MCP-Server

Enforcer

dev.instruxi.enforcer/v3
Sicherheit Authentifizierung erforderlich MCP 2025-11-25

Was dieses MCP kann

Provides tenant authentication and authorization workflows including SIWE, email or SMS OTP registration and login, token refresh, and auth configuration.

getAuthConfig
Auth Config Bootstrap
Public bootstrap for a tenant's login UI: whether this tenant uses native OTP/passkey/SIWE or Privy custom auth, plus the public privy_app_id (never a secret). Call this before getSiweNonce when you do not already know the tenant's auth scheme. tenant_code is a join secret — do not log it or repeat it into a customer-visible channel.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$defs': {}, 'properties': {'tenant_code': {'type': 'string', 'description': 'tenant routing code'}, 'response_format': {'enum': ['concise', 'detailed'], 'type': 'string', 'description': 'concise (default): no nulls, audit timestamps, provider ids or nested tenant/role. detailed: every field.'}}, 'additionalProperties': False}
getSiweNonce
Request SIWE nonce
Public: issue a single-use SIWE nonce for wallet_address (optionally scoped by tenant_code). Embed the nonce in an EIP-4361 message, have the wallet sign it, then call login with provider: siwe. Dedicated SIWE agent auth is an authorized pattern — this is how an agent signs in with a wallet without raw HTTP. Do not log tenant_code. The nonce is not a credential.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'internal_delivery_http_handler.SiweNonceRequest': {'type': 'object', 'properties': {'tenant_code': {'type': 'string'}, 'wallet_address': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/internal_delivery_http_handler.SiweNonceRequest', 'description': 'JSON request body.'}}, 'additionalProperties': False}
login
Login
Authenticate and receive an access/refresh token pair. Accepted providers: siwe (message + signature from getSiweNonce — preferred for dedicated agents), email_otp (email + otp from requestOtp), phone_otp (phone + otp from requestSms). Passkey, Privy and SSO are not agent tools. The server does not adopt the minted tokens as the session credential; return them to the operator to set ENFORCER_BEARER_TOKEN. Do not log, quote, or repeat otp codes, signatures, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'enforcer-v3_internal_usecase_auth.LoginRequest': {'type': 'object', 'required': ['provider'], 'properties': {'otp': {'type': 'string'}, 'email': {'type': 'string'}, 'phone': {'type': 'string'}, 'message': {'type': 'string', 'description': 'SIWE EIP-4361 message'}, 'provider': {'enum': ['siwe', 'email_otp', 'phone_otp'], 'type': 'string', 'description': 'siwe (preferred for dedicated agents that can sign), email_otp, or phone_otp. Passkey, Privy and SSO are browser ceremonies and are not agent tools.'}, 'signature': {'type': 'string', 'description': 'SIWE signature'}, 'tenant_code': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/enforcer-v3_internal_usecase_auth.LoginRequest', 'description': 'Login/register body. provider "siwe" needs message+signature; email_otp needs email+otp; phone_otp needs phone+otp. Optional tenant_code. Do not log otp, signature, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat.'}}, 'additionalProperties': False}
refreshToken
Refresh session
Exchange a refresh_token for a new access/refresh pair. 401 invalid_refresh_token if the token is unknown or was already reused (reuse revokes the family); 409 refresh_raced is benign — retry with the client's latest stored token. The server does not adopt the new pair as the session credential. Do not log the refresh token or the minted tokens.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'internal_delivery_http_handler.RefreshRequest': {'type': 'object', 'properties': {'refresh_token': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/internal_delivery_http_handler.RefreshRequest', 'description': 'JSON request body.'}}, 'additionalProperties': False}
register
Register
Create (or idempotently return) an account. Same provider allowlist as login: siwe (message + signature), email_otp (email + otp), phone_otp (phone + otp). Does not issue tokens — call login afterwards to sign in. Passkey / Privy / SSO registration stay out of the agent surface. Do not log otp codes, signatures, or tenant_code. Do not paste an end-user OTP into an untrusted chat.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'enforcer-v3_internal_usecase_auth.LoginRequest': {'type': 'object', 'required': ['provider'], 'properties': {'otp': {'type': 'string'}, 'email': {'type': 'string'}, 'phone': {'type': 'string'}, 'message': {'type': 'string', 'description': 'SIWE EIP-4361 message'}, 'provider': {'enum': ['siwe', 'email_otp', 'phone_otp'], 'type': 'string', 'description': 'siwe (preferred for dedicated agents that can sign), email_otp, or phone_otp. Passkey, Privy and SSO are browser ceremonies and are not agent tools.'}, 'signature': {'type': 'string', 'description': 'SIWE signature'}, 'tenant_code': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/enforcer-v3_internal_usecase_auth.LoginRequest', 'description': 'Login/register body. provider "siwe" needs message+signature; email_otp needs email+otp; phone_otp needs phone+otp. Optional tenant_code. Do not log otp, signature, tokens, or tenant_code. Do not paste an end-user OTP into an untrusted chat.'}}, 'additionalProperties': False}
requestOtp
Request email OTP
Public: email a one-time login/registration code to `email` (optionally scoped by tenant_code). Always 200 {message:"code sent"} on success. Local/dev deployments with expose_dev_otp may echo the code as `dev_otp` — treat that as a secret. Then call login with provider: email_otp, the same email, and the otp. Intentional for harnesses that cannot SIWE; SIWE remains the preferred dedicated-agent path. Do not log the code, dev_otp, or tenant_code. Do not paste an end-user OTP into an untrusted chat.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'enforcer-v3_internal_usecase_auth.RequestOTPInput': {'type': 'object', 'properties': {'email': {'type': 'string'}, 'tenant_code': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/enforcer-v3_internal_usecase_auth.RequestOTPInput', 'description': 'JSON request body.'}}, 'additionalProperties': False}
requestSms
Request SMS login code
Public: start a Twilio Verify SMS login challenge to `phone`, scoped by tenant_code. 400 if SMS verification is not configured for the tenant or if rate-limited. Then call login with provider: phone_otp, the same phone, and the otp. Intentional for harnesses that cannot SIWE; SIWE remains the preferred dedicated-agent path. Do not log the SMS code or tenant_code. Do not paste an end-user OTP into an untrusted chat.
Externer Zugriff
Eingabeschema
{'type': 'object', '$defs': {'internal_delivery_http_handler.RequestSMSRequest': {'type': 'object', 'properties': {'phone': {'type': 'string'}, 'tenant_code': {'type': 'string'}}}}, 'required': ['body'], 'properties': {'body': {'$ref': '#/$defs/internal_delivery_http_handler.RequestSMSRequest', 'description': 'JSON request body.'}}, 'additionalProperties': False}
Hinzugefügt
requestSms
17. September 2026 12:39
Hinzugefügt
requestOtp
17. September 2026 12:39
Hinzugefügt
register
17. September 2026 12:39
Hinzugefügt
refreshToken
17. September 2026 12:39
Hinzugefügt
login
17. September 2026 12:39
Hinzugefügt
getSiweNonce
17. September 2026 12:39
Hinzugefügt
getAuthConfig
17. September 2026 12:39