{"_id":"@byliner/mcp-agent","_rev":"2-f8dc87fc3d66284ab11e8db1d3b6d189","name":"@byliner/mcp-agent","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@byliner/mcp-agent","version":"0.1.0","keywords":["mcp","modelcontextprotocol","byliner","approval","human-in-the-loop","agent"],"license":"MIT","_id":"@byliner/mcp-agent@0.1.0","maintainers":[{"name":"aarontropy","email":"aarontropy@gmail.com"}],"homepage":"https://byliner.dev","bugs":{"url":"https://github.com/byliner-dev/byliner/issues"},"bin":{"byliner-mcp-agent":"dist/server.js"},"dist":{"shasum":"12a43723c7e8fcd8fee277f6ade1cb389a11f91c","tarball":"https://registry.npmjs.org/@byliner/mcp-agent/-/mcp-agent-0.1.0.tgz","fileCount":14,"integrity":"sha512-kkYt2DfUSkX3sKJwHyennzNOMmfVTSjhG8Nf1cNk2ZnIq4M7PJw9DOtHmyzsyTKA08wBF59c5XJv/W2E7KsPhA==","signatures":[{"sig":"MEYCIQC5J5yC1LxKwtfQeVI5+KMOtr9YQeayrGVDDjAr3qjPhAIhAM9JqtJfoPczDTDTJUJPzu36s2P6kYP+GshW025XLJ1F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33843},"type":"module","engines":{"node":">=20"},"gitHead":"32cb9c19fa39132f814455c98431b56fcc4d2d1b","scripts":{"dev":"tsx watch src/server.ts","build":"rm -rf dist && tsc -p tsconfig.build.json","start":"tsx src/server.ts","inspect":"npx @modelcontextprotocol/inspector tsx src/server.ts","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"aarontropy","email":"aarontropy@gmail.com"},"repository":{"url":"git+https://github.com/byliner-dev/byliner.git","type":"git","directory":"apps/mcp-agent"},"_npmVersion":"10.9.0","description":"MCP server letting an AI agent submit actions for multi-party human approval via Byliner. Cannot approve, reject, or delegate — by design.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"zod":"^3.23.8","dotenv":"^16.4.5","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-agent_0.1.0_1784491573386_0.4969657150574158","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@byliner/mcp-agent","version":"0.2.0","type":"module","bin":{"byliner-mcp-agent":"dist/server.js"},"scripts":{"start":"tsx src/server.ts","dev":"tsx watch src/server.ts","inspect":"npx @modelcontextprotocol/inspector tsx src/server.ts","typecheck":"tsc --noEmit","build":"rm -rf dist && tsc -p tsconfig.build.json","prepack":"npm run build"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","dotenv":"^16.4.5","zod":"^3.23.8"},"devDependencies":{"@types/node":"^22.9.0","tsx":"^4.19.2","typescript":"^5.6.3"},"description":"MCP server letting an AI agent submit actions for multi-party human approval via Byliner. Cannot approve, reject, or delegate — by design.","keywords":["mcp","modelcontextprotocol","byliner","approval","human-in-the-loop","agent"],"license":"MIT","homepage":"https://byliner.dev","repository":{"type":"git","url":"git+https://github.com/byliner-dev/byliner.git","directory":"apps/mcp-agent"},"engines":{"node":">=20"},"publishConfig":{"access":"public"},"bugs":{"url":"https://github.com/byliner-dev/byliner/issues"},"_id":"@byliner/mcp-agent@0.2.0","gitHead":"bb1734bc64f871fef675c38aeaa09964ceb18dff","_nodeVersion":"22.12.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-c+57yxUhktm/FK+uFv5eB1FXBXwKenWMx2U4mZctojQwfF/5nLTIQOj/mhibLLtAPVAWOzviAwdGRNLmlnANVQ==","shasum":"aeca2565fd8372ed57c0b71e7ce285fa6901fd4a","tarball":"https://registry.npmjs.org/@byliner/mcp-agent/-/mcp-agent-0.2.0.tgz","fileCount":14,"unpackedSize":34247,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDqJE8VIzOSDFYTyGAKOJZNguwz8P2N3wfzpniqVO32/gIhAOc/C18nzo0qO1Xy0Kk2YlbQz40Ask6ssoHkByBUl3Kx"}]},"_npmUser":{"name":"aarontropy","email":"aarontropy@gmail.com"},"directories":{},"maintainers":[{"name":"aarontropy","email":"aarontropy@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-agent_0.2.0_1784593624299_0.4092798439945977"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-19T20:06:13.179Z","modified":"2026-07-21T00:27:04.636Z","0.1.0":"2026-07-19T20:06:13.528Z","0.2.0":"2026-07-21T00:27:04.450Z"},"bugs":{"url":"https://github.com/byliner-dev/byliner/issues"},"license":"MIT","homepage":"https://byliner.dev","keywords":["mcp","modelcontextprotocol","byliner","approval","human-in-the-loop","agent"],"repository":{"type":"git","url":"git+https://github.com/byliner-dev/byliner.git","directory":"apps/mcp-agent"},"description":"MCP server letting an AI agent submit actions for multi-party human approval via Byliner. Cannot approve, reject, or delegate — by design.","maintainers":[{"name":"aarontropy","email":"aarontropy@gmail.com"}],"readme":"# `@byliner/mcp-agent`\n\nMCP server that lets an agent submit actions for multi-party human approval.\n\nA thin adapter over the Byliner Engine API — it contains no business logic.\nSee [`docs/mcp-servers.md`](../../docs/mcp-servers.md) for the design rationale\nshared by both servers.\n\n## Tools\n\n| Tool | Engine call |\n|---|---|\n| `request_approval` | `POST /v1/approval-requests` (`Idempotency-Key` required) |\n| `get_approval_status` | `GET /v1/approval-requests/{id}` |\n| `cancel_approval` | `POST /v1/approval-requests/{id}/cancel` (`Idempotency-Key` required) |\n\n`request_approval` returns immediately with a pending id — it does not block\nwaiting for a decision. Poll `get_approval_status`.\n\n**There is no `approve`, `reject`, or `delegate` tool, by design.** An agent\ncannot decide its own request, and no agent can execute a human's decision.\nSee `docs/mcp-servers.md` §1.\n\n`cancel_approval` is not a decision — it withdraws a request this server's own\ncredential initiated. The engine refuses it for anyone else's request (403\n`cancellation_not_permitted`).\n\n## Environment variables\n\n| Var | Required | Default | Purpose |\n|---|---|---|---|\n| `BYLINER_API_KEY` | **yes** | — | Engine API key. Determines org, environment, and the principal this server acts as. |\n| `BYLINER_API_URL` | no | `http://localhost:4000` | Engine API base URL. |\n| `BYLINER_ACTOR_ASSERTION` | no* | — | Actor-identity assertion (the driving human's IdP JWT) layered on the API-key call, naming which human this agent acts for. Sent as `X-Byliner-Actor-Assertion`. *Required when the API key is an MCP key. |\n| `BYLINER_DASHBOARD_URL` | no | same as `BYLINER_API_URL` | Where `review_url` points. The deployed demo serves the dashboard and API from one origin, so the default is right there; local development needs `http://localhost:5173`. |\n| `BYLINER_TIMEOUT_MS` | no | `10000` | Per-request timeout. |\n\nThe seeded demo key is `byl_demo_codegen_agent_key` (printed by `pnpm seed`).\n\n### Identity comes from the credential, never from a tool call\n\nThe API key *is* this server's identity. The engine looks it up by hash and\nderives org, environment, and the acting principal from the match. Nothing here\nnames an actor, and no tool argument can influence one — a per-call identity\nparameter would let the calling model assert who is requesting, which is the\nself-asserted-initiator hole the design explicitly forbids.\n\n`BYLINER_ACTOR_ASSERTION` follows the same rule: read from the environment at\nstartup, never accepted per call. With none configured, an agent-key call\nproceeds on API-key-only attribution — a legitimate machine-initiated case (a\nCI/CD gate, a scheduled job). An MCP-key call, by contrast, requires it: the\nengine verifies the assertion and records that human as a co-requester who\ncannot approve the request. This is not enforced client-side; the engine decides\nwhat it accepts.\n\nThis replaced a `BYLINER_DEMO_ACTOR_ID` variable that existed only because the\nengine used to read the actor from an unverified header.\n\n## Running\n\n```bash\n# From the repo root, with the engine running on :4000\npnpm --filter @byliner/api dev\n\n# Then, in another shell:\nBYLINER_API_KEY=byl_demo_codegen_agent_key pnpm --filter @byliner/mcp-agent start\n```\n\nExercise the tools with the MCP Inspector:\n\n```bash\ncd apps/mcp-agent\nBYLINER_API_KEY=byl_demo_codegen_agent_key pnpm inspect\n```\n\n## Claude Desktop config\n\nAdd to `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"byliner-agent\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@byliner/mcp-agent\"],\n      \"env\": {\n        \"BYLINER_API_KEY\": \"byl_demo_codegen_agent_key\",\n        \"BYLINER_API_URL\": \"http://localhost:4000\"\n      }\n    }\n  }\n}\n```\n\nNo checkout required — `npx` fetches the published package. To run against a\nlocal checkout instead, use `[\"tsx\", \"/absolute/path/to/apps/mcp-agent/src/server.ts\"]`.\n\nThe transport is stdio, so the server logs to stderr only; anything written to\nstdout would corrupt the protocol stream.\n","readmeFilename":"README.md"}