{"_id":"@aura-labs.ai/mcp-server-scout","_rev":"2-beeb9afccbd6ac467a0bbda8cf878a81","name":"@aura-labs.ai/mcp-server-scout","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@aura-labs.ai/mcp-server-scout","version":"1.0.0","keywords":["mcp","model-context-protocol","aura","scout","procurement","commerce","claude","ai-agent","ed25519"],"author":{"name":"AURA Labs"},"license":"BSL-1.1","_id":"@aura-labs.ai/mcp-server-scout@1.0.0","maintainers":[{"name":"marcmassar","email":"marc@aura-labs.ai"}],"homepage":"https://aura-labs.ai/docs/mcp","bugs":{"url":"https://github.com/aura-labs-ai/aura-labs/issues"},"bin":{"mcp-server-scout":"src/index.js"},"dist":{"shasum":"500bcc88c4334ddc08c477d56d08038a7d324f1e","tarball":"https://registry.npmjs.org/@aura-labs.ai/mcp-server-scout/-/mcp-server-scout-1.0.0.tgz","fileCount":7,"integrity":"sha512-O8Kuplbl+8GQ98C2MMaoCGAc2KyWtIiJIonnIhThukwUXQZ4ZGycgUeBsYhpqbKwIDxrCRT6lTQQggWM37OH2g==","signatures":[{"sig":"MEQCIFn3Xn7hzneabW8JjyfzyIouq4n/vq6kobz4QF6wduwyAiAzPxfuSdGRgAhUXP2nBMcPs625pUvgT0VymAB5a0WOww==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":43596},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"scripts":{"dev":"node --watch src/index.js","test":"node --test src/tests/*.test.js","start":"node src/index.js"},"_npmUser":{"name":"marcmassar","email":"marc@aura-labs.ai"},"repository":{"url":"git+https://github.com/aura-labs-ai/aura-labs.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP Server for AURA Scout — Expose purchasing capabilities to Claude and other MCP-compatible AI assistants","directories":{},"_nodeVersion":"25.8.0","dependencies":{"@aura-labs.ai/scout":"^0.2.0","@aura-labs.ai/sdk-common":"^0.1.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-scout_1.0.0_1773247411228_0.31704365402671075","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2026-03-11T16:43:31.140Z","modified":"2026-07-02T19:30:25.983Z","1.0.0":"2026-03-11T16:43:31.374Z"},"bugs":{"url":"https://github.com/aura-labs-ai/aura-labs/issues"},"author":{"name":"AURA Labs"},"license":"BSL-1.1","homepage":"https://aura-labs.ai/docs/mcp","keywords":["mcp","model-context-protocol","aura","scout","procurement","commerce","claude","ai-agent","ed25519"],"repository":{"url":"git+https://github.com/aura-labs-ai/aura-labs.git","type":"git"},"description":"MCP Server for AURA Scout — Expose purchasing capabilities to Claude and other MCP-compatible AI assistants","maintainers":[{"name":"marcmassar","email":"marc@aura-labs.ai"}],"readme":"# @aura-labs.ai/mcp-server-scout\n\nMCP Server for AURA Scout — Expose purchasing capabilities to Claude and other MCP-compatible AI assistants.\n\n## What is this?\n\nThis MCP server connects Claude to the AURA commerce protocol. It lets you find products, compare offers from competing suppliers, and commit to purchases — entirely through natural conversation.\n\nUnder the hood, the server uses the Scout SDK with Ed25519 cryptographic identity, conversational intent completeness checking, and structured offer evaluation. No API keys, no forms, no portals.\n\n**Example conversation:**\n```\nYou: I need noise-cancelling headphones for our office, maybe 20 of them\n\nClaude: A few questions to make sure I find the right options —\n        what's your budget, and when do you need them by?\n\nYou: Under $8000 total, within two weeks\n\nClaude: Searching for offers...\n\nClaude: I found 3 offers:\n1. TechMart — Sony WH-1000XM5 × 20 @ $348 each ($6,960 total) — 5 day delivery\n2. AudioPro — Bose QC Ultra × 20 @ $379 each ($7,580 total) — 3 day delivery\n3. OfficeBuy — JBL Tour One M2 × 20 @ $299 each ($5,980 total) — 7 day delivery\n\nAll within budget. AudioPro has the fastest delivery.\n\nYou: Go with AudioPro\n\nClaude: Committed. Transaction TX-abc123 confirmed with AudioPro.\n```\n\n## Installation\n\n### Claude Desktop\n\nAdd to `~/.claude/claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"aura-scout\": {\n      \"command\": \"npx\",\n      \"args\": [\"@aura-labs.ai/mcp-server-scout\"]\n    }\n  }\n}\n```\n\nRestart Claude Desktop. On first launch, the server auto-generates an Ed25519 identity and registers with AURA Core. No API key required.\n\n### Claude Code\n\nAdd to your project's `.mcp.json`:\n\n```json\n{\n  \"servers\": {\n    \"aura-scout\": {\n      \"command\": \"npx\",\n      \"args\": [\"@aura-labs.ai/mcp-server-scout\"]\n    }\n  }\n}\n```\n\n### Development\n\n```bash\ncd sdks/mcp-server-scout\nnpm install\nnpm start\n```\n\n## Tools\n\n### `aura_search`\n\nStart a new purchasing session with natural language.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `query` | string | yes | What you want to buy — be specific about product, quantity, budget, timeline |\n\nReturns `needs_clarification` (with a question) or `searching` (with a session_id).\n\n### `aura_clarify`\n\nProvide additional information when `aura_search` needs clarification.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `session_id` | string | yes | Session ID from `aura_search` |\n| `text` | string | yes | User's answer to the clarification question |\n\n### `aura_get_offers`\n\nRetrieve offers from competing suppliers.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `session_id` | string | yes | Session ID from `aura_search` |\n\nReturns structured offers with price, delivery estimate, constraint evaluation, and gap notes.\n\n### `aura_commit`\n\nCommit to a specific offer, initiating the transaction.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `session_id` | string | yes | Session containing the offer |\n| `offer_id` | string | yes | The offer to commit to |\n\n### `aura_cancel`\n\nCancel an active session before commitment.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `session_id` | string | yes | Session to cancel |\n\n### `aura_status`\n\nCheck session or transaction status.\n\n| Parameter | Type | Required | Description |\n|-----------|------|----------|-------------|\n| `session_id` | string | yes | Session to check |\n\n## Configuration\n\n| Variable | Default | Description |\n|----------|---------|-------------|\n| `AURA_CORE_URL` | `https://aura-labsai-production.up.railway.app` | Core API endpoint |\n| `AURA_KEY_PATH` | `~/.aura/keys.json` | Persistent Ed25519 key storage path |\n| `AURA_OFFER_TIMEOUT` | `30000` | Milliseconds to wait for offers |\n| `AURA_LOG_LEVEL` | `info` | Log verbosity (`debug`, `info`, `warn`, `error`) |\n\n## Security\n\n**Key storage:** The MCP server auto-detects the best storage for Ed25519 private keys via `@aura-labs.ai/sdk-common`:\n- **macOS** — Keys stored in the system Keychain (hardware-backed encryption at rest via Secure Enclave on Apple Silicon). Zero native dependencies — uses the `security` CLI.\n- **Linux / Windows** — Keys stored at `~/.aura/keys.json` with `0600` permissions (owner read/write only).\n\nOverride with `AURA_KEY_PATH` env var for custom file path, or pass `{ type: 'file' }` to force file-based storage.\n\n**No secrets in config:** The MCP server requires no API keys, bearer tokens, or passwords. Identity is purely Ed25519 key-based.\n\n**Threat model:** The key's blast radius in v1 is limited to session creation and offer commitment. No payment processing occurs (see MCP_SCOUT_SERVER.md NG1). Key rotation and revocation are planned for v2.\n\n## Architecture\n\n```\nClaude Desktop / Claude Code\n  ↕ MCP Protocol (stdio)\nMCP Scout Server (this package)\n  ↕ Scout SDK (@aura-labs.ai/scout)\n    ↕ KeyManager → createStorage() (Keychain on macOS, File elsewhere)\n    ↕ IntentSession (completeness gating)\n    ↕ ScoutClient (Ed25519-signed requests)\n      ↕ AURA Core API\n        ↕ Beacon matching + offer collection\n```\n\nKey design decisions:\n\n- **Scout SDK integration** — All Core interactions through the SDK. No raw HTTP.\n- **Ed25519 identity** — Auto-generated on first run, persisted via FileStorage. No API keys.\n- **IntentSession completeness** — Vague requests trigger clarification before consuming Core resources.\n- **In-memory sessions** — SessionStore tracks active sessions. Identity persists; session state is ephemeral.\n\n## Response Shapes\n\nAll tool responses follow consistent structures:\n\n```jsonc\n// Success\n{ \"status\": \"ok\", \"data\": { ... } }\n\n// Searching (session created, awaiting offers)\n{ \"status\": \"searching\", \"session_id\": \"...\" }\n\n// Needs clarification\n{ \"status\": \"needs_clarification\", \"question\": \"...\", \"missing\": [...], \"round\": 1, \"session_id\": \"...\" }\n\n// No offers received\n{ \"status\": \"no_offers\", \"message\": \"...\" }\n\n// Error\n{ \"status\": \"error\", \"code\": \"SESSION_NOT_FOUND\", \"message\": \"...\" }\n```\n\nError codes: `INVALID_INPUT`, `SESSION_NOT_FOUND`, `INVALID_STATE`, `NETWORK_ERROR`, `COMMITMENT_FAILED`, `SESSION_ERROR`, `SERVER_ERROR`.\n\n## License\n\nBusiness Source License 1.1 — See [LICENSE](LICENSE) for details.\n","readmeFilename":"README.md"}