Serveur MCP

Alter Onboarding

io.github.AlterAIDev/alter-onboarding
Outils développeur Sécurité Public et accessible MCP 2025-11-25

Ce que fait ce MCP

Guides developers through Alter API integrations with provider operation schemas, SDK patterns, authentication flows, runtime policies, verification, and troubleshooting.

fetch_doc
Fetch any page of the Alter documentation by slug (e.g. "quickstart"). The whole published docs site is bundled here, skill pages included, so every page a doc, a skill or a flow step links to can be read in-band. Accepts any spelling the docs use: a bare slug, a leading slash, a #section anchor, a full docs.alterauth.com URL, or an older path that now redirects. Omit the slug to list every page.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'slug': {'type': 'string', 'maxLength': 200, 'description': 'Doc slug, e.g. "guides/call-apis-on-behalf-of-users".'}}}
get_operation_schema
Fetch one provider API operation's full contract — method, path, parameters, request/response schemas — live from Alter's provider-spec catalog, plus the spec's source and freshness. Get operation ids from list_operations first.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['provider_id', 'operation_id'], 'properties': {'kind': {'enum': ['oauth', 'managed'], 'type': 'string', 'description': 'Provider family: oauth (user-authorized) or managed (API-key).'}, 'provider_id': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Provider id, e.g. "google" or "github".'}, 'operation_id': {'type': 'string', 'maxLength': 500, 'minLength': 1, 'description': 'Operation id from list_operations, e.g. "gmail.users.messages.list".'}}}
get_started
Begin or change an Alter integration. Without args: lists the phases. With `phase`: returns that phase's flows + a heuristic hint — classify the use case YOURSELF and call again with `goal` for the plan. If the use case spans multiple flows, run them sequentially.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'goal': {'enum': ['user-data', 'backend-secret', 'agent', 'add-provider', 'add-secret', 'add-agent', 'rotate-key', 'manage-grant', 'set-policy'], 'type': 'string', 'description': "The flow id YOU classified. Returns that flow's full plan."}, 'phase': {'enum': ['setup', 'modify'], 'type': 'string', 'description': 'setup (integrate from scratch) or modify (change an existing integration).'}, 'use_case': {'type': 'string', 'maxLength': 2000, 'description': 'Plain-English description of what the developer wants.'}}}
list_operations
List the API operations a provider exposes, live from Alter's provider-spec catalog (e.g. "what can I call on google?"). Returns operation ids + methods/paths, plus the spec's source and freshness. Omit `kind` to auto-detect the provider family; when the id exists in both oauth and managed you'll be asked to pass `kind`. Machine-readable rows ride in `structuredContent` (see this tool's outputSchema) — read those rather than parsing the prose.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['provider_id'], 'properties': {'kind': {'enum': ['oauth', 'managed'], 'type': 'string', 'description': 'Provider family: oauth (user-authorized) or managed (API-key).'}, 'limit': {'type': 'integer', 'maximum': 500, 'minimum': 1, 'description': 'Max operations to return (backend default 100, max 500).'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Zero-based offset for paging through large operation lists.'}, 'search': {'type': 'string', 'maxLength': 200, 'description': 'Case-insensitive filter over operation ids/paths/summaries.'}, 'provider_id': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Provider id, e.g. "google" or "github".'}}}
Schéma de sortie
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['provider_id', 'provider_kind', 'spec_version', 'total', 'offset', 'operations'], 'properties': {'total': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Total operations matching the query (before limit/offset).'}, 'offset': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Zero-based offset of the first row.'}, 'operations': {'type': 'array', 'items': {'type': 'object', 'required': ['operation_id', 'method', 'path_template', 'summary'], 'properties': {'method': {'type': 'string', 'description': 'HTTP method, e.g. GET.'}, 'summary': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'description': 'One-line description, or null when the spec omits it.'}, 'operation_id': {'type': 'string', 'description': 'Pass to get_operation_schema for the full contract.'}, 'path_template': {'type': 'string', 'description': 'Path with {placeholders}, e.g. /repos/{owner}/{repo}.'}}, 'additionalProperties': False}, 'description': "This page of operations, in the catalog's serving order."}, 'provider_id': {'type': 'string', 'description': 'Resolved provider id the rows belong to.'}, 'spec_version': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': "Alter's ingested spec version these rows came from."}, 'provider_kind': {'enum': ['oauth', 'managed'], 'type': 'string', 'description': 'Resolved provider family: oauth or managed.'}}, 'additionalProperties': False}
list_phases
List the lifecycle phases this server serves (setup, modify) and what each is for.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
list_providers
List every provider with an ingested API spec in Alter's provider-spec catalog, with each spec's source and freshness. Optionally filter by `kind`. Start here, then call list_operations for a provider's operations.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'kind': {'enum': ['oauth', 'managed'], 'type': 'string', 'description': 'Provider family: oauth (user-authorized) or managed (API-key).'}}}
list_skills
List the guidance Skills available on this server, with the phase each serves. Read a skill via its resource (skill://alter/<name>).
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
next_step
Return the next step for a flow. Pass the goal (flow id) and the id of the last completed step (omit `after` for the first step). Run each step's detect command FIRST and skip the run command when detection passes. The design step also returns that flow's complete starter ALTER_INTEGRATION.md.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['goal'], 'properties': {'goal': {'enum': ['user-data', 'backend-secret', 'agent', 'add-provider', 'add-secret', 'add-agent', 'rotate-key', 'manage-grant', 'set-policy'], 'type': 'string', 'description': 'The flow id (setup goal or modify operation).'}, 'after': {'type': 'string', 'maxLength': 10, 'description': 'Id of the last completed step (e.g. "2", "3a").'}}}
policy_language
The authoritative grammar of Alter's runtime-policy language, live from the deployed backend: every authorable rule type with its JSON body schema, caps, authorable levels, worked examples, and fail-closed semantics. Call with no arguments for the overview; pass `rule_type` (e.g. "content_match") for one type's full grammar. Use it before authoring rules with `alter policy rules create` — never guess a body shape. Vocabulary: the dashboard's "Runtime policies" surface, the docs' "policy", and `alter policy` are one feature, and the dashboard's "Require human approval" type is the `require_approval` rule type (its grant-editor block is the grant-level baseline of the same gate). The same grammar is what policy files carry: `alter policy validate|test|plan|apply` review rules in Git and CI, and a rule with a `code_owner` is changed through its file, never with `rules update`. Workflow prose: the `set-policy` modify flow (`get_started` with phase=modify), fetch_doc("guides/set-policies"), fetch_doc("guides/add-human-in-the-loop-approvals"), fetch_doc("guides/policy-as-code"), and fetch_doc("reference/cli/commands/policy").
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'rule_type': {'type': 'string', 'maxLength': 50, 'minLength': 1, 'description': 'One rule type\'s full grammar, e.g. "content_match" or "quota".'}}}
sdk_integration
Return the Alter SDK wiring (install + client init + request) to write into the developer's codebase, for a language and setup goal.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['language', 'goal'], 'properties': {'goal': {'enum': ['user-data', 'backend-secret', 'agent'], 'type': 'string', 'description': 'The setup goal (user-data | backend-secret | agent).'}, 'language': {'enum': ['python', 'typescript'], 'type': 'string', 'description': 'Target language.'}}}
sdk_pattern
Return a runnable Alter SDK call pattern for a language: `proxy-call` (zero-egress proxy_request + HITL), `resolve-grant-by-user` (call as an end user via their delegated grant), `delegate-managed-secret` (the operator-side delegation step), or `resolve-ambiguous-grant` (an identity-mode call matched several of one user's grants: choose deliberately, never the first, and persist it; ask the developer at design time whether users can hold several accounts per provider). Use AFTER `sdk_integration` has wired the client.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['language', 'pattern'], 'properties': {'pattern': {'enum': ['proxy-call', 'resolve-grant-by-user', 'delegate-managed-secret', 'resolve-ambiguous-grant'], 'type': 'string', 'description': 'proxy-call | resolve-grant-by-user | delegate-managed-secret | resolve-ambiguous-grant.'}, 'language': {'enum': ['python', 'typescript'], 'type': 'string', 'description': 'Target language.'}}}
search_docs
Search every bundled page of the Alter documentation (docs and skill pages) by keywords: returns the best-matching pages with the section and a snippet that matched. Use it when a flow step or doc did not point you at the page you need, instead of guessing slugs or listing every page; then read one with fetch_doc and its slug.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 20, 'minimum': 1, 'description': 'Maximum results (default 8, at most 20).'}, 'query': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Keywords or a short phrase, e.g. "connect widget popup" or "PAT scopes login".'}}}
troubleshoot
Map a @alter-ai/cli exit code or error message to a remediation.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'error': {'type': 'string', 'maxLength': 10000, 'description': 'The stderr / error message.'}, 'exit_code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'The CLI process exit code.'}}}
verify_integration
Return a copy-pasteable recipe to VERIFY an integration works: `first-call` (code↔design, an audit row, correct attribution) or `per-user-isolation` (a multi-user/broker server runs two users under different credentials and rejects cross-user access). Guidance only — you run the commands.
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['scenario'], 'properties': {'scenario': {'enum': ['first-call', 'per-user-isolation'], 'type': 'string', 'description': 'first-call | per-user-isolation.'}}}
Modifié
policy_language
1 October 2026 02:44
Ajouté
search_docs
19 September 2026 02:41
Modifié
fetch_doc
19 September 2026 02:41
Modifié
sdk_pattern
19 September 2026 02:41
Ajouté
policy_language
17 September 2026 12:40
Ajouté
get_operation_schema
17 September 2026 12:40
Ajouté
list_operations
17 September 2026 12:40
Ajouté
list_providers
17 September 2026 12:40
Ajouté
fetch_doc
17 September 2026 12:40
Ajouté
verify_integration
17 September 2026 12:40
Ajouté
troubleshoot
17 September 2026 12:40
Ajouté
sdk_pattern
17 September 2026 12:40
Ajouté
sdk_integration
17 September 2026 12:40
Ajouté
next_step
17 September 2026 12:40
Ajouté
get_started
17 September 2026 12:40
Ajouté
list_skills
17 September 2026 12:40
Ajouté
list_phases
17 September 2026 12:40

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…