Skip to main content
Glama
OktoLabsAI

okto-nexus

by OktoLabsAI

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
artifact_putC

Register a file/text/json/markdown/html artifact in the resolved workspace. Docs: okto-nexus://reference/tool-docs/artifacts.

artifact_getA

Retrieve an artifact by id within the workspace resolved from project_root. Reads are audience-scoped: a caller outside the frozen audience gets NOT_FOUND (indistinguishable from a missing id).

event_getA

Read a cursor-paginated page of the event log (non-blocking). Actors outside your comm scope are omitted; yours and system events always show. Docs: okto-nexus://reference/tool-docs/events.

event_cursorA

Return the stream's CURRENT END as a cursor (O(1), no scan) - the pre-flight monitor anchor so you see only events appended after now. Returns {cursor} (0 for empty).

event_waitA

Read the event log; optionally long-poll (0/omitted/null = snapshot; >0 blocks). Scoped like event_get (actors outside your comm scope omitted). Patterns: okto-nexus://reference/monitoring.

handoff_createA

Create an OPEN handoff (validates target/visibility); emit handoff.created. After creating, poll handoff_get for status/result. Full docs: okto-nexus://reference/tool-docs/handoff.

handoff_list_availableA

Expire leases, then list OPEN handoffs visible+eligible to the caller (paginated); entries are metadata-only until claimed.

handoff_claimA

Atomically claim an OPEN handoff; single winner, others get a structured error. Returns the payload + claimed_by/lease_expires_at. In strict mode pass session_id + session_secret.

handoff_completeA

Owner-only delivery of a CLAIMED handoff: -> COMPLETED, or -> VERIFYING when acceptance_criteria were set (verifier decides via handoff_verify). In strict mode pass session creds.

handoff_verifyB

Verifier-only verdict on a VERIFYING handoff: 'pass' -> COMPLETED (verified_by), 'fail' -> CLAIMED for rework (feedback + renewed lease). In strict mode pass session creds.

handoff_rejectA

Reject a handoff (owner CLAIMED->REJECTED or direct-target OPEN->REJECTED). In trust_mode=strict pass session_id + session_secret.

handoff_cancelA

Creator-only OPEN -> CANCELLED; retract a handoff nobody should take (e.g. a pool target matching zero agents). Only OPEN handoffs cancel. In strict mode pass session creds.

handoff_getA

Read a handoff by id: status, claimant, payload, result/rejected_reason + verification/dependency fields if set. The creator's path to the outcome. Full docs: okto-nexus://reference/tool-docs/handoff.

coordination_healthA

Windowed coordination-health report for the workspace: aggregated ok|warn status, 7 metric blocks and thresholds. Requires feature_health and health.read.

workspace_resolveB

Resolve a project_root to its deterministic workspace_id and upsert it.

agent_registerA

Update YOUR OWN profile (role/capabilities/metadata); SELF-ONLY (else PERMISSION_DENIED). Capabilities are fail-closed against the central catalog. Docs: okto-nexus://reference/tool-docs/identity.

agent_whoamiA

Return YOUR OWN profile: agent_id, role, capabilities, metadata, permissions, effective_policies + governance, plus communication style when set. Docs: okto-nexus://reference/tool-docs/identity.

session_openA

Open a session bound to (agent_id, workspace_id); returns a per-session session_secret (ONLY here - keep it; required by sensitive verbs in strict mode). Heartbeat to receive broadcasts.

session_heartbeatA

Advance a session heartbeat and report the derived status; keeps you PRESENT (in the broadcast audience) and clear of the stale-session reaper.

session_closeB

Close a session (idempotent); repeating returns ok and stays closed.

workspace_listA

GLOBAL-ADMIN: enumerate ALL workspaces. Paths OMITTED by default (include_paths=true is an admin/ops opt-in). For discovery use agent_list / capability_list.

agent_listA

List registered agents (global), each with role/capabilities and last_seen_at. Authenticated callers see only agents their comm scope can reach (plus themselves); anonymous callers see all.

agent_getA

Return one agent's details incl. last_seen_at. Scoped by reachability: an agent outside your comm scope reads as NOT_FOUND, indistinguishable from a non-existent agent_id.

capability_listB

List the capability catalog merged with owners: every registered name (with description; agent_count 0 if unowned), agents scoped to your comm reach. Normalised as capability routing matches.

inbox_pullA

Take your unread messages into in-flight and return them WITH body (index-free; no cursor). At-least-once: unacked pulls are redelivered. Docs: okto-nexus://reference/tool-docs/inbox.

inbox_ackA

Acknowledge messages into history (read). Returns {acknowledged, read_message_ids}. Emits a message.read receipt to each sender.

inbox_extendA

Renew the lease on in-flight messages you pulled but have not finished (now + extend_seconds). All-or-nothing: if any id is not in-flight the call fails per-message and nothing is extended.

inbox_peekA

Triage pending messages (unread + in-flight) WITHOUT consuming. READ-ONLY, envelope-only by default (body_preview + body_bytes). include_parked/include_bodies opt in.

inbox_countA

Return your inbox lane sizes {unread, in_flight, read}. Cheap READ-ONLY between-turns check (pull when unread > 0). Expired in-flight leases count as unread; parked excluded.

inbox_historyA

List your acknowledged (read) messages, newest-first, keyset-paginated (stable pages even while you keep acknowledging). READ-ONLY.

message_statusA

Track a message you SENT: per-recipient delivery states {recipient, status, attempts, read_at} (unread/delivered/read/parked). READ-ONLY.

message_createA

Persist a message and fan it out to recipient inboxes; emit message.created. The response confirms delivery (recipients + delivered_count). Full docs: okto-nexus://reference/tool-docs/messages.

channel_createA

Create a channel by name (idempotent; created=false if it already existed). Channels are organizational labels, not ACLs.

channel_listB

Return the workspace channels (general is seeded by default).

message_getA

MIGRATED (S3): replaced by inbox_pull / inbox_peek / inbox_history. Always returns ok:false code=MIGRATED with the replacement call.

message_listA

MIGRATED (S3): replaced by inbox_peek / inbox_history (your messages) and event_get (bus traffic). Always returns ok:false code=MIGRATED.

message_waitA

MIGRATED (S3): replaced by inbox_count polling (cheap) or event_wait (explicit blocking). Always returns ok:false code=MIGRATED.

poll_token_issueA

Issue an ephemeral read-only monitor bearer (nxsept_...) for this authenticated agent's session workspace. Store only in the background monitor; never persist the raw token.

poll_token_renewA

Rotate and extend the active ephemeral poll token for this session. The previous raw nxsept_ bearer stops working immediately.

poll_token_revokeB

Revoke the active ephemeral poll token for this session.

shared_md_renderB

Render the per-workspace human-readable shared.md (atomic overwrite).

tag_listA

List the global operator-managed tag catalog (keys + values) that agent tags, comm_scope and tag targets are validated against fail-closed.

nexus_infoA

Report server versions: package_version, schema_version, surface_revision, resource_versions, features (read-only {feature_*: bool}). Call when behaviour disagrees with cached schemas.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
Pre-flight (full)The exact first-turn bootstrap sequence, in full detail.
Communication & inboxIntent-based choice among handoff, broadcast message and direct message, plus channels, inbox reception and delivery/read receipts.
Monitoring & event listeningevent_get/event_wait observability vs the inbox, MCP background listeners, EPT remote pollers for wake-capable harnesses, monitor invariants, reference loops, and anti-patterns.
Routing target grammarThe full routing-target grammar (every strategy shape, rules, examples, edge cases) shared by message_create and handoff_create.
Tool docs - messages & channelsFull reference for message_create / channel_create / channel_list and the migrated message_get/list/wait shims.
Tool docs - inboxFull reference for the per-recipient inbox tools (pull/ack/extend/peek/count/history/message_status).
Tool docs - event logFull reference for event_get / event_cursor / event_wait (streams, filters, cursors, the long-poll).
Tool docs - handoffFull reference for the handoff lifecycle (create/list_available/claim/complete/verify/reject/cancel/get), including the opt-in VERIFYING cycle and DAG dependencies.
Tool docs - identity & sessionsFull reference for workspace/agent/session tools (resolve, whoami, register, list, get, capability_list, session open/heartbeat/close, workspace_list).
Tool docs - artifactsFull reference for artifact_put / artifact_get.
Governance policiesOperator-attached policies (bindings): actions, limit kinds, deny-overrides semantics, windows, and the POLICY_DENIED / QUOTA_EXCEEDED error format.
Human-in-the-loop approvalsWhat a pending_approval envelope means, which approval.* events to watch via event_wait, how a rejection reaches you, and why you must never re-send while pending.

TDQS

A3.5/5.0

Scored across 43 tools

Disambiguation4/5

The tool set covers many distinct sub-domains (handoffs, inbox, events, sessions, etc.), and most tools have clearly differentiated purposes. However, some read-oriented tools overlap (event_get/event_wait, inbox_pull/inbox_peek) and three legacy message_* tools are deprecated but still present, which could momentarily confuse an agent.

Naming Consistency5/5

All 43 tools use consistent snake_case with a domain_action pattern (e.g., handoff_create, inbox_pull, poll_token_issue). The only variation is minor compound forms like handoff_list_available, but the convention is predictable and uniform.

Tool Count2/5

43 tools is well above the typical 3–15 range and even excluding the 3 deprecated message tools leaves 40. This heavy surface likely burdens agents and exceeds what the server’s purpose requires.

Completeness4/5

The surface covers CRUD-like lifecycle for handoffs, inbox, sessions, events, artifacts, agents, workspaces, and poll tokens, with no dead ends in core workflows. Minor gaps exist (no artifact list/delete, no agent/channel delete), but agents can work around them.

Maintenance

ActivityActive
ResponsivenessSlow