{"_id":"@artifacta-mcp/mcp","_rev":"6-35bc88ba5a58cb5ba0e2b0d58137f664","name":"@artifacta-mcp/mcp","dist-tags":{"latest":"1.0.4"},"versions":{"0.1.0":{"name":"@artifacta-mcp/mcp","version":"0.1.0","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","_id":"@artifacta-mcp/mcp@0.1.0","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"homepage":"https://artifacta.io","bugs":{"url":"https://github.com/sagapeak/artifacta/issues"},"bin":{"artifacta-mcp":"dist/cli.js"},"dist":{"shasum":"2bd4e484cf532fe9fcbb8028f2a77dd6b531036a","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-0.1.0.tgz","fileCount":72,"integrity":"sha512-im3YoEz3GA8DmP6lh4R3ZNEQPNyvQ6Ufdm9e5fs1NHlZ4I7SeMV0fyeh8kF/3+HMPlw4KesMoBeIdMG9Tmn0EA==","signatures":[{"sig":"MEUCIH8NmXjVsx5lLHPrRMQ3C/mJX5cxMoNBrux2uDiANPhxAiEA7OwXk/WMwY3QOtBBB/xFSSAjxBkiQAhFGmqNJjAsaLs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":168185},"main":"./dist/server.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"cfb7468ba377874dd4131b9bdc470e191dcd00fb","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build","test:integration":"vitest run --config vitest.integration.config.ts"},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"repository":{"url":"git+https://github.com/sagapeak/artifacta.git","type":"git","directory":"mcp/typescript"},"_npmVersion":"10.8.2","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","directories":{},"_nodeVersion":"20.20.2","dependencies":{"undici":"^7.25.0","smol-toml":"^1.6.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.19.0","vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1779679850539_0.8262257294376671","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@artifacta-mcp/mcp","version":"0.2.0","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","_id":"@artifacta-mcp/mcp@0.2.0","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"homepage":"https://artifacta.io","bugs":{"url":"https://github.com/sagapeak/artifacta/issues"},"bin":{"artifacta-mcp":"dist/cli.js"},"dist":{"shasum":"29b5d288a1442a4286c5d36ce04fd9e7104941b0","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-0.2.0.tgz","fileCount":92,"integrity":"sha512-SKfNGcIlt9bMI/61CjML1xvvglBpZzfvbAdHnWvXwQShkutPimzSEcIUV4c4b1i5Rg2K4lAN5CS0dSZPHrtqhQ==","signatures":[{"sig":"MEUCICm4rldQsq8z6Nxg176JDhTwK6eRWcmy8QHnb4KFqH4IAiEAlyGJfO4JXhZGa638BN3fN+DhHQbFsQKy1dLMk/kaA/k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":260674},"main":"./dist/server.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"9ab1d396f11383224d6aaaac81bda25f3677cef6","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","secret-audit":"tsx scripts/secret-audit.ts","prepublishOnly":"npm run build","test:integration":"vitest run --config vitest.integration.config.ts"},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"repository":{"url":"git+https://github.com/sagapeak/artifacta.git","type":"git","directory":"mcp/typescript"},"_npmVersion":"10.8.2","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","directories":{},"_nodeVersion":"20.20.2","dependencies":{"undici":"^7.25.0","smol-toml":"^1.6.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.19.0","vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0_1779779646022_0.4359800805333822","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@artifacta-mcp/mcp","version":"1.0.0","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","_id":"@artifacta-mcp/mcp@1.0.0","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"homepage":"https://artifacta.io","bugs":{"url":"https://github.com/sagapeak/artifacta/issues"},"bin":{"artifacta-mcp":"dist/cli.js"},"dist":{"shasum":"65b60b8e4ac001febe90c13991f8a21ab654329e","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-1.0.0.tgz","fileCount":96,"integrity":"sha512-0mtGqdV/1r5e5Fs/LII9w3pUYkYSY1UtDoKhEHdK+8VdCdIYj6MWpb6LiflL+/AaqnYGDdcPPEVPIGyLOMh1WQ==","signatures":[{"sig":"MEUCIQC97EFsVV5+9pB4ykT7LhicL0JDGp+3y0pK9+KHVlieaQIgTY3FhMwke+rvJc0MplevvYTS7pXZM6jjemHaTWfYtAs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":286777},"main":"./dist/server.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"084e2bb2718e6b6716d3376e574d677d0ba7fb0c","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","secret-audit":"tsx scripts/secret-audit.ts","prepublishOnly":"npm run build","test:integration":"vitest run --config vitest.integration.config.ts"},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"repository":{"url":"git+https://github.com/sagapeak/artifacta.git","type":"git","directory":"mcp/typescript"},"_npmVersion":"10.8.2","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","directories":{},"_nodeVersion":"20.20.2","dependencies":{"undici":"^7.25.0","smol-toml":"^1.6.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.19.0","vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.0.0_1779952032338_0.6342685187253598","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@artifacta-mcp/mcp","version":"1.0.1","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","_id":"@artifacta-mcp/mcp@1.0.1","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"homepage":"https://artifacta.io","bugs":{"url":"https://github.com/sagapeak/artifacta/issues"},"bin":{"artifacta-mcp":"dist/cli.js"},"dist":{"shasum":"aa15c84d83f6ccb14454528fa21d19cf3fd843eb","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-1.0.1.tgz","fileCount":96,"integrity":"sha512-qg6ko6VjTL+dzj6t+J+wTbHE4GnXWvHD1XqblnXO0tnVgB6+TNn+ubbG89bDMpcZOM0G/J7FJJUVRLkSZXes7Q==","signatures":[{"sig":"MEUCICDdMZloCCkFj6Jd23yE4jDOclQlgPaiJTv9a7pMkimWAiEA+qw/3PgCgU2jWqERTz2tk922pDmeTiZPEU7wEgUiDko=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":288289},"main":"./dist/server.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"46acf689831d472bc4224bda00ef68349f05e1eb","mcpName":"io.artifacta/mcp","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","secret-audit":"tsx scripts/secret-audit.ts","prepublishOnly":"npm run build","test:integration":"vitest run --config vitest.integration.config.ts"},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"repository":{"url":"git+https://github.com/sagapeak/artifacta.git","type":"git","directory":"mcp/typescript"},"_npmVersion":"10.8.2","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","directories":{},"_nodeVersion":"20.20.2","dependencies":{"undici":"^7.25.0","smol-toml":"^1.6.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.19.0","vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.0.1_1780645034090_0.057033384807487986","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@artifacta-mcp/mcp","version":"1.0.2","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","_id":"@artifacta-mcp/mcp@1.0.2","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"homepage":"https://artifacta.io","bugs":{"url":"https://github.com/SagaPeak/artifacta-mcp/issues"},"bin":{"artifacta-mcp":"dist/cli.js"},"dist":{"shasum":"f74402235a3848bd0ddb52ec23a40ab92e3c18af","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-1.0.2.tgz","fileCount":96,"integrity":"sha512-nMEjVP+bqkiiSzAKslzGm6tf5lGYV4LdFvmD3hLGnuBaDL+iOzaxaGuhs1ISTdc8lGCmk4ryV8ccpzWE3VzCJA==","signatures":[{"sig":"MEUCIQCGrtpSwADG5llkv8D5FR9o7JB9nBN7YuDCoyY4VWfx9AIgBdjZAgBKhZUGF8BeMdnBQt1LbGyGQy6RIS8nUbt6MGs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":289227},"main":"./dist/server.js","type":"module","engines":{"node":">=20.0.0"},"gitHead":"2512b62052c0b01af6d72cd3b615d3b81dd1f695","mcpName":"io.artifacta/mcp","scripts":{"test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","secret-audit":"tsx scripts/secret-audit.ts","prepublishOnly":"npm run build","test:integration":"vitest run --config vitest.integration.config.ts"},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"repository":{"url":"git+https://github.com/SagaPeak/artifacta-mcp.git","type":"git","directory":"typescript"},"_npmVersion":"10.8.2","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","directories":{},"_nodeVersion":"20.20.2","dependencies":{"undici":"^7.25.0","smol-toml":"^1.6.1","@modelcontextprotocol/sdk":"1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.19.0","vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^22.0.0","ajv-formats":"^3.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.0.2_1781242710199_0.3379623374415559","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@artifacta-mcp/mcp","version":"1.0.4","mcpName":"io.artifacta/mcp","description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","type":"module","main":"./dist/server.js","bin":{"artifacta-mcp":"dist/cli.js"},"scripts":{"build":"tsc","test":"vitest run","test:integration":"vitest run --config vitest.integration.config.ts","typecheck":"tsc --noEmit","secret-audit":"tsx scripts/secret-audit.ts","prepublishOnly":"npm run build"},"engines":{"node":">=20.0.0"},"homepage":"https://artifacta.io","repository":{"type":"git","url":"git+https://github.com/SagaPeak/artifacta-mcp.git","directory":"typescript"},"bugs":{"url":"https://github.com/SagaPeak/artifacta-mcp/issues"},"license":"MIT","author":{"name":"Artifacta","email":"team@artifacta.io"},"keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"publishConfig":{"access":"public"},"dependencies":{"@modelcontextprotocol/sdk":"1.29.0","jose":"^6.2.3","smol-toml":"^1.6.1","undici":"^7.28.0"},"overrides":{"hono":"^4.12.21","fast-uri":"^3.1.2","vite":"^7.3.5","ip-address":"^10.2.0","qs":"^6.15.2","esbuild":"^0.28.1"},"devDependencies":{"@types/node":"^22.0.0","ajv":"^8.17.1","ajv-formats":"^3.0.1","tsx":"^4.19.0","typescript":"^5.7.0","vitest":"^3.2.6"},"_id":"@artifacta-mcp/mcp@1.0.4","gitHead":"ab3cb6f9e970d393b1311edd545fdc5880bc981d","_nodeVersion":"22.23.0","_npmVersion":"10.9.8","dist":{"integrity":"sha512-iyey4b6MYd9JcF9QOZSOaMc7fK7JpRq2mssh3rc+yyXpmivTyDEeUOsasPOordb79n91zgcWssl1ct6+v1bJNg==","shasum":"124ed5290b2609509709b8468355c5f20e0dae1a","tarball":"https://registry.npmjs.org/@artifacta-mcp/mcp/-/mcp-1.0.4.tgz","fileCount":114,"unpackedSize":384248,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGXv3byDR5WrqfF/kDYj2zQodbtpWxR6x4EfQp+81zU7AiEAqm4SngELoBBMsqaGxzQ9krvZbNsIjWE96jEW0DV07XY="}]},"_npmUser":{"name":"sagapeak_jn","email":"jn@sagapeak.com"},"directories":{},"maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_1.0.4_1782828643964_0.7341809977712201"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T03:30:50.414Z","modified":"2026-06-30T14:10:44.254Z","0.1.0":"2026-05-25T03:30:50.711Z","0.2.0":"2026-05-26T07:14:06.156Z","1.0.0":"2026-05-28T07:07:12.488Z","1.0.1":"2026-06-05T07:37:14.256Z","1.0.2":"2026-06-12T05:38:30.359Z","1.0.4":"2026-06-30T14:10:44.109Z"},"bugs":{"url":"https://github.com/SagaPeak/artifacta-mcp/issues"},"author":{"name":"Artifacta","email":"team@artifacta.io"},"license":"MIT","homepage":"https://artifacta.io","keywords":["artifacta","mcp","model-context-protocol","ai","agents","artifact-store"],"repository":{"type":"git","url":"git+https://github.com/SagaPeak/artifacta-mcp.git","directory":"typescript"},"description":"Artifacta MCP server — artifact store for AI agents (TypeScript, Node 20+).","maintainers":[{"name":"sagapeak_jn","email":"jn@sagapeak.com"}],"readme":"# @artifacta-mcp/mcp\n\nArtifacta MCP server — artifact store for AI agents.\n\n## Installation\n\n```bash\nnpx @artifacta-mcp/mcp\n```\n\nOr install globally:\n\n```bash\nnpm install -g @artifacta-mcp/mcp\n```\n\n## Configuration\n\nThe server resolves your Artifacta API key using the following precedence (highest first):\n\n| Source | How to set |\n|--------|-----------|\n| `--api-key=<key>` flag | Pass at launch: `artifacta-mcp --api-key=ak_live_...` |\n| `ARTIFACTA_API_KEY` env var | `export ARTIFACTA_API_KEY=ak_live_...` |\n| `~/.artifacta/mcp.toml` | See config file format below |\n| *(none)* | Server starts; first tool call returns an auth error with setup instructions |\n\nThe API base URL follows the same precedence via `--api-url`, `ARTIFACTA_API_URL`, or `api_url` in the config file. Defaults to `https://api.artifacta.io`.\n\n### Config file format\n\n```toml\n[default]\napi_key = \"ak_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\napi_url = \"https://api.artifacta.io\"   # optional\n\n[staging]\napi_key = \"ak_live_yyyy...\"\napi_url = \"https://api.staging.artifacta.io\"\n```\n\nSelect a profile with `--profile=staging` or `ARTIFACTA_PROFILE=staging`.\n\nProfile precedence: `--profile` flag > `ARTIFACTA_PROFILE` env > `[default]` section.\n\nWhen both `--api-key` and `--profile` are passed, `--api-key` wins for the credential but `--profile` still selects `api_url` from the named section (unless `--api-url` is also passed).\n\n### File permissions (Linux/macOS)\n\nThe config file must not be world-writable. The server refuses to start if `~/.artifacta/mcp.toml` has write permission for others (`chmod 600 ~/.artifacta/mcp.toml` is recommended). A warning is emitted if the file is world-readable.\n\n### File permissions (Windows) — known limitation\n\nPOSIX file permission enforcement is not available on Windows in v1. The server emits a one-time warning when loading `~/.artifacta/mcp.toml` and continues without checking ACLs. Ensure the file is restricted to your own user account via Windows file properties or `icacls`.\n\n**Deviation from POSIX behavior:** On Windows, world-writable and world-readable permission checks are skipped entirely. This will be addressed in a future release when Windows ACL probing is implemented.\n\n## Exit codes\n\n| Code | Meaning |\n|------|---------|\n| 0 | Clean exit (--version, --help, graceful shutdown) |\n| 1 | Runtime or transport failure |\n| 2 | Configuration or permissions error (invalid key, world-writable file, missing profile) |\n\n## Usage with Claude Desktop and Cursor\n\nFull client setup — launch flags, path confinement, share-link consent, and\ntroubleshooting — is documented in the [MCP server\noverview](https://docs.artifacta.io/mcp/overview).\n\nClaude Desktop and Cursor do not advertise MCP write confirmations. Add\n`--allow-destructive` so `create_download_link` (public share URLs) appears\nin `tools/list`; without it the tool is hidden by design. Combine with\n`--allow-path` when using `store_artifact.path` for local file uploads.\n\nAdd to `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\\Claude\\claude_desktop_config.json` (Windows). Cursor uses `~/.cursor/mcp.json` (or project-local `.cursor/mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"artifacta\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@artifacta-mcp/mcp\", \"--allow-path\", \"/Users/you/uploads\", \"--allow-destructive\"],\n      \"env\": {\n        \"ARTIFACTA_API_KEY\": \"ak_live_...\"\n      }\n    }\n  }\n}\n```\n\nThe `-y` flag tells `npx` to skip the install confirmation prompt — required for unattended startup. Omit `--allow-path` if you only need inline `content` uploads and read-only tools.\n\nAfter saving, restart the host and confirm the server is connected from the MCP settings panel.\n\n## Hosted MCP (Streamable HTTP)\n\nA hosted endpoint is available at **`https://mcp.artifacta.io/mcp`** so agents can\nuse Artifacta without installing this package or running a local process. The\nhosted server is the same TypeScript server, run with `--transport=http`. The\nnpm and PyPI stdio packages remain fully supported and are unchanged; the Python\npackage is **stdio-only** and does not serve HTTP.\n\n### Connect with OAuth (standard interactive path)\n\nFor interactive clients (Claude Code, Claude Desktop, Cursor), connect by URL and\nsign in through your browser — no API key to copy. The one-liner\n`claude mcp add --transport http artifacta https://mcp.artifacta.io/mcp` self-registers\na public OAuth client via Dynamic Client Registration (PKCE, **no client secret**);\na fixed-`clientId` `add-json` form is the manual fallback. You choose the tool\npermissions (read / write / destroy) on a consent screen. Full setup, including\nboth forms and the `/mcp` → Authenticate flow, is documented here:\n\n**[Connect Claude Code (Hosted)](https://docs.artifacta.io/mcp/install/claude-code-hosted)**\n\n### Headless / CI — `ak_live_` bearer\n\nFor unattended agents and CI that cannot run an interactive browser login, the\nhosted endpoint also accepts a raw `ak_live_` API key as a bearer token,\nforwarded to the REST API exactly as stdio does. API keys are full-access, so all\ntools are exposed. This is the **headless / CI-only** path — interactive users\nshould use OAuth above.\n\n### Endpoint contract\n\n| Request | Result |\n|---------|--------|\n| `POST /mcp` | JSON-RPC, returns `application/json` (stateless — no `MCP-Session-Id`) |\n| `GET /mcp` | `405 Method Not Allowed` (no long-lived SSE in v1) |\n| `GET /healthz` | `200 {\"status\":\"ok\"}` |\n\nSend `Authorization: Bearer <your ak_live_ key>` on every `POST /mcp`. Missing or\nmalformed bearer tokens return `401`. Responses carry `Cache-Control: no-store`.\n\n### curl smoke test (headless `ak_live_` path)\n\nThese are the exact calls the deployment canary runs green over the headless\n`ak_live_` path. Read the key from the environment — never paste it on the\ncommand line.\n\n```bash\nexport ARTIFACTA_API_KEY=ak_live_...\n\n# 1. initialize → serverInfo.name == \"artifacta\"\ncurl -s https://mcp.artifacta.io/mcp \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Accept: application/json, text/event-stream\" \\\n  -H \"Authorization: Bearer $ARTIFACTA_API_KEY\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"curl\",\"version\":\"0\"}}}'\n\n# 2. tools/list → array including whoami, list_artifacts\ncurl -s https://mcp.artifacta.io/mcp \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Accept: application/json, text/event-stream\" \\\n  -H \"Authorization: Bearer $ARTIFACTA_API_KEY\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"tools/list\",\"params\":{}}'\n\n# 3. tools/call whoami → identity, plan, usage\ncurl -s https://mcp.artifacta.io/mcp \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Accept: application/json, text/event-stream\" \\\n  -H \"Authorization: Bearer $ARTIFACTA_API_KEY\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":3,\"method\":\"tools/call\",\"params\":{\"name\":\"whoami\",\"arguments\":{}}}'\n```\n\nThe `Accept: application/json, text/event-stream` header is what a compliant MCP\nclient sends; the SDK requires both media types even though the hosted server\nalways responds with `application/json`.\n\n### Self-hosting the HTTP transport\n\nTo run the HTTP transport yourself (the hosted deployment uses the bundled\n`Dockerfile`):\n\n```bash\nartifacta-mcp --transport=http --port=8080\n```\n\n| Setting | How to set | Notes |\n|---------|-----------|-------|\n| Transport | `--transport=http` | Default is `stdio`; HTTP is opt-in |\n| Port | `--port=<n>` or `PORT` env | `PORT` is used by the Docker image / Railway |\n| API base URL | `ARTIFACTA_API_URL` | Defaults to `https://api.artifacta.io` |\n| Allowed browser origins | `MCP_ALLOWED_ORIGINS` | Comma-separated exact-match allow-list; a present `Origin` not on the list returns `403`. Absent `Origin` (curl, CI, agents) is allowed. Leave unset for non-browser clients |\n\nUnlike stdio, the HTTP transport does **not** read `ARTIFACTA_API_KEY` from its\nenvironment — each request supplies its own bearer token, so one server can\nserve many tenants.\n\n## Troubleshooting\n\n### `unauthorized` errors on every tool call\n\nThe most common failure mode is a missing or invalid API key. The MCP server itself starts even when no key is configured — the auth check happens on the first tool call. When that call fails, the server returns a structured remediation block to the agent. Common causes:\n\n- **No key configured at all.** The server has no `--api-key`, no `ARTIFACTA_API_KEY`, and no `~/.artifacta/mcp.toml`. Set one of the three.\n- **Wrong env var name.** Must be `ARTIFACTA_API_KEY` exactly. `ARTIFACTA_KEY` and `API_KEY` are not read.\n- **Key revoked.** The key was rotated or revoked in the dashboard. Generate a new one at <https://app.artifacta.io/dashboard/keys>.\n- **Key shape mismatch.** Keys must match `ak_live_` followed by 32 alphanumeric characters. The server refuses to start (exit 2) if the configured key has the wrong shape.\n- **Tenant suspended.** The account is in the post-deletion grace period. The error message includes \"suspended\"; restore the account from the dashboard.\n\nTo verify your key directly:\n\n```bash\ncurl -H \"Authorization: Bearer $ARTIFACTA_API_KEY\" https://api.artifacta.io/v1/whoami\n```\n\n### Server fails to start on Windows\n\nWindows skips POSIX permission checks on `~/.artifacta/mcp.toml` (see \"File permissions (Windows)\" above). If startup still fails, check that the file is reachable from the user account Claude Desktop runs as.\n\n### `npx` hangs on first launch\n\n`npx` downloads the package on first run, which can take 10–30 seconds on a slow connection. Subsequent launches use the cache and are near-instant. If `npx` fails with a network error, the package can be installed globally instead: `npm install -g @artifacta-mcp/mcp`, then point Claude Desktop's `command` at `artifacta-mcp` directly with `args: []`.\n\n## License\n\nMIT — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}