a11oy / pages /hatun-mcp.html
betterwithage's picture
deploy(hf): sync szl-holdings/a11oy@185449689f48dd45efa0daa5f057a20fb04b4bf6 derived COPY set
65f0228 verified
Raw
History Blame Contribute Delete
14.3 kB
<!doctype html><html lang="en"><head><meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>a11oy · Hatun-MCP — agentic MCP server</title>
<!-- SPDX-License-Identifier: Apache-2.0 · © 2026 SZL Holdings · Doctrine v12 additive · Signed: Yachay · Co-author: Perplexity Computer Agent -->
<style>
:root{--bg:#0a0b10;--panel:#12141d;--panel2:#171a25;--ink:#e8eaf0;--mut:#9aa0b4;--gold:#d9b35c;--line:#252938;--grn:#3fb950;--amb:#d29922;--red:#f85149;}
*{box-sizing:border-box}body{margin:0;background:var(--bg);color:var(--ink);font:15px/1.6 -apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Helvetica,Arial,sans-serif}
a{color:var(--gold);text-decoration:none}a:hover{text-decoration:underline}
header{border-bottom:1px solid var(--line);padding:14px 22px;display:flex;align-items:center;gap:14px;background:linear-gradient(180deg,#10121b,#0a0b10)}
header .brand{font-weight:700;letter-spacing:.5px;color:var(--gold);font-size:18px}
header .tag{color:var(--mut);font-size:12px}
nav{display:flex;flex-wrap:nowrap;gap:8px;padding:10px 22px;border-bottom:1px solid var(--line);background:var(--panel);overflow-x:auto;overscroll-behavior-inline:contain;scrollbar-width:thin}
nav a{font-size:12.5px;padding:4px 10px;border:1px solid var(--line);border-radius:999px;color:var(--mut)}
nav a:hover{border-color:var(--gold);color:var(--gold);text-decoration:none}
nav a.active{background:var(--gold);color:#0a0b10;border-color:var(--gold);font-weight:600}
main{max-width:1040px;margin:0 auto;padding:28px 22px 60px}
h1{font-size:26px;margin:0 0 4px;color:#fff}h2{font-size:18px;margin:28px 0 10px;color:var(--gold)}
.sub{color:var(--mut);margin:0 0 18px;font-size:13.5px}
.card{background:var(--panel);border:1px solid var(--line);border-radius:12px;padding:18px 20px;margin:14px 0}
.grid{display:grid;grid-template-columns:repeat(auto-fill,minmax(230px,1fr));gap:14px;margin:16px 0}
.grid a.tile{display:block;background:var(--panel2);border:1px solid var(--line);border-radius:12px;padding:16px;color:var(--ink)}
.grid a.tile:hover{border-color:var(--gold);text-decoration:none}
.grid a.tile .t{color:var(--gold);font-weight:600;margin-bottom:4px}.grid a.tile .d{color:var(--mut);font-size:12.5px}
table{width:100%;border-collapse:collapse;margin:12px 0;font-size:13.5px}
.table-wrap{width:100%;overflow-x:auto;overscroll-behavior-inline:contain;-webkit-overflow-scrolling:touch}
.table-wrap table{min-width:620px}
th,td{text-align:left;padding:8px 10px;border-bottom:1px solid var(--line);vertical-align:top}
th{color:var(--mut);font-weight:600;font-size:12px;text-transform:uppercase;letter-spacing:.4px}
code,pre{font-family:ui-monospace,SFMono-Regular,Menlo,monospace;font-size:12.5px}
pre{background:#0d0f17;border:1px solid var(--line);border-radius:10px;padding:14px;overflow:auto;color:#cdd3e3}
.pill{display:inline-block;padding:2px 9px;border-radius:999px;font-size:11.5px;font-weight:600}
.g{background:rgba(63,185,80,.15);color:var(--grn)}.a{background:rgba(210,153,34,.15);color:var(--amb)}.r{background:rgba(248,81,73,.15);color:var(--red)}.n{background:#1c2030;color:var(--mut)}
.note{border-left:3px solid var(--gold);padding:8px 14px;background:rgba(217,179,92,.06);color:#d8dbe6;font-size:13.5px;margin:14px 0;border-radius:0 8px 8px 0}
footer{border-top:1px solid var(--line);color:var(--mut);font-size:11.5px;padding:18px 22px;line-height:1.7}
.kbd{background:#1c2030;border:1px solid var(--line);border-radius:6px;padding:1px 7px;font-family:ui-monospace,monospace;font-size:12px}
.statline{display:flex;flex-wrap:wrap;gap:18px;align-items:center;font-size:13.5px}
.statline b{color:var(--ink)}
.tag2{display:inline-block;background:#1c2030;color:var(--mut);border:1px solid var(--line);border-radius:6px;padding:1px 7px;font-size:11px;margin-left:6px}
.st{color:var(--amb);font-weight:600}
@media(max-width:700px){
header{padding:12px 14px;align-items:flex-start;flex-direction:column;gap:2px}
nav{padding:9px 14px}
main{padding:20px 14px 44px}
h1{font-size:23px;line-height:1.25}
.card{padding:15px}
.statline{display:grid;grid-template-columns:1fr;gap:8px}
pre{white-space:pre-wrap;overflow-wrap:anywhere}
footer{padding:16px 14px}
}
</style> <link rel="stylesheet" href="/assets/szl-flow.css" data-szl-flow-asset="style" />
<link rel="stylesheet" href="/assets/szl-holo-v2.css" data-szl-holo-asset="style-v2" />
</head><body>
<header><span class="brand">a11oy</span><span class="tag">Brand Orchestration Layer · the one place to see everything</span></header>
<nav><a href="/hub">Hub</a><a href="/a11oy.code">a11oy.code</a><a href="/docs">Docs</a><a href="/pricing">Pricing</a><a href="/api-keys">API Keys</a><a href="/sdk">SDK</a><a href="/status">Status</a><a href="/hatun-mcp" class="active">Hatun-MCP</a><a href="/observability">Observability</a><a href="/security">Security</a><a href="/compliance">Compliance</a><a href="/cued-engagement">Cued Engagement</a><a href="/uds">UDS</a><a href="/counter-uas">Counter-UAS</a><a href="/evidence">Evidence</a><a href="/upgrades">Upgrades</a><a href="/audit">Audit</a><a href="/gap-report">Gap Report</a></nav>
<main>
<h1>Hatun-MCP — agentic MCP server</h1>
<p class="sub"><b>Hatun</b> (Quechua: <i>great / sovereign</i>) is the Model Context Protocol gateway for SZL capabilities. This page separates a reachable runtime declaration from execution and receipt evidence. A listed tool is not proof that it has run. Receipt and signer fields remain <b>UNKNOWN</b> or <b>UNAVAILABLE</b> until the read-only evidence endpoint observes an actual governed-run receipt.</p>
<div class="card">
<div class="statline">
<span>Live status: <span id="health"><span class="pill n">probing…</span></span></span>
<span>Signer: <b id="signer"></b></span>
<span>Khipu chain: <b id="chain"></b></span>
<span>Protocol: <b id="proto"></b></span>
<span>Probe latency: <b id="lat"></b></span>
</div>
<p class="sub" style="margin:12px 0 0">Runtime path: <code>/mcp/</code> (same origin) · Transport: JSON-RPC over HTTP (<code>POST /mcp/</code>). Availability, protocol revision, signer evidence, and receipt-chain evidence are populated only from successful reads below.</p>
</div>
<h2>Tools declared (<span id="toolcount"></span>) <span id="toolsource" class="pill a">STATIC FALLBACK</span></h2>
<p class="sub">The initial rows are an explicitly labelled static fallback. A successful <code>GET /mcp/</code> replaces them with the runtime-declared catalog. Neither state is execution proof.</p>
<div class="table-wrap"><table><thead><tr><th>Tool</th><th>Description</th><th>Evidence class</th></tr></thead><tbody id="tools"></tbody></table></div>
<h2>Organ mesh</h2>
<p class="sub">Same-origin map of Hatun to second brain, anatomy, ouroboros, and the formula codex. Labels are route presence. Second-brain readiness is whatever that endpoint reports this request.</p>
<div class="table-wrap"><table><thead><tr><th>Organ</th><th>Job</th><th>Surface</th><th>Label</th></tr></thead><tbody id="mesh"><tr><td colspan="4" class="sub">loading…</td></tr></tbody></table></div>
<h2>Recent invocations</h2>
<p class="sub">This bounded, ephemeral feed contains only summaries of governed agent runs for which this process actually created a receipt. It does not claim that every MCP discovery or tool call is signed, and reading it never mints a receipt.</p>
<div class="table-wrap"><table><thead><tr><th>Time (UTC)</th><th>Observed tool</th><th>Outcome</th><th>Receipt evidence</th></tr></thead><tbody id="inv"><tr><td colspan="4" class="sub">loading…</td></tr></tbody></table></div>
<h2>Connect a client</h2>
<div class="card">
<p style="margin:0 0 8px">Claude Desktop — deployment example using the <code>mcp-remote</code> bridge. Verify the target URL and authentication requirements in your environment before use:</p>
<pre>{
"mcpServers": {
"szl-a11oy": {
"command": "npx",
"args": ["-y", "mcp-remote", "/mcp/"]
}
}
}</pre>
<p class="sub" style="margin:8px 0 0">Same-origin checks: <code>GET /mcp/</code> for runtime discovery, <code>GET /api/hatun/evidence</code> for the no-mint evidence contract, and <code>GET /api/hatun/invocations</code> for observed receipt summaries. A public-key path alone is not proof that any receipt was signed.</p>
</div>
<div class="note">The page performs read-only same-origin probes. <code>GET /mcp/</code> supplies runtime declarations; <code>GET /api/hatun/evidence</code> supplies observed receipt state. Neither GET signs, appends, or upgrades evidence.</div>
<p class="sub">Source: <code>szl_agentic_loop.py</code> · read-only probes of <code>/mcp/</code> and <code>/api/hatun/evidence</code></p>
<script>
const BASE="";
const FALLBACK_TOOLS=[
{name:"retrieve_context",description:"Governance-corpus retrieval declaration"},
{name:"policy_check",description:"Deny-by-default policy declaration"},
{name:"trust_score",description:"Advisory trust-score declaration"},
{name:"sign_receipt",description:"Receipt-signing declaration"},
{name:"verify_receipt",description:"Receipt-verification declaration"}
];
function cell(text,tag){const el=document.createElement(tag||'td');el.textContent=text==null?'—':String(text);return el;}
function pill(text,cls){const el=document.createElement('span');el.className='pill '+cls;el.textContent=text;return el;}
function setStatus(id,text,cls){const host=document.getElementById(id);host.textContent='';host.appendChild(pill(text,cls));}
function paintTools(list,evidenceClass){const tb=document.getElementById('tools');tb.textContent='';
list.forEach(tool=>{const tr=document.createElement('tr');const name=cell(tool.name,'td');
const code=document.createElement('code');code.textContent=tool.name||'—';name.textContent='';name.appendChild(code);
tr.appendChild(name);tr.appendChild(cell(tool.description||tool.title||'No description reported'));
const status=cell('','td');status.appendChild(pill(evidenceClass,evidenceClass==='RUNTIME DECLARED'?'n':'a'));tr.appendChild(status);tb.appendChild(tr);});
document.getElementById('toolcount').textContent=list.length;}
paintTools(FALLBACK_TOOLS,'STATIC FALLBACK');
const t0=performance.now();
fetch(BASE+"/mcp/",{cache:'no-store'}).then(r=>r.json().then(j=>({r,j}))).then(({r,j})=>{
document.getElementById('lat').textContent=Math.round(performance.now()-t0)+' ms';
setStatus('health',r.ok?'REACHABLE':'HTTP '+r.status,r.ok?'g':'a');
document.getElementById('proto').textContent=j.protocolVersion||'UNKNOWN';
if(r.ok&&j&&Array.isArray(j.tools)){
paintTools(j.tools,'RUNTIME DECLARED');
const source=document.getElementById('toolsource');source.className='pill n';source.textContent='RUNTIME DECLARED';
}
}).catch(()=>{setStatus('health','UNAVAILABLE','r');document.getElementById('lat').textContent='UNAVAILABLE';});
fetch(BASE+"/api/hatun/evidence",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(e=>{
const signer=e&&e.signer||{};const chain=e&&e.receipt_chain||{};
document.getElementById('signer').textContent=signer.status==='OBSERVED_VERIFIED'?(signer.label||'OBSERVED_VERIFIED'):(signer.status||'UNKNOWN');
document.getElementById('chain').textContent=chain.status||'UNKNOWN';
}).catch(()=>{document.getElementById('signer').textContent='UNAVAILABLE';document.getElementById('chain').textContent='UNAVAILABLE';});
function paintEmptyInvocation(message){const tb=document.getElementById('inv');tb.textContent='';const tr=document.createElement('tr');
const td=cell(message,'td');td.colSpan=4;td.className='sub';tr.appendChild(td);tb.appendChild(tr);}
fetch(BASE+"/api/hatun/mesh",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(m=>{
const tb=document.getElementById('mesh'); if(!tb) return; tb.textContent='';
const organs=(m&&m.organs)||[];
if(!organs.length){const tr=document.createElement('tr'); const td=cell('UNAVAILABLE — mesh contract empty','td'); td.colSpan=4; td.className='sub'; tr.appendChild(td); tb.appendChild(tr); return;}
organs.forEach(o=>{const tr=document.createElement('tr');
const id=cell('','td'); const code=document.createElement('code'); code.textContent=o.id||'—'; id.appendChild(code); tr.appendChild(id);
tr.appendChild(cell(o.job||'—'));
const surf=cell('','td'); const a=document.createElement('a'); a.href=o.href||'#'; a.textContent=o.href||'—'; surf.appendChild(a); tr.appendChild(surf);
const lab=cell('','td'); lab.appendChild(pill(o.label||'UNAVAILABLE','n')); tr.appendChild(lab); tb.appendChild(tr);});
}).catch(()=>{const tb=document.getElementById('mesh'); if(!tb) return; tb.textContent=''; const tr=document.createElement('tr'); const td=cell('UNAVAILABLE — mesh contract could not be read','td'); td.colSpan=4; td.className='sub'; tr.appendChild(td); tb.appendChild(tr);});
fetch(BASE+"/api/hatun/invocations",{cache:'no-store'}).then(r=>r.ok?r.json():Promise.reject()).then(feed=>{
const items=feed&&Array.isArray(feed.items)?feed.items:[];const tb=document.getElementById('inv');tb.textContent='';
if(!items.length){paintEmptyInvocation('UNKNOWN — no governed-run receipt has been observed in this process.');return;}
items.slice(0,12).forEach(x=>{const tr=document.createElement('tr');tr.appendChild(cell(x.ts));
const tool=cell('','td'),code=document.createElement('code');code.textContent=x.tool||'—';tool.appendChild(code);tr.appendChild(tool);
const outcome=cell('','td');outcome.appendChild(pill(x.outcome||'UNKNOWN',x.outcome==='DENY'?'r':'a'));tr.appendChild(outcome);
const ev=cell('','td'),evCode=document.createElement('code');evCode.textContent=(x.signature_status||'UNKNOWN')+' · '+(x.receipt_hash||'').slice(0,16);ev.appendChild(evCode);tr.appendChild(ev);tb.appendChild(tr);});
}).catch(()=>{paintEmptyInvocation('UNAVAILABLE — the read-only invocation feed could not be read.');});
</script>
</main>
<footer>Doctrine v11 honesty boundary · tool catalog = runtime declaration, not execution proof · signer and receipt-chain state remain UNKNOWN or UNAVAILABLE until observed evidence exists · GET reads never mint receipts</footer>
<script src="/assets/szl-flow.js" defer data-szl-flow-asset="script"></script>
<script src="/assets/szl-holo-v2.js" defer data-szl-holo-asset="script-v2"></script>
</body></html>