{"_id":"@aiko-systems/mcp","_rev":"10-e94e1b082c1bae89ef348c903e7f4d94","name":"@aiko-systems/mcp","dist-tags":{"latest":"0.2.9"},"versions":{"0.2.0":{"name":"@aiko-systems/mcp","version":"0.2.0","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.0","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"60932ec6180715f04b2d7924cd699dbc48a898d2","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.0.tgz","fileCount":6,"integrity":"sha512-TIi0GSXn8iZTH+6JaFEpMngGk3pEvDVanktxbiWtaH1838sEGWEmfQob7Ol2qYI1gx1cDLuiNx+9oR7nSx22zQ==","signatures":[{"sig":"MEUCIFHkiRr7/XNEI3LutbX++rNDbu8K+9QXJH2Zmqt6Rr/8AiEA6SiDfTGUPpA8WNP2DbWmsVjmJ7ceNlXxsF/EpzhiA2s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41416},"type":"module","engines":{"node":">=20"},"gitHead":"18184068cb644b503a0a87d82cfd413289181f32","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server — gives your coding agent scoped, contract-backed design-system context for patching an existing artefact (getContextBundle), then verifies the patch (verifyPatch). Two transports: local engine CLI, or a hosted Aiko gateway (AIKO_GATEWAY_U","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0_1786985081431_0.875573593854021","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@aiko-systems/mcp","version":"0.2.1","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.1","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"858ff536fa85dd89b722d3dfcc0cb352d58b0e07","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.1.tgz","fileCount":7,"integrity":"sha512-Wmbr3o4Ol+Y/5oyb0QiAuTmKPkyabY8xr878BpTRMbI9l3DaP9Stguf/7htDn9Wlb69nxKSn8Ff43x07zbdrKw==","signatures":[{"sig":"MEUCIGYtVO/0KrS5Ejbw+QxHDW8H4alFRaFozWMIxUsoGaSfAiEA6FfcRr493V4W1oaGC/+/bAet5WzuijfbDNX0XQAjc9c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45983},"type":"module","engines":{"node":">=20"},"gitHead":"29fe5e656bdc2aa486ffb96bd1ea4bea699b170d","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server — gives your coding agent scoped, contract-backed design-system context for patching an existing artefact (getContextBundle), then verifies the patch (verifyPatch). Two transports: local engine CLI, or a hosted Aiko gateway (AIKO_GATEWAY_U","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.1_1786985563043_0.8921230178488657","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@aiko-systems/mcp","version":"0.2.2","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.2","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"1de03c0b53f9956e04b447c1a1df28cc186a80d7","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.2.tgz","fileCount":7,"integrity":"sha512-BqAg9ej0jTXyglsIN2Q457aGXEN0lCeFEk6/R1Uj2AcgW7YeyFanZKSJd64W+voyhiz9lk7WRlpUI5XwR9BSWg==","signatures":[{"sig":"MEUCID3OMq//mrlSRyg5tR+e9doLiapF28uX359ueCkMB3sLAiEAm5xLVkZhqIVXHgEmI2KFPUF2thkia5GSibmhs158SAA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":46961},"type":"module","engines":{"node":">=20"},"gitHead":"e5ccb230003e83c0f60d2451367c1f0846c5c580","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server — gives your coding agent scoped, contract-backed design-system context for patching an existing artefact (getContextBundle), then verifies the patch (verifyPatch). Two transports: local engine CLI, or a hosted Aiko gateway (AIKO_GATEWAY_U","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.2_1786991852876_0.9437723177601443","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@aiko-systems/mcp","version":"0.2.3","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.3","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"118cdd63247d6dd205ee85a7a2e11fcb03332361","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.3.tgz","fileCount":8,"integrity":"sha512-YvTiRBTGX9kW9Ps+mLShsgNKCDxNfSVw+I91C4a364mAT0EOD6GmW7yLBUWaHiFZxalBRIbAHOV3sflqhWYoKQ==","signatures":[{"sig":"MEQCIDTuoIOrHQwW6VGsxrihOdzNU6biT1B6gnLW+Gg3jmfPAiBkZXQhxivJCVyrE2jr4M3DYGIAbYv+3Mhrdho8iLNcZA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67959},"type":"module","engines":{"node":">=20"},"gitHead":"3c2afa6245a876fd79f91ffbd97cc3780d8af8a8","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.3_1787643748171_0.4748594227633294","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@aiko-systems/mcp","version":"0.2.4","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.4","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"33aab8e5609a6db88a91007116e71f019d557b75","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.4.tgz","fileCount":8,"integrity":"sha512-8NYNXLcmZcdq9gVmRPkarapiXfILDZu1WA3sEdV9oteawRSzLRUjcsmJUSlE7+2d/zM1C/8cuMBbe0OS98SW4g==","signatures":[{"sig":"MEQCIBazQC9JjoZSZT8C09gkh9cEIm+owxFL388iYp5CyQKzAiBoiEFhU01EnD62Li2hZDsSiMMvVklU4wr+dWFmJ/Ycsw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":69877},"type":"module","engines":{"node":">=20"},"gitHead":"596a82f247b416da2e4f9b9665faf9f872e04a56","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.4_1787669904983_0.18164443812555153","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@aiko-systems/mcp","version":"0.2.5","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.5","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"6b150964be3832b85c68e02fb8dde18800c7ce62","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.5.tgz","fileCount":8,"integrity":"sha512-/crVMpdVdNrI0l3MHIM26dMYWsOas4hXiuWDvkUc1lbMScRVTLMz31caiL29oyKw0wLixgVBeObbTja6298lZA==","signatures":[{"sig":"MEUCIQDVmv4VSE0yoqKPaEaX3GzBLYEB4397N8aIGyUdH0htxQIgOshHxT1/n+h7BaOj20U2RuCkth379W2sivYdTj5FI7c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71953},"type":"module","engines":{"node":">=20"},"gitHead":"299164c447493506eb17c5bd398ee7c6f92e3865","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.5_1787672280806_0.6955011777459068","host":"s3://npm-registry-packages-npm-production"}},"0.2.6":{"name":"@aiko-systems/mcp","version":"0.2.6","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.6","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"035af47ac5f6a48db7d2ab1bd4643f96dfdbeeb0","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.6.tgz","fileCount":8,"integrity":"sha512-LaccAloJvkvbvfT/wIvcrchJZm86I06vfetvggkLF16+KLDxy+JmjNdHFofJjHfEuA6SKgKgnmoRKmdYNFYEnw==","signatures":[{"sig":"MEUCICBKR9WVqZALEbJ9PFoSDvBo07GBM4xP5wq0a1HXK76qAiEAkI7IWE9K49gZJcEV1jfhKNNpGQ5dH2/x6umg3pwbnoo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89639},"type":"module","engines":{"node":">=20"},"gitHead":"7f7ea61c58582899e0ba448259f30f977da5fe6f","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.6_1787748382089_0.31492189613273713","host":"s3://npm-registry-packages-npm-production"}},"0.2.7":{"name":"@aiko-systems/mcp","version":"0.2.7","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.7","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"60996c266ab969e5a13eafd33aef77967c48c89d","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.7.tgz","fileCount":8,"integrity":"sha512-m+mSuLu8F91wGa1Fw4ICTNHS3MpUZIoEeTnIUnXalCZiLXF5HAQWlfH7fGkliLrAd2U7Ti+GR7zruG9MQsAI1A==","signatures":[{"sig":"MEYCIQDSNEPiLTvhcStx233Wjry/g8WiZVB/UgpSO/LO9tcW2QIhAMQwwdQN29ykCeZ3pSPXJ8kValtqGCxdNifhzmLf5X6P","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":92071},"type":"module","engines":{"node":">=20"},"gitHead":"5bc533c04c921114c189995932338c740d2c7d5f","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.7_1787749797333_0.594301270668673","host":"s3://npm-registry-packages-npm-production"}},"0.2.8":{"name":"@aiko-systems/mcp","version":"0.2.8","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"license":"MIT","_id":"@aiko-systems/mcp@0.2.8","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"d50c19b6c64a32d72f5e472de7818085da1d8972","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.8.tgz","fileCount":8,"integrity":"sha512-EmygAUnfuxxDQEENn34E+2iG5iUFN1NQfYJDZLaKw6b+LRYVYw+Qj1nHexbkleORltOeHU9rF9LrvMiiPiHjxQ==","signatures":[{"sig":"MEUCIQCoa/3qE1KILh15RehtThI+r6JEqD2ejqE3t1xQemXyuwIgJy9nd9Fog5wiZuOxaCZ2Oucwrkvzmv2MuBrfphddRGE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDxowQefa1wfPcuy6TeTpriHRA1LvX38vk0SmGCMvmWxwIhAPDDReuCFVOdUo5a0jK1wJPaZED6cap8e3onx3mbElsV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":107299},"type":"module","engines":{"node":">=20"},"gitHead":"595607c56e4dd6d07f5a6e0bf916d839b9214a4a","scripts":{"test":"node --test","start":"node server.mjs"},"_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@posthog/mcp":"0.12.0","posthog-node":"5.51.4","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.8_1789578471845_0.4162531358651671","host":"s3://npm-registry-packages-npm-production"}},"0.2.9":{"_id":"@aiko-systems/mcp@0.2.9","bin":{"aiko-mcp":"server.mjs"},"dist":{"shasum":"a2d865a731a390d83f53c484325eaf0562306831","tarball":"https://registry.npmjs.org/@aiko-systems/mcp/-/mcp-0.2.9.tgz","fileCount":8,"integrity":"sha512-QBdlE/QKRzSV8l87k+ikYiJQqjsL/Nr3Eplq3trRpsozVppVuMJWrIsWCHuYaZhyDMqW66hXtdCiaUhJ0EXHCA==","signatures":[{"sig":"MEQCIHkeYqSAgUr4cVhYp8diwIGFLgekh+EmlsixIVaNfqQCAiAlwFVvBP4sNV7E+3gk0qgFbtCJozJgcyh+9sYTav8DdQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAiQPaKH5e1jmYPVruBqsDQToazFH28jx7ua1D+ti8suAiBU79pEpf5h142Qud1jffS3TLShpLwJhoQmFlM0YLCX4w=="}],"unpackedSize":108888},"name":"@aiko-systems/mcp","type":"module","engines":{"node":">=20"},"gitHead":"40e6de14cfcede17ef508288b8e006b0e0a03671","license":"MIT","scripts":{"test":"node --test","start":"node server.mjs"},"version":"0.2.9","_npmUser":{"name":"aiko-systems","email":"daniel@aiko.systems"},"keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"_npmVersion":"11.1.0","description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","directories":{},"maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.0","@posthog/mcp":"0.12.0","posthog-node":"5.51.4","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.2.9_1789663767456_0.8976752136739519"}}},"time":{"created":"2026-08-17T16:44:41.193Z","modified":"2026-09-17T16:49:27.693Z","0.2.0":"2026-08-17T16:44:41.580Z","0.2.1":"2026-08-17T16:52:43.218Z","0.2.2":"2026-08-17T18:37:33.035Z","0.2.3":"2026-08-25T07:42:28.299Z","0.2.4":"2026-08-25T14:58:25.136Z","0.2.5":"2026-08-25T15:38:00.967Z","0.2.6":"2026-08-26T12:46:22.226Z","0.2.7":"2026-08-26T13:09:57.504Z","0.2.8":"2026-09-16T17:07:51.934Z","0.2.9":"2026-09-17T16:49:27.554Z"},"license":"MIT","keywords":["mcp","design-system","aiko","verification","claude-code","cursor"],"description":"Aiko MCP server for scoped, contract-backed design-system context and verification. Supports local engine, OAuth-hosted MCP, and legacy static-bearer gateway transports.","maintainers":[{"name":"aiko-systems","email":"daniel@aiko.systems"}],"readme":"# @aiko-systems/mcp — the Aiko MCP server for coding agents\n\nGive your coding agent (Claude Code, Cursor, or any MCP client) scoped, contract-backed\ndesign-system context for patching an **existing** artefact, then let Aiko verify whether the patch\nstayed inside the system. Two calls carry the whole loop:\n\n1. **`getContextBundle`** — read-only task context: the current artefact slice, resolved effective\n   contracts for the seed components, the tokens you may bind, edit scope, preservation obligations,\n   forbidden changes, pre-existing findings (advisory), and the verification plan.\n2. **`verifyPatch`** — the trust report: pass / design-drift / unknown, with what drifted (+ repair\n   hints), what the patch fixed (credited), what was already broken (never blamed on the patch), a\n   4-way diff-scope classification, and explicit gate coverage (ran vs not run).\n\nBoth are free and deterministic — no model call, no mutation. Aiko asks for scope when it lacks it;\nit does not guess.\n\n## Customer workflow\n\nChoose the lane before calling a tool:\n\n1. In local mode, call `listModules` before supplying an ingestion `targets` value. Use a returned\n   module id, not a guessed framework/family name such as `react`. Hosted MCP does not expose\n   module enumeration; omit optional `targets` there unless an operator supplied a registered id.\n2. For a known canonical component, call `getContext` for questions. For an edit through hosted\n   Aiko, call `getContextBundle` with that component in `seedComponents` and either the changed line\n   range or its symbol, then call `verifyPatch` after the edit. Hosted Aiko refuses an incomplete\n   component scope rather than guessing. The engine's direct/local file-only bundle path remains for\n   source that is not yet canonical; its component-scoped contract gates report `unknown`, not a\n   clean pass.\n3. For a component or token source that Aiko does not yet represent, call `proposeIngestion`.\n   A genuinely new canonical instance remains a pending, human-approved apply; only reuse-only,\n   no-review deltas may be applied automatically.\n\nDo not add an `aiko:realizes` comment before ingestion. Ingestion records source provenance; the\nstamp is the durable back-link for a realized artifact. A later `verifyPatch` may ask you to add it\nto a hand-authored or ingested file, using its exact repair hint.\n\n## Install — hosted Aiko\n\nYour agent starts a local stdio bridge that reads only the files you explicitly pass to the hosted\nendpoint. The bridge is the repository boundary; the hosted service never runs a command on your\nmachine or receives an absolute local path.\n\n**Claude Code** (`.mcp.json` in your repo, or `~/.claude.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"aiko\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiko-systems/mcp@0.2.9\"],\n      \"env\": {\n        \"AIKO_MCP_URL\": \"https://mcp.aiko.systems/mcp\",\n        \"AIKO_OAUTH_ISSUER\": \"https://app.aiko.systems\",\n        \"AIKO_WORKSPACE\": \"your-workspace-id\",\n        \"AIKO_LOCAL_REPO\": \"/absolute/path/to/your/repository\"\n      }\n    }\n  }\n}\n```\n\n**Cursor** (`.cursor/mcp.json`): same block under `mcpServers`.\n\nNotes for hosted mode:\n\n- The one-time setup prompt generated in Observatory is already browser-approved, so its login\n  command completes immediately without opening a second browser window. To connect manually or\n  reconnect later, run `npx -y @aiko-systems/mcp@0.2.9 login` with the same connection values. It\n  opens your default browser for the OAuth 2.1 authorization-code + PKCE flow and prints the URL\n  as a manual fallback. Set `AIKO_MCP_NO_BROWSER=1` for a headless terminal. The bridge stores only\n  a rotating user credential in `~/.config/aiko/mcp-oauth.json` with mode 600.\n- `AIKO_LOCAL_REPO` is required before the bridge will read a file. It resolves symlinks, refuses\n  paths outside that repository, hidden paths, credentials, and non-source/non-document file\n  types, then sends bounded inline content and a repository-relative locator to the hosted endpoint.\n- Hosted mode exposes `ping`, context, verification, drift reporting, ingestion proposals, and\n  agent-assisted projection discovery. For an existing canonical component, use\n  `listProjectionSurfaces` → `getContext` → write the local artifact with the exact\n  `aiko:realizes` stamp supplied by context → run the local typecheck → `verifyArtifact` with its\n  bounded `buildResult` → `recordVerifiedRealization`. The final step writes Aiko's receipt only\n  when the supplied bytes, lineage stamp, and local build result pass; it never writes or commits\n  customer code. A target with no contract remains `not-verified` and must not be recorded.\n  The local bridge submits one bounded source file from `AIKO_LOCAL_REPO`; Aiko funds the model\n  reconcile, applies per-user/IP/workspace limits and the workspace monthly cap, and returns a\n  reviewable delta. Graph apply remains an approval-gated operator flow. Compile commands are\n  never accepted by hosted mode; only the local agent's capped pass/fail receipt is accepted.\n- Figma is intentionally not a code target in that loop. Aiko has **no** Figma Desktop plugin and\n  cannot install, open, or control one. A Figma write is an operator handoff that requires the\n  separately configured **Figma Console MCP**, with its Desktop Bridge plugin running in Figma\n  Desktop and connected to the intended file. An agent must use Figma Console's own\n  `figma_execute` or purpose-built write tool only after that independent connection is\n  available; Aiko's `listProjectionSurfaces` reports these prerequisites rather than claiming it\n  can drive the bridge.\n\n## Install — local mode (self-hosted / development)\n\nThe server bridges to the `aiko <command> --json` CLI on this machine. Requires Ruby, the\n`aiko-graph/` engine, and a workspace.\n\n```json\n{\n  \"mcpServers\": {\n    \"aiko\": {\n      \"command\": \"node\",\n      \"args\": [\"/abs/path/to/aiko-graph/mcp/server.mjs\"],\n      \"env\": { \"AIKO_WORKSPACE\": \"your-workspace-id\" }\n    }\n  }\n}\n```\n\n(Or `AIKO_GRAPH_ROOT=/abs/path/to/workspace/state`.) All 12 tools are available locally, including\nthe paid/mutating ingestion tools — which stay approval-gated by the engine itself.\n\n## The compile (build) gate — operator CLI only\n\nNo MCP transport executes compile commands, repository configuration, package scripts, or build\nauto-detection. MCP verification reports the build gate as `not-run`; this keeps tools marked\nread-only from becoming a local command-execution surface. Run a build gate as an explicit operator\naction through `aiko verify` or `aiko verify-patch run` instead.\n\nThe human-operated CLI resolves its command in this order:\n\n1. `--compile \"<cmd>\"` (per call)\n2. `AIKO_COMPILE_CMD` env\n3. `.aiko/config.json` in your repo root: `{ \"compileCmd\": \"npm run typecheck\" }`\n4. auto-detect: a `package.json` `typecheck` (then `build`) script → `npm run <script>`;\n   else a `tsconfig.json` → `npx tsc --noEmit -p tsconfig.json`\n\nWith no command resolvable the CLI reports `not-run` and, if no other deterministic gate ran, the\nverdict is `not-verified`, never a hollow pass.\n\n## Tools\n\n| Tool | Remote | Notes |\n|---|---|---|\n| `ping` | ✓ | Connectivity health-check — call once after setup, or any time before relying on the others. Free, no side effects. |\n| `getContextBundle` | ✓ | THE patch-task context object. A rejected scope returns its outcome + actionable reasons as data. |\n| `verifyPatch` | ✓ | The trust report. Design-drift is a normal report, not an error. |\n| `getContext` | ✓ | Per-component context (approved parts/props, obligations, token constraints, projection loss). |\n| `auditComponent` | ✓ | Check a component's current code against its contract without a diff. |\n| `reportDrift` | ✓ | The current AikoReport proof object. |\n| `verifyArtifact` | ✓ | Component-level gate suite against bounded inline content. |\n| `listProjectionSurfaces` | hosted | Supported destination surfaces for customer-agent projection. |\n| `recordVerifiedRealization` | hosted | Re-verifies a stamped artifact with a passing local build receipt, then writes provenance. |\n| `provisionOraclePackage` | ✓ | Installs one engine-pinned package required by the selected surface oracle; no arbitrary package input. |\n| `proposeIngestion` | ✓ | Aiko-funded model reconcile for one bounded local source; returns a delta to review, mutates nothing. |\n| `validateIngestionDelta` | local | Free, non-mutating. |\n| `applyApprovedDelta` | local | **MUTATING** — refuses without an engine-validated approval file. |\n| `recordRealization` | local | Small provenance write. |\n\n## Design: conformance-first, ops delegated\n\nThis is a thin MCP server over three transports (`bridge.mjs`):\n\n```\nhosted:  agent ──MCP──> aiko-mcp ──HTTPS (OAuth bearer, /mcp)──> Observatory ──internal──> Aiko Engine\nlegacy:  agent ──MCP──> aiko-mcp ──HTTPS (static bearer, /api/w/<workspace>/…)──> Aiko Engine API Gateway\nlocal:   agent ──MCP──> aiko-mcp ──exec──> aiko <cmd> --json ──> Aiko::* engine\n```\n\nHosted mode applies user membership and billing checks per request, tool scopes, OAuth token\nrotation/reuse detection, origin validation, payload limits, and audit records. The legacy static\nbearer mode remains only for existing pilot installations while they migrate. Legacy\n`AIKO_GATEWAY_URL` must use HTTPS except for literal loopback development hosts; non-loopback use\nrequires both `AIKO_WORKSPACE` and `AIKO_TOKEN`, refuses redirects, and uses a bounded request\ntimeout. Any legacy tool that reads a local file also requires `AIKO_LOCAL_REPO` and applies the\nsame realpath containment, sensitive-file, extension, binary, and size policy as hosted OAuth.\n\n## Files + verify\n\n- `server.mjs` — `createServer()` registers the tools over `StdioServerTransport`.\n- `tools.mjs` — the 12 tool definitions (zod schemas + per-transport dispatch).\n- `bridge.mjs` — local `bridge()`/`runTool()`, hosted OAuth `runHostedTool()`, and legacy gateway\n  dispatch.\n- `hosted-auth.mjs` — OAuth PKCE login, refresh, and user-only credential storage for the local\n  bridge.\n- `test/tools.test.mjs` — local round-trip against a real engine workspace.\n- `test/remote.test.mjs` — remote dispatch against a fake gateway (paths, auth header, A1c content\n  shipping, honest refusals, unreachable-gateway errors).\n\n```sh\nnpm test                      # both suites; local tests need AIKO_GRAPH_ROOT pointing at a workspace\nruby ../test/run.rb           # engine suite (gateway routes incl. /api/context/get + hosted posture)\n```\n\nPublishing: the package is public under the Aiko-owned `@aiko-systems` scope. Installer output pins\nthe reviewed package version; update that pin only when publishing a tested release.\n","readmeFilename":"README.md"}