REMOTE MCP SERVER · v3.2

The authority protocol for future agents.

ChatGPT, Codex, and compatible agents can identify their delegation chain, enforce risk, territory, rate, and reversibility limits, request human approval, and return a verifiable decision receipt.

https://kyvlt.com/api/mcp

Every agent identifies

A stable passport survives a model or provider change.

Authority narrows

A sub-agent can never exceed the root mandate or its delegation depth.

Every decision proves

A receipt binds the action, policy snapshot, and actor chain.

Available tools

Narrow tools reduce ambiguous authority and accidental activation.

draft_mandate

Define bounded authority without creating any real permission.

simulate_action

Test AUTHORIZED, CONFIRMATION_REQUIRED, or BLOCKED without acting.

verify_mandate_proof

Verify the public status and limits associated with a CLE-… proof code.

verify_action_receipt

Verify the agent chain and cryptographic fingerprints of a final decision.

get_profile

Identify the connected KYVLT profile through OAuth without asking for credentials.

create_mandate_for_review

Save an inactive mandate for the human owner to review and activate.

list_mandates

Read the connected profile’s mandates and limits without returning secret tokens.

list_agent_passports

Read stable declared agent identities, capabilities, and protocols.

list_pending_actions

View requests that are waiting for a human decision.

get_rights_summary

Read My Rights leads and missing document categories without exposing file contents.

prepare_rights_application

Prepare one My Rights case under an active owner mandate without external submission.

stage_assistant_action

Stage an exact Gmail or Google Calendar action without executing it.

list_ready_actions

Return only actions the human owner has already approved.

record_action_result

Record completed or failed only after a real external attempt.

revoke_mandate

Permanently revoke a mandate after explicit confirmation.

Safety rules

  • Private access uses OAuth 2.1, PKCE S256, short-lived access tokens, and rotating refresh tokens.
  • No tool asks for a password, cookie, payment detail, API key, or mandate token in chat.
  • A mandate created by an agent remains inactive until its owner reviews and activates it.
  • Staging an action never executes it. A provider is called only after approval.
  • My Rights returns pre-screening leads without guaranteeing eligibility or exposing vault contents.
  • KYVLT governs only agents and services that call its API or tools.
  • Self-declared passports are not represented as legal identity or third-party assurance.