{"_id":"@apatureai/bastion","_rev":"2-1bfc76ae89211d2b696c9b0b6d54d953","name":"@apatureai/bastion","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.1":{"name":"@apatureai/bastion","version":"0.1.1","author":{"name":"Aditya Prathapa"},"license":"MIT","_id":"@apatureai/bastion@0.1.1","maintainers":[{"name":"aprathapa","email":"aprathapa01@gmail.com"}],"homepage":"https://github.com/apatureai/bastion#readme","bugs":{"url":"https://github.com/apatureai/bastion/issues"},"bin":{"mcp-review":"dist/review-cli.js","mcp-review-local":"dist/local-stdio.js","mcp-review-server":"dist/boot.js"},"dist":{"shasum":"6e4d63df05dfb19cda92e81f0da223f96a5d09da","tarball":"https://registry.npmjs.org/@apatureai/bastion/-/bastion-0.1.1.tgz","fileCount":169,"integrity":"sha512-/e00BG4FSJtiR3ijSp7TJn29L4tIfok6OJlMmFSdI7OGcjDAcOBahPw0tE7NZEZzbCr3zx+/eVo8mTSt1oYYAw==","signatures":[{"sig":"MEUCIQDe8U9JS7W/RKhB2q3o9dwBUgn/g+hFG7paJmRORQ/oBQIgYVZs50JZ9nXofwSCUKLsyftoZLhgE/TSYc+lorE2k/g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":606168},"main":"./dist/index.js","type":"module","_from":"file:apatureai-bastion-0.1.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","start":"node dist/boot.js"},"_npmUser":{"name":"aprathapa","email":"aprathapa01@gmail.com"},"_resolved":"/tmp/e40f8163b248450a7240837b73bea8e0/apatureai-bastion-0.1.1.tgz","_integrity":"sha512-/e00BG4FSJtiR3ijSp7TJn29L4tIfok6OJlMmFSdI7OGcjDAcOBahPw0tE7NZEZzbCr3zx+/eVo8mTSt1oYYAw==","repository":{"url":"git+https://github.com/apatureai/bastion.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"11.17.0","description":"Apature Bastion server: agent-facing MCP tools (design_review, design_review_get) over the Verdict review surface.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"pg":"^8.16.3","zod":"^4.4.3","jose":"^6.2.3","@apatureai/bastion-types":"0.1.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","@types/pg":"^8.15.4","ajv-formats":"^3.0.1","@electric-sql/pglite":"^0.5.4"},"_npmOperationalInternal":{"tmp":"tmp/bastion_0.1.1_1787613602662_0.48438160956368725","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@apatureai/bastion","version":"0.1.2","mcpName":"io.github.apatureai/bastion","description":"Apature Bastion server: agent-facing MCP tools (design_review, design_review_get) over the Verdict review surface.","license":"MIT","author":{"name":"Aditya Prathapa"},"repository":{"type":"git","url":"git+https://github.com/apatureai/bastion.git","directory":"packages/mcp-server"},"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"publishConfig":{"access":"public"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","jose":"^6.2.3","pg":"^8.16.3","zod":"^4.4.3","@apatureai/bastion-types":"0.1.2"},"devDependencies":{"@electric-sql/pglite":"^0.5.4","@types/pg":"^8.15.4","ajv":"^8.17.1","ajv-formats":"^3.0.1"},"bin":{"bastion":"dist/local-stdio.js","bastion-local":"dist/local-stdio.js","bastion-server":"dist/boot.js","bastion-review":"dist/review-cli.js"},"scripts":{"test":"vitest run","start":"node dist/boot.js"},"_id":"@apatureai/bastion@0.1.2","bugs":{"url":"https://github.com/apatureai/bastion/issues"},"homepage":"https://github.com/apatureai/bastion#readme","_integrity":"sha512-2ErHCTrDUzsuHwUd7X/R9KiGOee3xysiKqFRnWutAjS1/bTF+lU3Vj22ZRRZhMUfCRSeAQuSX4gZcS354AaX5A==","_resolved":"/tmp/df174d438e0ce487d0f58e68358dca40/apatureai-bastion-0.1.2.tgz","_from":"file:apatureai-bastion-0.1.2.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-2ErHCTrDUzsuHwUd7X/R9KiGOee3xysiKqFRnWutAjS1/bTF+lU3Vj22ZRRZhMUfCRSeAQuSX4gZcS354AaX5A==","shasum":"aa3f11156db7796faf35beb155e68a56f4125f34","tarball":"https://registry.npmjs.org/@apatureai/bastion/-/bastion-0.1.2.tgz","fileCount":169,"unpackedSize":606707,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIElimTSzAzUF3sDVSylEMfWW2Ln82jdnlhL3kskpS7WLAiANfjdQq3Or+2KWKqq8+qX6zG+eke2nAsnFpxIwrDtAaQ=="}]},"_npmUser":{"name":"aprathapa","email":"aprathapa01@gmail.com"},"directories":{},"maintainers":[{"name":"aprathapa","email":"aprathapa01@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bastion_0.1.2_1787620237891_0.3301017633150507"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-24T23:20:02.562Z","modified":"2026-08-25T01:10:38.254Z","0.1.1":"2026-08-24T23:20:02.819Z","0.1.2":"2026-08-25T01:10:38.053Z"},"bugs":{"url":"https://github.com/apatureai/bastion/issues"},"author":{"name":"Aditya Prathapa"},"license":"MIT","homepage":"https://github.com/apatureai/bastion#readme","repository":{"type":"git","url":"git+https://github.com/apatureai/bastion.git","directory":"packages/mcp-server"},"description":"Apature Bastion server: agent-facing MCP tools (design_review, design_review_get) over the Verdict review surface.","maintainers":[{"name":"aprathapa","email":"aprathapa01@gmail.com"}],"readme":"# @apatureai/bastion\n\nThe [Apature Bastion](https://github.com/apatureai/bastion) server: an in-loop, read-only design-review MCP server for coding agents. It exposes five agent-facing tools (`design_review`, `design_review_get`, `design_recheck`, `design_review_cancel`, `design_review_panel_action`) over two transports — a local stdio server that runs with no credentials, and a Streamable HTTP edge with OAuth 2.1 resource-server auth, per-tenant Postgres state, and submit-and-poll jobs. It judges and verifies a rendered UI; it never edits code.\n\nWith nothing configured the judgments come from a fixture and every review is stamped `provenance.model_backed: false`. Set `VERDICT_CLI` to a built [apatureai/verdict](https://github.com/apatureai/verdict) checkout and the same server reviews your page for real.\n\n## Install\n\n```bash\nnpm install @apatureai/bastion\n```\n\n## Usage\n\nThe package ships four binaries. `bastion` is the default: `npx -y @apatureai/bastion`\nlaunches the local stdio MCP server, which is what an MCP client spawns.\n\n| Binary | What it is |\n|---|---|\n| `bastion` | default entrypoint; an alias for `bastion-local` so bare `npx @apatureai/bastion` just works |\n| `bastion-local` | the local stdio MCP server (fixture engine unless one is configured) |\n| `bastion-review` | one-shot review of a URL through the configured backend |\n| `bastion-server` | the production Streamable HTTP composition root (needs a database, issuer, and engine) |\n\nRegister the local server with any stdio MCP client:\n\n```json\n{\n  \"mcpServers\": {\n    \"apature-review-local\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@apatureai/bastion\"]\n    }\n  }\n}\n```\n\nOr compose the pieces directly:\n\n```ts\nimport { createLocalReviewServer } from \"@apatureai/bastion\";\n\nconst server = createLocalReviewServer(); // fully offline, fixture judgments\n```\n\n## Reviewing a target\n\nTargets must be https, with one exception: a loopback dev host (`localhost`, `127.0.0.0/8`, `::1`) may be plain http, so a coding agent can review its own local dev server in-loop. Every other host keeps the full SSRF boundary — https only, no IP literals, ownership-verified allowlist, and egress classification with DNS-rebind rejection — so a public name that merely resolves to a private or loopback address is still refused.\n\n## Configuration, the SSRF boundary, the OAuth edge, and running a real backend\n\nare all documented in the [bastion repository README](https://github.com/apatureai/bastion#readme), including a no-credentials quickstart (`pnpm demo`) and how to point the server at a live judgment engine.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}