/** * The Auden MCP server. Exposes the context layer (`/api/v1/context/*`) to any * agent as a small set of tools over stdio (`list_bundles`, `pull_context`, * `push_context`, `create_bundle`, `file_context`, `list_inbox`, `pull_inbox`, * `archive_inbox`), so an agent configures it once (in `.mcp.json` / Claude * Code / Cursor) instead of wiring each source. The server name (`auden`) * namespaces them, so tool names stay bare underscores — dots are outside the Anthropic/Claude Code tool-name charset. * * Every tool maps 1:1 to a REST route on the dashboard via `ContextClient`. The * server acts as the user (it reuses the CLI token) and constrains exposure * locally: `readOnly` refuses mutating tools, and `bundles` (an allowlist) * limits which bundles are reachable — the "wire once, still scoped" answer. * * Argument validation is Valibot (never Zod) per repo convention; the low-level * `Server` is used precisely so tool input schemas are plain JSON Schema and * incoming arguments are validated by our own Valibot schemas rather than the * SDK's Zod shapes. */ import { Server } from '@modelcontextprotocol/sdk/server/index.js'; import { runImportTool } from './import-tool.js'; import type { ContextClient } from './client.js'; import type { ImportToolAuth } from './import-tool.js'; import type { WriteItemsDeps } from './write-items.js'; export type McpServerDeps = { client: ContextClient; /** * When true, mutating tools (push_context, create_bundle, file_context, * archive_inbox) are refused. */ readOnly: boolean; /** Bundle allowlist; null means every bundle the caller owns is reachable. */ bundles: string[] | null; /** Injectable clock so relative `since` windows resolve deterministically. */ now?: () => Date; /** Injectable filesystem for `writeToDir`, for tests. */ writeDeps?: WriteItemsDeps; /** * The working directory a `writeToDir` must stay inside, and the subtree the * `import` tool may read from. Defaults to `process.cwd()` — the tree the * agent is actually working in, which is the whole basis of both guards * (`mcp/write-scope.ts` → `refuseOutsideTree`). */ cwd?: string; /** * Credentials for the `import` tool, which reaches the rules-import endpoint * rather than the context client (a guide cannot ride `push_context`; see * `mcp/import-tool.ts`). Omitted when no token resolved, in which case the * tool refuses by name instead of failing at the HTTP call. */ importAuth?: ImportToolAuth; /** Injectable importer internals, for tests. */ importDeps?: Pick[1], 'discoverFn' | 'resolveCandidatesFn' | 'importFn' | 'repoIdFn'>; }; export type ToolResult = { content: { type: 'text'; text: string; }[]; isError?: boolean; }; export type ToolDefinition = { name: string; description: string; inputSchema: Record; handler: (args: unknown) => Promise; }; /** * Build the tool definitions (name, JSON-Schema input, handler). Exposed * separately from `createMcpServer` so handlers unit-test directly against a * mocked client without a transport. */ export declare function buildTools(deps: McpServerDeps): ToolDefinition[]; /** * Wire the tools into an MCP `Server` with stdio-ready request handlers. The * caller connects a transport (`await server.connect(new StdioServerTransport())`). */ export declare function createMcpServer(deps: McpServerDeps): Server; //# sourceMappingURL=server.d.ts.map