MCP Server

Raziel

io.github.tide-foundation/raziel
Developer Tools Security Public & reachable MCP 2025-11-25

What this MCP does

Provides implementation guidance, playbooks, diagnostics, and security analysis for TideCloak authentication, encryption, identity governance, and access control.

tide_adapter
Read an adapter instruction file (AGENTS, CLAUDE, replit)
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Adapter file name. Available: AGENTS, CLAUDE, replit'}}, 'additionalProperties': False}
tide_blast_radius
Run a Blast Radius Assessment of an EXISTING app: an adversarial, vendor-neutral map of where authority is concentrated to a single point (whoever obtains that one thing obtains everything it governs), scored by blast radius (Total/Systemic/Contained/Limited) across three cores — Identity, Governance, Access — and delivered as a director-facing PDF. Phase 1 names no vendor; an opt-in Phase 2 companion explains how TideCloak shrinks each blast radius. Use this when the user wants to 'assess', 'red team', 'threat model', 'find the security gaps in', or make a before/after security case for an existing application.
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
tide_branding
BRAND THE ENCLAVE FOR THE USER — generate a logo + background and upload them so the Tide login/approval screen is branded. Returns a single ready-to-run command that generates the assets (no image model needed), validates them, uploads both, and saves+signs the IdP settings. Also returns the VERIFIED upload contract (multipart parts, the png/jpg/jpeg/gif/webp allowlist with SVG REJECTED, the 5 MB cap, set-branding = save AND re-sign, IGA-exempt) plus image-model prompts for agents that can generate images. Pass realm/accent/appName to get the command pre-filled. CALL THIS whenever branding, a logo, a background, theming or 'skinning' the enclave or login screen comes up — then RUN the command; do not just describe it.
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'realm': {'type': 'string', 'description': "Realm to brand, e.g. 'myapp'. Fills in the command."}, 'accent': {'type': 'string', 'description': "Hex accent colour without '#', e.g. '2f6f4e'. Default 1f6feb."}, 'appName': {'type': 'string', 'description': "App name. Deterministically varies the mark's geometry so realms look distinct."}, 'tidecloakUrl': {'type': 'string', 'description': 'Base URL. Default http://localhost:8080.'}}, 'additionalProperties': False}
tide_canon
Read a canon file (invariants, anti-patterns, concepts, framework-matrix, feature-mapping, troubleshooting, tidecloak-bootstrap, etc.)
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Canon file name. Available: agent-authority, anti-patterns, breach-precedents, concepts, custom-contracts, feature-mapping, framework-matrix, hosting-options, iga-change-requests-api, invariants, redirect-handler, security-gap-mapping, security-runtime-probes, tide-neutralization, tidecloak-bootstrap, tidecloak-endpoints, tidify-compatibility, troubleshooting, ux-states, verifiable-claims, version-policy'}}, 'additionalProperties': False}
tide_choose_playbook
Recommend the right playbook for a given situation
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['situation'], 'properties': {'situation': {'type': 'string', 'description': "Describe what the builder wants to do, e.g. 'add login to a new Next.js app'"}}, 'additionalProperties': False}
tide_choose_scenario
Match a user request to a known scenario pattern before falling back to generic playbooks
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['situation'], 'properties': {'situation': {'type': 'string', 'description': "Describe the app or problem, e.g. 'build an organisation password manager'"}}, 'additionalProperties': False}
tide_dpop_asset
Returns the CONTENTS of `public/tide_dpop_auth.html` — the DPoP relay page the Tide enclave loads during login — plus its sha256, the required next.config.ts rewrite/CSP wiring, and how to verify. The file is NOT shipped in the @tidecloak/* npm packages and is NOT in the TideCloak container, so there is nowhere else to get it: without this tool people search GitHub and find a STALE copy that posts to window.parent, which breaks the popup fallback and fails login with TIDE-SWE-UNHANDLED. CALL THIS whenever DPoP is enabled (it is on by default), whenever a login fails with TIDE-SWE-UNHANDLED or 'Popup DPoP verification failed to load', and before copying this file from anywhere else.
Read only
Input schema
{'type': 'object', 'properties': {}}
tide_gaps
Read the gap register — what is still uncertain or unresolved in the pack
Read only
Input schema
{'type': 'object', 'properties': {}}
tide_hosting
Where TideCloak runs: local Docker vs partner-hosted (Skycloak managed TideCloak-as-a-service). Returns the local-vs-hosted decision with the honest trade-offs, the trust model, the verified Skycloak API reference (correct cluster field names and the required version), and the full provisioning playbook. CALL THIS BEFORE STARTING ANY TIDECLOAK DEPLOYMENT — the choice must be made up front (I-17) because a realm cannot be moved between local and hosted afterwards. Triggers: 'deploy to production', 'deploy TideCloak', 'go live', 'host this somewhere', 'managed option', 'stable URL', 'can someone host TideCloak for us', or any request to stand up an instance where local-vs-hosted has not been settled.
Read only
Input schema
{'type': 'object', 'properties': {}}
tide_list
List all available content in the Tide agent pack by category
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['category'], 'properties': {'category': {'enum': ['canon', 'playbooks', 'skills', 'prompts', 'adapters', 'scenarios', 'all'], 'type': 'string', 'description': "Which category to list, or 'all' for everything"}}, 'additionalProperties': False}
tide_list_scenarios
List all available scenario patterns under reference-apps/
Read only
Input schema
{'type': 'object', 'properties': {}}
tide_onboarding
STOP KEYCLOAK'S 'UPDATE ACCOUNT INFORMATION' PAGE and collect the details in-app instead. Tide asserts ONLY a username (the vuid) -- no email, no name -- so Keycloak blocks new users on an unstyled form showing a 64-hex username. Returns: a read-only DIAGNOSTIC that identifies which of FOUR mechanisms is causing the page (they need different fixes), the script that fixes it, and a ready-to-drop React modal that collects the details AFTER login via the Account API. CALL THIS whenever signup, onboarding, 'Update Account Information', a profile/details form, or 'what users see after they create an account' comes up -- and ALSO proactively once a realm is bootstrapped, because the default is that every new user hits that page.
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'realm': {'type': 'string', 'description': "Realm, e.g. 'vialproof'. Fills in the commands."}, 'fields': {'type': 'array', 'items': {'enum': ['displayName', 'firstName', 'lastName', 'email'], 'type': 'string'}, 'description': "Which fields to collect. ASK THE USER FIRST â\x80\x94 do not guess. Default ['firstName','lastName']."}, 'appName': {'type': 'string', 'description': "App name, e.g. 'Mood Garden'. Used in the modal's copy."}, 'framework': {'enum': ['nextjs-app', 'nextjs-pages', 'react-vite'], 'type': 'string', 'description': 'Controls the mounting snippet. Default nextjs-app.'}, 'tidecloakUrl': {'type': 'string', 'description': 'Base URL. Default http://localhost:8080.'}, 'componentPath': {'type': 'string', 'description': "Where to WRITE the component, e.g. 'src/components/ProfileOnboarding.tsx'."}}, 'additionalProperties': False}
tide_playbook
Read a step-by-step playbook for a specific Tide task
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Playbook name. Available: add-auth-nextjs-existing, add-auth-nextjs-fresh, add-rbac-nextjs, bootstrap-realm-from-template, configure-e2ee-roles-and-policies, deploy-forseti-policy, deploy-tidecloak-docker, diagnose-broken-login, diagnose-missing-roles-or-claims, initialize-admin-and-link-account, migrate-from-existing-auth, protect-api-nextjs, protect-aspnet-core-asgard, protect-routes-nextjs, provision-tidecloak-skycloak, setup-forseti-e2ee, setup-iga-admin-panel, start-tidecloak-dev, verify-jwt-server-side'}}, 'additionalProperties': False}
tide_prompt
Read a reusable starter prompt from the pack
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Prompt file name. Available: add-admin-approval-flow, build-private-customer-portal, migrate-generic-auth-to-tide, red-team-review, secure-existing-app, security-gap-analysis'}}, 'additionalProperties': False}
tide_scenario
Read a scenario summary from reference-apps/<scenario>/scenario.md
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Scenario name. Available: attested-provenance-registry, encrypted-communication, git-pr-signing-service, iga-admin-governance, organisation-password-manager, policy-governed-signing'}}, 'additionalProperties': False}
tide_scenario_bootstrap
Read a scenario bootstrap sequence from reference-apps/<scenario>/bootstrap-sequence.md
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Scenario name. Available: attested-provenance-registry, encrypted-communication, git-pr-signing-service, iga-admin-governance, organisation-password-manager, policy-governed-signing'}}, 'additionalProperties': False}
tide_scenario_manifest
Read a scenario manifest from reference-apps/<scenario>/manifest.yaml
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Scenario name. Available: attested-provenance-registry, encrypted-communication, git-pr-signing-service, iga-admin-governance, organisation-password-manager, policy-governed-signing'}}, 'additionalProperties': False}
tide_scenario_roles
Read a scenario role-policy matrix from reference-apps/<scenario>/role-policy-matrix.md
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Scenario name. Available: attested-provenance-registry, encrypted-communication, git-pr-signing-service, iga-admin-governance, organisation-password-manager, policy-governed-signing'}}, 'additionalProperties': False}
tide_security_analysis
Analyze an EXISTING (possibly non-Tide) system for security gaps and map them to Tide capabilities. Returns the Security Analyst role instructions, the security gap mapping table (SG-01…SG-18), and the runtime-probe procedures. Use this when the user asks 'do a security analysis', 'where is my auth weak', or 'what would Tide change about my security'.
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'include_runtime_probes': {'type': 'boolean', 'description': 'Include the runtime-confirmation probe procedures (canon/security-runtime-probes.md). Only relevant when the operator is authorized to probe a live target. Defaults to true.'}}, 'additionalProperties': False}
tide_skill
Read a composable skill definition
Read only
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Skill name. Available: grc-review, tide-diagnostics, tide-integration, tide-learning-capture, tide-mcp-qa, tide-rbac-and-e2ee, tide-red-team, tide-reviewer, tide-route-and-api-protection, tide-scenario-resolver, tide-security-analyst, tide-setup, tide-solutions-architect'}}, 'additionalProperties': False}
Added
tide_gaps
Sept. 17, 2026, 12:52 p.m.
Added
tide_branding
Sept. 17, 2026, 12:52 p.m.
Added
tide_onboarding
Sept. 17, 2026, 12:52 p.m.
Added
tide_dpop_asset
Sept. 17, 2026, 12:52 p.m.
Added
tide_hosting
Sept. 17, 2026, 12:52 p.m.
Added
tide_blast_radius
Sept. 17, 2026, 12:52 p.m.
Added
tide_security_analysis
Sept. 17, 2026, 12:52 p.m.
Added
tide_choose_playbook
Sept. 17, 2026, 12:52 p.m.
Added
tide_choose_scenario
Sept. 17, 2026, 12:52 p.m.
Added
tide_scenario_bootstrap
Sept. 17, 2026, 12:52 p.m.
Added
tide_scenario_roles
Sept. 17, 2026, 12:52 p.m.
Added
tide_scenario_manifest
Sept. 17, 2026, 12:52 p.m.
Added
tide_scenario
Sept. 17, 2026, 12:52 p.m.
Added
tide_list_scenarios
Sept. 17, 2026, 12:52 p.m.
Added
tide_adapter
Sept. 17, 2026, 12:52 p.m.
Added
tide_prompt
Sept. 17, 2026, 12:52 p.m.
Added
tide_skill
Sept. 17, 2026, 12:52 p.m.
Added
tide_playbook
Sept. 17, 2026, 12:52 p.m.
Added
tide_canon
Sept. 17, 2026, 12:52 p.m.
Added
tide_list
Sept. 17, 2026, 12:52 p.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…