{"_id":"@aura-labs-ai/mcp-server-admission","name":"@aura-labs-ai/mcp-server-admission","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@aura-labs-ai/mcp-server-admission","version":"0.1.0","description":"AURA admission MCP server: the local action layer that onboards an agent onto the AURA certification bench. Holds the agent's Ed25519 keys and signs every admission request locally — keys never leave the machine.","type":"module","main":"src/index.js","bin":{"mcp-server-admission":"src/index.js"},"scripts":{"test":"node --test src/tests/*.test.js"},"dependencies":{"@aura-labs-ai/sdk-common":"^0.2.0","@modelcontextprotocol/sdk":"^1.0.0"},"overrides":{"fast-uri":"^3.1.3","hono":"^4.12.28","path-to-regexp":"^8.4.2"},"engines":{"node":">=20"},"keywords":["aura","mcp","admission","agent","ed25519","sandbox"],"license":"MIT","publishConfig":{"access":"public"},"gitHead":"79b7beb4bdca71ac857f09a7e6657d429d552a69","_id":"@aura-labs-ai/mcp-server-admission@0.1.0","_nodeVersion":"25.8.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-Zsq9yalpGv7WCoFIYK0KUg956LeRaYmxrCUCmrBsaje9P2fWXoX1onVlqksMGiLHaZD3SpDorSzo3rjb2HYa+w==","shasum":"7331ac88e8cb6cfeeaac1fed5fa16c1e5901f43c","tarball":"https://registry.npmjs.org/@aura-labs-ai/mcp-server-admission/-/mcp-server-admission-0.1.0.tgz","fileCount":5,"unpackedSize":27420,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBRStVvhosECB8PE8l0Zantlc8GuzFSq1zWHMsLrWyAOAiAxOyLk59803U8tzHWQfTbTymX1lkV1iTay2tewmqgSjw=="}]},"_npmUser":{"name":"marcmassar","email":"marc@aura-labs.ai"},"directories":{},"maintainers":[{"name":"marcmassar","email":"marc@aura-labs.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-admission_0.1.0_1783758708162_0.5170927732794348"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-11T08:31:47.879Z","0.1.0":"2026-07-11T08:31:48.289Z","modified":"2026-07-11T08:31:48.658Z"},"maintainers":[{"name":"marcmassar","email":"marc@aura-labs.ai"}],"description":"AURA admission MCP server: the local action layer that onboards an agent onto the AURA certification bench. Holds the agent's Ed25519 keys and signs every admission request locally — keys never leave the machine.","keywords":["aura","mcp","admission","agent","ed25519","sandbox"],"license":"MIT","readme":"# @aura-labs-ai/mcp-server-admission\n\nThe local action layer of AURA agent admission. An agent installs this MCP\nserver in its own environment; the server holds the agent's Ed25519 keys and\nsigns every admission request itself. The private keys never leave the machine —\nonly signatures do. Discovery stays on the hosted AURA MCP; authority lives here.\n\n## Install\n\n```json\n{\n  \"mcpServers\": {\n    \"aura-admission\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aura-labs-ai/mcp-server-admission\"]\n    }\n  }\n}\n```\n\nEnvironment:\n\n- `AURA_BENCH_URL` — the certification bench (default `https://sandbox.aura-labs.ai`)\n- `AURA_KEY_PATH` — key file location override (default: macOS Keychain, else `~/.aura/keys.json` at 0600)\n\n## The tools, in recorded-run order\n\nProvision opens the recorded conformance run, and registrations are captured\ninto it only when the sandbox key is presented — so the order below matters.\nRegistering before provisioning still succeeds, but the transcript never\ncaptures it.\n\n1. `get_admission_guide` — read the admission chain from the bench.\n2. `mint_sandbox_key` — two-phase. The first call generates and holds a\n   dedicated domain signing key and returns the exact domain-control proof to\n   publish (DNS TXT `_aura-agent-key.<domain>` = `aura-key=<public_key>`, or the\n   HTTPS document `https://<domain>/.well-known/aura-agent-key` containing\n   `{\"public_key\":\"<base64>\"}`). Publish it, call again: the tool attempts the\n   mint and, until the proof is visible, returns the bench's `looked_for` /\n   `found` verbatim. On success the bearer key is held locally.\n3. `provision_sandbox` — the seeded market, the manifest, and the opened\n   `run_id`. Idempotent.\n4. `register_principal` — signed locally with the held principal key.\n5. `register_agent` — signed locally with the held agent key.\n6. `reset_sandbox` — opens a fresh run (not idempotent; spends run quota).\n\n## Key custody\n\nThree Ed25519 keypairs (principal, agent, domain — the bench enforces\nfingerprint uniqueness, so they are distinct by construction) plus the chain\nstate (`sandbox_key`, `principal_id`, `agent_id`, `namespace_id`, `run_id`)\npersist across restarts via the platform storage adapter. Nothing sensitive is\never written to stdout (the MCP channel) or included in tool results.\n\n## Publishing (maintainers)\n\nThe package publishes over npm OIDC trusted publishing from the repository\nworkflow. A brand-new package name requires a one-time bootstrap publish via\ntraditional auth, then registering its Trusted Publisher on npmjs.com, before\nthe workflow can publish it.\n","readmeFilename":"README.md","_rev":"1-b4769dad9ee1c0af5f142afb8a807b52"}