch an agent-purchasing flow against the kye-payments-card profilegenerate_open_banking_authority_map — map a TPP → agent → ASPSP Authority Graph™assess_kye_readiness — readiness review against the 12-question Authority Finality™ assessmentprepare_evidence_pack_summary — one-page summary of an evidence pack for a regulator-facing briefSecurity
MCP server deployments have introduced real-world risks: malicious tool execution, credential theft, prompt-injection-driven privilege escalation. And supply-chain compromise via untrusted server packages. The KYE™ MCP Server assumes the worst by default.
Start
The flow below describes the v1.1 install path. Today, integrate against the KYE™ Reference Gateway™ directly via the SDKs. the same authority + decision + evidence semantics apply.
npm i @kye/mcp-server (v1.1)npx @kye/mcp-server --config kye-mcp.jsonnpx @kye/mcp-server conformanceAdjacent reading
What it is. Why it matters. What to do next.
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Canonical KYE™ surfaces referenced on this page: Authority Graph™ · Evidence Pack™ · KYE Protocol™.