Kai Ase Siren
Skip to content

Features

What mcp-beaver ships today. It turns an umbra Guardfile into a guarded MCP server with a matching HTTP tool API, distributed as one runtime image plus a generic Helm chart.

Commands

  • serve.md - the generic runtime, grant-to-tool projection.
  • lint.md - offline validation, and lint-upstream.
  • spec-mode.md - swagger-resolved grants.
  • inherit.md - tiers that compose the sibling nodes as well as the grants, and flatten.
  • upstream.md - the guarded passthrough proxy, as flags or as a mcp-upstream guardfile the chart mounts, the credential it presents upstream, and the withhold stubs it states.
  • pull.md - pull, an mcp-upstream guardfile written from a registry entry and the upstream's own readOnlyHint.
  • version - the release this binary was built from, stamped at build time and advertised in every MCP handshake. See release.md.
  • directory.md - directory, the registry swept into a guardfile per server, a sweep record, and the two pages that index them.
  • oauth2.md - oauth2-client, the one credential this runtime mints rather than reads.
  • ssm.md - the exact-parameter AWS reader.
  • s3.md - the asset publisher, and the one write-capable mode.

Guardfile surface

Runtime

Distribution. - release.md is the installable binary and its Homebrew formula. image.md, ci.md, chart.md, and chart-values.md are the image the fleet deploys.

See also