{"_id":"@atestia/tier4-mcp-server","name":"@atestia/tier4-mcp-server","dist-tags":{"latest":"0.2.0"},"versions":{"0.2.0":{"name":"@atestia/tier4-mcp-server","version":"0.2.0","description":"Reference MCP server for the Tier-4 v1.2 open specification. The universal evidence layer for regulated AI. Captures vendor model attestation (SR 26-2 + OCC 2013-29), risk data lineage (BCBS 239 + CCAR + HMDA), fair-lending explainability (ECOA Reg B adve","main":"dist/index.js","types":"dist/index.d.ts","type":"module","bin":{"tier4-mcp-server":"dist/cli.js"},"scripts":{"build":"tsc","test":"npm run build && node examples/smoke-test.mjs && node examples/stdio-roundtrip-test.mjs && node examples/v02-features-test.mjs","test:smoke":"node examples/smoke-test.mjs","test:stdio":"node examples/stdio-roundtrip-test.mjs","test:v02":"node examples/v02-features-test.mjs","lint":"eslint src --ext .ts","format":"prettier --write src","spec:validate":"node dist/cli.js spec-validate","prepublishOnly":"npm run build"},"keywords":["mcp","model-context-protocol","sr-26-2","occ-2013-29","bcbs-239","model-risk-management","mrm","vendor-attestation","banking","agentic-ai","ai-governance","regtech","tier-4","compliance","anthropic","bedrock"],"author":{"name":"Tier-4 Compliance Working Group + Atestia Inc."},"homepage":"https://github.com/Atestia/tier4-mcp-server","license":"MPL-2.0","repository":{"type":"git","url":"git+https://github.com/Atestia/tier4-mcp-server.git"},"bugs":{"url":"https://github.com/Atestia/tier4-mcp-server/issues"},"engines":{"node":">=20"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","better-sqlite3":"^11.0.0","zod":"^3.23.0"},"devDependencies":{"@types/better-sqlite3":"^7.6.13","@types/node":"^22.0.0","@typescript-eslint/eslint-plugin":"^8.0.0","@typescript-eslint/parser":"^8.0.0","eslint":"^9.0.0","prettier":"^3.0.0","typescript":"^5.6.0","vitest":"^2.0.0"},"publishConfig":{"access":"public"},"gitHead":"228ae0afdd92653ae9ee2cb75b660e83be5a2db0","_id":"@atestia/tier4-mcp-server@0.2.0","_nodeVersion":"25.5.0","_npmVersion":"11.8.0","dist":{"integrity":"sha512-A8LKMf4IFhiIOeTzdE1uU7F3rL6ZI01c2FhpBESEe82Ps+iakR2wZK5w273o8n7Ra6vG6b+JjEGlKrZivchWzg==","shasum":"f2ca2d7ebccc6a31ae79dce867fb932dc9c45cf4","tarball":"https://registry.npmjs.org/@atestia/tier4-mcp-server/-/tier4-mcp-server-0.2.0.tgz","fileCount":52,"unpackedSize":210450,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBQKDxfdm+ZnSvLGaYmMzMxqSm4Bq302Dey4QgWv/tdOAiAIoWDDegVWDwtahpBhLLndNHZAI0RXn1c4zjBwq5r8wg=="}]},"_npmUser":{"name":"atestia","email":"admin.atestia@gmail.com"},"directories":{},"maintainers":[{"name":"atestia","email":"admin.atestia@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/tier4-mcp-server_0.2.0_1780343837153_0.8564045946361492"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-01T19:57:16.943Z","0.2.0":"2026-06-01T19:57:17.315Z","modified":"2026-06-01T19:57:17.514Z"},"maintainers":[{"name":"atestia","email":"admin.atestia@gmail.com"}],"description":"Reference MCP server for the Tier-4 v1.2 open specification. The universal evidence layer for regulated AI. Captures vendor model attestation (SR 26-2 + OCC 2013-29), risk data lineage (BCBS 239 + CCAR + HMDA), fair-lending explainability (ECOA Reg B adve","homepage":"https://github.com/Atestia/tier4-mcp-server","keywords":["mcp","model-context-protocol","sr-26-2","occ-2013-29","bcbs-239","model-risk-management","mrm","vendor-attestation","banking","agentic-ai","ai-governance","regtech","tier-4","compliance","anthropic","bedrock"],"repository":{"type":"git","url":"git+https://github.com/Atestia/tier4-mcp-server.git"},"author":{"name":"Tier-4 Compliance Working Group + Atestia Inc."},"bugs":{"url":"https://github.com/Atestia/tier4-mcp-server/issues"},"license":"MPL-2.0","readme":"<div align=\"center\">\n\n# Tier-4 MCP Server\n\n**The universal evidence layer for regulated AI.**\n\n[![npm version](https://img.shields.io/npm/v/@atestia/tier4-mcp-server.svg)](https://www.npmjs.com/package/@atestia/tier4-mcp-server)\n[![License: MPL-2.0](https://img.shields.io/badge/License-MPL_2.0-blue.svg)](https://www.mozilla.org/en-US/MPL/2.0/)\n[![Spec: v1.2](https://img.shields.io/badge/Spec-v1.2-blue.svg)](https://github.com/Atestia/tier4-mcp-server/blob/main/docs/SPEC.md)\n[![Tests: 74 passing](https://img.shields.io/badge/Tests-74%20passing-brightgreen.svg)](#testing)\n[![Node: >=20](https://img.shields.io/badge/Node-%3E%3D20-green.svg)](https://nodejs.org/)\n[![MCP: 2024-11-05](https://img.shields.io/badge/MCP-2024--11--05-purple.svg)](https://modelcontextprotocol.io/)\n[![OpenLineage compatible](https://img.shields.io/badge/OpenLineage-compatible-orange.svg)](https://openlineage.io/)\n\n[Specification](https://github.com/Atestia/tier4-mcp-server/blob/main/docs/SPEC.md) · [Working Group Charter](https://github.com/Atestia/tier4-mcp-server#working-group) · [Index Methodology](https://github.com/Atestia/website/blob/main/methodology.html) · [Conformance Registry](https://github.com/Atestia/tier4-mcp-server#conformance)\n\n</div>\n\n---\n\n## What is this?\n\n`@atestia/tier4-mcp-server` is an Anthropic Model Context Protocol (MCP) server that captures regulator-grade evidence of every vendor model invocation, every risk data lineage event, and every agent reasoning chain — at runtime, in production, from any AI agent.\n\nIt implements the open **Tier-4 v1.2** specification (CC-BY-4.0) governed by the Tier-4 Compliance Working Group, a Delaware 501(c)(6) industry association.\n\n**Banks today. Capital markets, insurance, healthcare next.**\n\n```bash\nnpm install @atestia/tier4-mcp-server\n```\n\n---\n\n## Why it exists\n\nEvery Tier-1 US bank now invokes external vendor LLMs in production: JPMorgan LLM Suite (~250K seats), Goldman GS AI Assistant (46.5K seats), Wells Fargo + Google Agentspace (215K seats), Citi Arc, Bank of America CashPro AI, Morgan Stanley AI at MS, Capital One agent systems, US Bank.\n\nWhen the next examination cycle begins, examiners will ask: *\"Show me the vendor model invocation log for this decision, six months ago.\"*\n\nBanks today have no answer. Their agent platforms record nothing of that granularity.\n\n**Tier-4 fills the gap.**\n\n| Regulation | What it requires | What Tier-4 captures |\n|---|---|---|\n| **BCBS 239** (Basel, binding) | Risk data aggregation lineage | `tier4.lineage.bcbs239` |\n| **ECOA Reg B** (statute, binding) | Explainability of credit denials | `tier4.lineage.regb` + `tier4.reasoning.capture` + `tier4.packet.regb-notice` |\n| **SR 26-2** (Fed supervisory) | Vendor model governance | `tier4.credit.evaluate` + `tier4.packet.sr-26-2` |\n| **OCC 2013-29** (long-standing) | Vendor questionnaire | `tier4.packet.occ-2013-29` |\n| **EU AI Act Annex III** (Aug 2026) | High-risk AI transparency | `tier4.reasoning.capture` |\n| **NAIC AI Bulletin** (insurance) | AI underwriting explainability | (Q1 2027) |\n| **FDA AI/ML SaMD** (healthcare) | Medical AI conformity | (Q2 2027) |\n\n---\n\n## 60-second quickstart\n\n```bash\n# 1. Install\nnpm install -g @atestia/tier4-mcp-server\n\n# 2. Configure your AI agent (Claude Desktop / Cursor / Bedrock AgentCore / LangChain)\n# Claude Desktop config:\ncat ~/.config/claude_desktop/claude_desktop_config.json\n{\n  \"mcpServers\": {\n    \"tier4\": {\n      \"command\": \"tier4-mcp-server\",\n      \"env\": {\n        \"TIER4_TENANT_ID\": \"your-bank-mrm-tenant\"\n      }\n    }\n  }\n}\n```\n\nYour agent now has 10 tools available for capturing regulatory evidence at runtime. Every vendor model invocation is persisted to a Tier-4-conformant lineage trail. Every credit decision can be made into a Reg B Adverse Action Notice on demand. Every BCBS 239 reporting flow has a captured lineage event.\n\n---\n\n## Architecture\n\n```mermaid\nflowchart TB\n    Agent[AI Agent / Bedrock / Claude Desktop / LangChain]\n    Agent -->|MCP stdio| Server[Tier-4 MCP Server]\n\n    Server --> Lineage[Lineage Store<br/>SQLite WAL]\n    Server --> Reasoning[Reasoning Capture]\n    Server --> Packets[Packet Generators]\n\n    Packets --> OCC[OCC 2013-29]\n    Packets --> SR[SR 26-2]\n    Packets --> BCBS[BCBS 239]\n    Packets --> RegB[ECOA Reg B Notice]\n\n    Lineage --> OLAdapter[OpenLineage Adapter]\n    OLAdapter --> Marquez[Marquez]\n    OLAdapter --> Snowflake[Snowflake]\n    OLAdapter --> Databricks[Databricks Unity]\n\n    style Server fill:#7c3aed,color:#fff\n    style Lineage fill:#0891b2,color:#fff\n    style Reasoning fill:#0891b2,color:#fff\n    style Packets fill:#0891b2,color:#fff\n```\n\nSee [`ARCHITECTURE.md`](./ARCHITECTURE.md) for the full system architecture, threat model, storage model, and pluggable interfaces.\n\n---\n\n## The 10 MCP tools\n\n### Lineage capture\n\n- **`tier4.credit.evaluate`** — Record a vendor-model invocation for a credit decision\n- **`tier4.lineage.bcbs239`** — Capture a BCBS 239 risk data lineage event\n- **`tier4.lineage.regb`** — Capture an ECOA Reg B adverse action lineage event\n- **`tier4.lineage.fetch`** — Fetch the full lineage trail by lineage_id\n\n### Reasoning capture\n\n- **`tier4.reasoning.capture`** — Capture an agent reasoning chain (the THINKING flow)\n\n### Packet generators\n\n- **`tier4.packet.occ-2013-29`** — OCC 2013-29 vendor questionnaire (47 fields, 7 sections)\n- **`tier4.packet.sr-26-2`** — SR 26-2 vendor attestation pack (5 artifacts)\n- **`tier4.packet.bcbs-239`** — BCBS 239 risk-data aggregation reference\n- **`tier4.packet.regb-notice`** — ECOA Reg B Adverse Action Notice (customer-facing + 25-month compliance record)\n\n### Ecosystem bridge\n\n- **`tier4.openlineage.export`** — Export a Tier-4 lineage record as an OpenLineage RunEvent\n\n---\n\n## Example: capture a reasoning chain\n\n```json\n{\n  \"agentId\": \"citi-credit-agent-002\",\n  \"invocationId\": \"inv-reason-001\",\n  \"agentDirective\": \"Evaluate SMB credit application #APP-12345\",\n  \"steps\": [\n    {\"stepType\": \"observation\", \"description\": \"Reviewed business profile\", \"timestamp\": \"2026-06-01T10:00:00Z\"},\n    {\"stepType\": \"tool_call\", \"description\": \"Called Experian\", \"toolName\": \"experian.credit_check\", \"vendorModelId\": \"experian-v3.2\", \"timestamp\": \"2026-06-01T10:00:01Z\"},\n    {\"stepType\": \"tool_result\", \"description\": \"Score 580\", \"outputs\": {\"score\": 580}, \"timestamp\": \"2026-06-01T10:00:02Z\"},\n    {\"stepType\": \"decision\", \"description\": \"Below threshold; recommend denial\", \"timestamp\": \"2026-06-01T10:00:03Z\"}\n  ],\n  \"finalDecision\": \"Recommend denial\",\n  \"confidence\": 0.85,\n  \"humanInLoop\": true,\n  \"humanReviewer\": \"loan-officer-123\",\n  \"humanReviewOutcome\": \"approved\",\n  \"startedAt\": \"2026-06-01T10:00:00Z\",\n  \"completedAt\": \"2026-06-01T10:00:03Z\"\n}\n```\n\nThe returned reasoning record can be linked to a lineage record, attached to a Reg B Adverse Action Notice, exported to OpenLineage, or retrieved for examiner review years later.\n\n---\n\n## Examples\n\nWorking integration examples in [`examples/`](./examples):\n\n- [`smoke-test.mjs`](./examples/smoke-test.mjs) — Direct lineage API smoke test (22 assertions)\n- [`stdio-roundtrip-test.mjs`](./examples/stdio-roundtrip-test.mjs) — Full MCP wire-protocol round-trip (18 assertions)\n- [`v02-features-test.mjs`](./examples/v02-features-test.mjs) — v0.2.0 D++ feature tests (34 assertions)\n\n---\n\n## Testing\n\n```bash\nnpm test\n```\n\nRuns all three test suites: 22 + 18 + 34 = **74 assertions, 0 failures**.\n\nThe test suites verify:\n\n- **Persistence:** Real SQLite write/read/close/reopen survival\n- **Wire protocol:** MCP initialize handshake, tools/list, tools/call round-trips\n- **Schema conformance:** All 10 tools return Tier-4 v1.2-conformant JSON\n- **Packet generation:** OCC 2013-29, SR 26-2, BCBS 239, Reg B Adverse Action produce valid packet structures\n- **OpenLineage adapter:** Tier-4 → OpenLineage event format round-trip\n- **Reasoning capture:** Multi-step chains with human-in-loop tracking and lineage linking\n\n---\n\n## Conformance\n\nThis implementation declares conformance with **Tier-4 v1.2** at the **Implementer** level per the [Conformance Test Suite](./cts) (CTS).\n\nTo claim higher conformance levels (Conformant, Certified), submit your implementation results to the [Tier-4 Conformant Implementations Registry](https://github.com/Atestia/tier4-mcp-server#conformance).\n\n---\n\n## Specification\n\nRead the full Tier-4 v1.2 specification: [`docs/SPEC.md`](./docs/SPEC.md) or [tier4.org/spec/v1.2](https://github.com/Atestia/tier4-mcp-server/blob/main/docs/SPEC.md).\n\nSpec is licensed under CC-BY-4.0; this reference implementation is licensed under MPL-2.0.\n\n---\n\n## Working Group\n\nThe Tier-4 Compliance Working Group is a Delaware 501(c)(6) industry association that develops, maintains, and promotes the Tier-4 specification. Atestia is the founding sponsor; Atestia holds a permanent non-voting Steering Committee seat.\n\n**Membership tiers:**\n- **Class I — Charter Member** (founding 10): $25K/yr (waived first 12mo) — Steering Committee seat, 3× spec vote, named in spec preamble\n- **Class II — General Member**: $25K/yr — 1× spec vote, 30-day embargo preview\n- **Class III — Implementer Member**: $0 — registry listing\n\nApply at [tier4.org/charter](https://github.com/Atestia/tier4-mcp-server#working-group).\n\n---\n\n## Commercial enterprise tier\n\nFor production banking deployments with examiner-defensible 7-year retention, customer-held KMS keys, MRM analyst UI, indemnification, and 24-7 support, see [atestia.ai/platform](https://github.com/Atestia).\n\nFor self-serve developer / vendor / audit-firm / insurance-carrier subscriptions, see [atestia.ai/pro](https://github.com/Atestia).\n\n---\n\n## Contributing\n\nWe welcome contributions. See [`CONTRIBUTING.md`](./CONTRIBUTING.md).\n\nThe fastest path to becoming a Tier-4 Implementer Member of the Working Group is to ship a Conformant implementation and submit it to the [registry](https://github.com/Atestia/tier4-mcp-server#conformance).\n\n---\n\n## Security\n\nFound a vulnerability? See [`SECURITY.md`](./SECURITY.md) for responsible disclosure.\n\n---\n\n## License\n\nCode: [MPL-2.0](./LICENSE)\nSpecification: [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/)\nTrademarks: \"Tier-4\" and \"Tier-4-Conformant\" are trademarks of Atestia Inc., licensed to the Tier-4 Compliance Working Group.\n\n---\n\n<div align=\"center\">\n\n**Built by [Atestia](https://github.com/Atestia) and the [Tier-4 Compliance Working Group](https://github.com/Atestia/tier4-mcp-server#working-group).**\n\n[Specification](https://github.com/Atestia/tier4-mcp-server/blob/main/docs/SPEC.md) · [Working Group](https://github.com/Atestia/tier4-mcp-server#working-group) · [Registry](https://github.com/Atestia/tier4-mcp-server#conformance) · [Index Methodology](https://github.com/Atestia/website/blob/main/methodology.html)\n\n</div>\n","readmeFilename":"README.md","_rev":"1-ae7f18766332e205693ae9f4d5027714"}