{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.zapsoblige-hash/policyvault","description":"Non-custodial Kaspa policy enforcement for AI agents; signers retain custody.","repository":{"url":"https://github.com/zapsoblige-hash/PolicyVault","source":"github"},"version":"1.6.2","packages":[{"registryType":"npm","identifier":"policyvault-mcp","version":"1.6.2","transport":{"type":"stdio"},"environmentVariables":[{"description":"Bare origin of the PolicyVault server (e.g. https://app.policy-vault.org, or your self-hosted origin). Refused if it embeds credentials or a path.","isRequired":true,"format":"string","name":"POLICYVAULT_MCP_SERVER_URL"},{"description":"Machine-identity bearer credential (pvmk_...), minted by the vault operator in the PolicyVault app with exactly the scopes the agent should hold. Never logged; deleted from the process environment after being read.","isRequired":true,"format":"string","isSecret":true,"name":"POLICYVAULT_MCP_TOKEN"},{"description":"Optional comma-separated scope list to narrow which tools are advertised (display-side only; enforcement is always server-side).","format":"string","name":"POLICYVAULT_MCP_SCOPES"}]}],"_meta":{"io.modelcontextprotocol.registry/publisher-provided":{"authorityStatement":"AI MAY REQUEST. POLICYVAULT DETERMINISTICALLY DECIDES. THE COVENANT ENFORCES. SIGNERS RETAIN CUSTODY.","custody":"This server holds no keys, signs nothing, broadcasts nothing. Every tool call is an ordinary authenticated HTTP request subject to server-side tenancy, scope, governance, risk, and covenant decisions.","protocolRevisions":["2025-11-25","2025-06-18"]}}},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-15T02:31:19.606561Z","publishedAt":"2026-09-15T02:31:19.606561Z","updatedAt":"2026-09-15T02:31:19.606561Z","isLatest":true}}}
