Spaces:
Running
Running
deploy(hf): sync szl-holdings/a11oy@185449689f48dd45efa0daa5f057a20fb04b4bf6 derived COPY set
65f0228 verified | <html lang="en"><head><meta charset="utf-8"> | |
| <meta name="viewport" content="width=device-width,initial-scale=1"> | |
| <title>a11oy · Hatun-MCP — agentic MCP server</title> | |
| <!-- SPDX-License-Identifier: Apache-2.0 · © 2026 SZL Holdings · Doctrine v12 additive · Signed: Yachay · Co-author: Perplexity Computer Agent --> | |
| <style> | |
| :root{--bg:#0a0b10;--panel:#12141d;--panel2:#171a25;--ink:#e8eaf0;--mut:#9aa0b4;--gold:#d9b35c;--line:#252938;--grn:#3fb950;--amb:#d29922;--red:#f85149;} | |
| *{box-sizing:border-box}body{margin:0;background:var(--bg);color:var(--ink);font:15px/1.6 -apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Helvetica,Arial,sans-serif} | |
| a{color:var(--gold);text-decoration:none}a:hover{text-decoration:underline} | |
| header{border-bottom:1px solid var(--line);padding:14px 22px;display:flex;align-items:center;gap:14px;background:linear-gradient(180deg,#10121b,#0a0b10)} | |
| header .brand{font-weight:700;letter-spacing:.5px;color:var(--gold);font-size:18px} | |
| header .tag{color:var(--mut);font-size:12px} | |
| nav{display:flex;flex-wrap:nowrap;gap:8px;padding:10px 22px;border-bottom:1px solid var(--line);background:var(--panel);overflow-x:auto;overscroll-behavior-inline:contain;scrollbar-width:thin} | |
| nav a{font-size:12.5px;padding:4px 10px;border:1px solid var(--line);border-radius:999px;color:var(--mut)} | |
| nav a:hover{border-color:var(--gold);color:var(--gold);text-decoration:none} | |
| nav a.active{background:var(--gold);color:#0a0b10;border-color:var(--gold);font-weight:600} | |
| main{max-width:1040px;margin:0 auto;padding:28px 22px 60px} | |
| h1{font-size:26px;margin:0 0 4px;color:#fff}h2{font-size:18px;margin:28px 0 10px;color:var(--gold)} | |
| .sub{color:var(--mut);margin:0 0 18px;font-size:13.5px} | |
| .card{background:var(--panel);border:1px solid var(--line);border-radius:12px;padding:18px 20px;margin:14px 0} | |
| .grid{display:grid;grid-template-columns:repeat(auto-fill,minmax(230px,1fr));gap:14px;margin:16px 0} | |
| .grid a.tile{display:block;background:var(--panel2);border:1px solid var(--line);border-radius:12px;padding:16px;color:var(--ink)} | |
| .grid a.tile:hover{border-color:var(--gold);text-decoration:none} | |
| .grid a.tile .t{color:var(--gold);font-weight:600;margin-bottom:4px}.grid a.tile .d{color:var(--mut);font-size:12.5px} | |
| table{width:100%;border-collapse:collapse;margin:12px 0;font-size:13.5px} | |
| .table-wrap{width:100%;overflow-x:auto;overscroll-behavior-inline:contain;-webkit-overflow-scrolling:touch} | |
| .table-wrap table{min-width:620px} | |
| th,td{text-align:left;padding:8px 10px;border-bottom:1px solid var(--line);vertical-align:top} | |
| th{color:var(--mut);font-weight:600;font-size:12px;text-transform:uppercase;letter-spacing:.4px} | |
| code,pre{font-family:ui-monospace,SFMono-Regular,Menlo,monospace;font-size:12.5px} | |
| pre{background:#0d0f17;border:1px solid var(--line);border-radius:10px;padding:14px;overflow:auto;color:#cdd3e3} | |
| .pill{display:inline-block;padding:2px 9px;border-radius:999px;font-size:11.5px;font-weight:600} | |
| .g{background:rgba(63,185,80,.15);color:var(--grn)}.a{background:rgba(210,153,34,.15);color:var(--amb)}.r{background:rgba(248,81,73,.15);color:var(--red)}.n{background:#1c2030;color:var(--mut)} | |
| .note{border-left:3px solid var(--gold);padding:8px 14px;background:rgba(217,179,92,.06);color:#d8dbe6;font-size:13.5px;margin:14px 0;border-radius:0 8px 8px 0} | |
| footer{border-top:1px solid var(--line);color:var(--mut);font-size:11.5px;padding:18px 22px;line-height:1.7} | |
| .kbd{background:#1c2030;border:1px solid var(--line);border-radius:6px;padding:1px 7px;font-family:ui-monospace,monospace;font-size:12px} | |
| .statline{display:flex;flex-wrap:wrap;gap:18px;align-items:center;font-size:13.5px} | |
| .statline b{color:var(--ink)} | |
| .tag2{display:inline-block;background:#1c2030;color:var(--mut);border:1px solid var(--line);border-radius:6px;padding:1px 7px;font-size:11px;margin-left:6px} | |
| .st{color:var(--amb);font-weight:600} | |
| @media(max-width:700px){ | |
| header{padding:12px 14px;align-items:flex-start;flex-direction:column;gap:2px} | |
| nav{padding:9px 14px} | |
| main{padding:20px 14px 44px} | |
| h1{font-size:23px;line-height:1.25} | |
| .card{padding:15px} | |
| .statline{display:grid;grid-template-columns:1fr;gap:8px} | |
| pre{white-space:pre-wrap;overflow-wrap:anywhere} | |
| footer{padding:16px 14px} | |
| } | |
| </style> <link rel="stylesheet" href="/assets/szl-flow.css" data-szl-flow-asset="style" /> | |
| <link rel="stylesheet" href="/assets/szl-holo-v2.css" data-szl-holo-asset="style-v2" /> | |
| </head><body> | |
| <header><span class="brand">a11oy</span><span class="tag">Brand Orchestration Layer · the one place to see everything</span></header> | |
| <nav><a href="/hub">Hub</a><a href="/a11oy.code">a11oy.code</a><a href="/docs">Docs</a><a href="/pricing">Pricing</a><a href="/api-keys">API Keys</a><a href="/sdk">SDK</a><a href="/status">Status</a><a href="/hatun-mcp" class="active">Hatun-MCP</a><a href="/observability">Observability</a><a href="/security">Security</a><a href="/compliance">Compliance</a><a href="/cued-engagement">Cued Engagement</a><a href="/uds">UDS</a><a href="/counter-uas">Counter-UAS</a><a href="/evidence">Evidence</a><a href="/upgrades">Upgrades</a><a href="/audit">Audit</a><a href="/gap-report">Gap Report</a></nav> | |
| <main> | |
| <h1>Hatun-MCP — agentic MCP server</h1> | |
| <p class="sub"><b>Hatun</b> (Quechua: <i>great / sovereign</i>) is the Model Context Protocol gateway for SZL capabilities. This page separates a reachable runtime declaration from execution and receipt evidence. A listed tool is not proof that it has run. Receipt and signer fields remain <b>UNKNOWN</b> or <b>UNAVAILABLE</b> until the read-only evidence endpoint observes an actual governed-run receipt.</p> | |
| <div class="card"> | |
| <div class="statline"> | |
| <span>Live status: <span id="health"><span class="pill n">probing…</span></span></span> | |
| <span>Signer: <b id="signer">—</b></span> | |
| <span>Khipu chain: <b id="chain">—</b></span> | |
| <span>Protocol: <b id="proto">—</b></span> | |
| <span>Probe latency: <b id="lat">—</b></span> | |
| </div> | |
| <p class="sub" style="margin:12px 0 0">Runtime path: <code>/mcp/</code> (same origin) · Transport: JSON-RPC over HTTP (<code>POST /mcp/</code>). Availability, protocol revision, signer evidence, and receipt-chain evidence are populated only from successful reads below.</p> | |
| </div> | |
| <h2>Tools declared (<span id="toolcount">—</span>) <span id="toolsource" class="pill a">STATIC FALLBACK</span></h2> | |
| <p class="sub">The initial rows are an explicitly labelled static fallback. A successful <code>GET /mcp/</code> replaces them with the runtime-declared catalog. Neither state is execution proof.</p> | |
| <div class="table-wrap"><table><thead><tr><th>Tool</th><th>Description</th><th>Evidence class</th></tr></thead><tbody id="tools"></tbody></table></div> | |
| <h2>Organ mesh</h2> | |
| <p class="sub">Same-origin map of Hatun to second brain, anatomy, ouroboros, and the formula codex. Labels are route presence. Second-brain readiness is whatever that endpoint reports this request.</p> | |
| <div class="table-wrap"><table><thead><tr><th>Organ</th><th>Job</th><th>Surface</th><th>Label</th></tr></thead><tbody id="mesh"><tr><td colspan="4" class="sub">loading…</td></tr></tbody></table></div> | |
| <h2>Recent invocations</h2> | |
| <p class="sub">This bounded, ephemeral feed contains only summaries of governed agent runs for which this process actually created a receipt. It does not claim that every MCP discovery or tool call is signed, and reading it never mints a receipt.</p> | |
| <div class="table-wrap"><table><thead><tr><th>Time (UTC)</th><th>Observed tool</th><th>Outcome</th><th>Receipt evidence</th></tr></thead><tbody id="inv"><tr><td colspan="4" class="sub">loading…</td></tr></tbody></table></div> | |
| <h2>Connect a client</h2> | |
| <div class="card"> | |
| <p style="margin:0 0 8px">Claude Desktop — deployment example using the <code>mcp-remote</code> bridge. Verify the target URL and authentication requirements in your environment before use:</p> | |
| <pre>{ | |
| "mcpServers": { | |
| "szl-a11oy": { | |
| "command": "npx", | |
| "args": ["-y", "mcp-remote", "/mcp/"] | |
| } | |
| } | |
| }</pre> | |
| <p class="sub" style="margin:8px 0 0">Same-origin checks: <code>GET /mcp/</code> for runtime discovery, <code>GET /api/hatun/evidence</code> for the no-mint evidence contract, and <code>GET /api/hatun/invocations</code> for observed receipt summaries. A public-key path alone is not proof that any receipt was signed.</p> | |
| </div> | |
| <div class="note">The page performs read-only same-origin probes. <code>GET /mcp/</code> supplies runtime declarations; <code>GET /api/hatun/evidence</code> supplies observed receipt state. Neither GET signs, appends, or upgrades evidence.</div> | |
| <p class="sub">Source: <code>szl_agentic_loop.py</code> · read-only probes of <code>/mcp/</code> and <code>/api/hatun/evidence</code></p> | |
| <script> | |
| const BASE=""; | |
| const FALLBACK_TOOLS=[ | |
| {name:"retrieve_context",description:"Governance-corpus retrieval declaration"}, | |
| {name:"policy_check",description:"Deny-by-default policy declaration"}, | |
| {name:"trust_score",description:"Advisory trust-score declaration"}, | |
| {name:"sign_receipt",description:"Receipt-signing declaration"}, | |
| {name:"verify_receipt",description:"Receipt-verification declaration"} | |
| ]; | |
| function cell(text,tag){const el=document.createElement(tag||'td');el.textContent=text==null?'—':String(text);return el;} | |
| function pill(text,cls){const el=document.createElement('span');el.className='pill '+cls;el.textContent=text;return el;} | |
| function setStatus(id,text,cls){const host=document.getElementById(id);host.textContent='';host.appendChild(pill(text,cls));} | |
| function paintTools(list,evidenceClass){const tb=document.getElementById('tools');tb.textContent=''; | |
| list.forEach(tool=>{const tr=document.createElement('tr');const name=cell(tool.name,'td'); | |
| const code=document.createElement('code');code.textContent=tool.name||'—';name.textContent='';name.appendChild(code); | |
| tr.appendChild(name);tr.appendChild(cell(tool.description||tool.title||'No description reported')); | |
| const status=cell('','td');status.appendChild(pill(evidenceClass,evidenceClass==='RUNTIME DECLARED'?'n':'a'));tr.appendChild(status);tb.appendChild(tr);}); | |
| document.getElementById('toolcount').textContent=list.length;} | |
| paintTools(FALLBACK_TOOLS,'STATIC FALLBACK'); | |
| const t0=performance.now(); | |
| fetch(BASE+"/mcp/",{cache:'no-store'}).then(r=>r.json().then(j=>({r,j}))).then(({r,j})=>{ | |
| document.getElementById('lat').textContent=Math.round(performance.now()-t0)+' ms'; | |
| setStatus('health',r.ok?'REACHABLE':'HTTP '+r.status,r.ok?'g':'a'); | |
| document.getElementById('proto').textContent=j.protocolVersion||'UNKNOWN'; | |
| if(r.ok&&j&&Array.isArray(j.tools)){ | |
| paintTools(j.tools,'RUNTIME DECLARED'); | |
| const source=document.getElementById('toolsource');source.className='pill n';source.textContent='RUNTIME DECLARED'; | |
| } | |
| }).catch(()=>{setStatus('health','UNAVAILABLE','r');document.getElementById('lat').textContent='UNAVAILABLE';}); | |
| fetch(BASE+"/api/hatun/evidence",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(e=>{ | |
| const signer=e&&e.signer||{};const chain=e&&e.receipt_chain||{}; | |
| document.getElementById('signer').textContent=signer.status==='OBSERVED_VERIFIED'?(signer.label||'OBSERVED_VERIFIED'):(signer.status||'UNKNOWN'); | |
| document.getElementById('chain').textContent=chain.status||'UNKNOWN'; | |
| }).catch(()=>{document.getElementById('signer').textContent='UNAVAILABLE';document.getElementById('chain').textContent='UNAVAILABLE';}); | |
| function paintEmptyInvocation(message){const tb=document.getElementById('inv');tb.textContent='';const tr=document.createElement('tr'); | |
| const td=cell(message,'td');td.colSpan=4;td.className='sub';tr.appendChild(td);tb.appendChild(tr);} | |
| fetch(BASE+"/api/hatun/mesh",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(m=>{ | |
| const tb=document.getElementById('mesh'); if(!tb) return; tb.textContent=''; | |
| const organs=(m&&m.organs)||[]; | |
| if(!organs.length){const tr=document.createElement('tr'); const td=cell('UNAVAILABLE — mesh contract empty','td'); td.colSpan=4; td.className='sub'; tr.appendChild(td); tb.appendChild(tr); return;} | |
| organs.forEach(o=>{const tr=document.createElement('tr'); | |
| const id=cell('','td'); const code=document.createElement('code'); code.textContent=o.id||'—'; id.appendChild(code); tr.appendChild(id); | |
| tr.appendChild(cell(o.job||'—')); | |
| const surf=cell('','td'); const a=document.createElement('a'); a.href=o.href||'#'; a.textContent=o.href||'—'; surf.appendChild(a); tr.appendChild(surf); | |
| const lab=cell('','td'); lab.appendChild(pill(o.label||'UNAVAILABLE','n')); tr.appendChild(lab); tb.appendChild(tr);}); | |
| }).catch(()=>{const tb=document.getElementById('mesh'); if(!tb) return; tb.textContent=''; const tr=document.createElement('tr'); const td=cell('UNAVAILABLE — mesh contract could not be read','td'); td.colSpan=4; td.className='sub'; tr.appendChild(td); tb.appendChild(tr);}); | |
| fetch(BASE+"/api/hatun/invocations",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(feed=>{ | |
| const items=feed&&Array.isArray(feed.items)?feed.items:[];const tb=document.getElementById('inv');tb.textContent=''; | |
| if(!items.length){paintEmptyInvocation('UNKNOWN — no governed-run receipt has been observed in this process.');return;} | |
| items.slice(0,12).forEach(x=>{const tr=document.createElement('tr');tr.appendChild(cell(x.ts)); | |
| const tool=cell('','td'),code=document.createElement('code');code.textContent=x.tool||'—';tool.appendChild(code);tr.appendChild(tool); | |
| const outcome=cell('','td');outcome.appendChild(pill(x.outcome||'UNKNOWN',x.outcome==='DENY'?'r':'a'));tr.appendChild(outcome); | |
| const ev=cell('','td'),evCode=document.createElement('code');evCode.textContent=(x.signature_status||'UNKNOWN')+' · '+(x.receipt_hash||'').slice(0,16);ev.appendChild(evCode);tr.appendChild(ev);tb.appendChild(tr);}); | |
| }).catch(()=>{paintEmptyInvocation('UNAVAILABLE — the read-only invocation feed could not be read.');}); | |
| </script> | |
| </main> | |
| <footer>Doctrine v11 honesty boundary · tool catalog = runtime declaration, not execution proof · signer and receipt-chain state remain UNKNOWN or UNAVAILABLE until observed evidence exists · GET reads never mint receipts</footer> | |
| <script src="/assets/szl-flow.js" defer data-szl-flow-asset="script"></script> | |
| <script src="/assets/szl-holo-v2.js" defer data-szl-holo-asset="script-v2"></script> | |
| </body></html> | |