tessera
Enables interaction with Appwrite's web application by compiling its routes into a terminal, allowing agents to discover and execute backend actions.
Provides a terminal interface for Cal.com's web application, exposing routes for scheduling and calendar management to agents.
Allows agents to navigate and interact with dev.to's web platform, compiling its routes into a terminal for content and community actions.
Offers a terminal-like interface to Firefly III's web application, enabling agents to manage financial data through its exposed routes.
Enables agents to interact with Gitea's web interface, compiling its routes into a terminal for repository and project management.
Provides a terminal interface for Medusa's web application, allowing agents to discover and execute commerce-related routes and actions.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@tesseraScan my repository and list all available routes with their permissions"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Tessera — Agent Terminal for the Web
Tessera compiles any website into a structured, governed terminal that AI agents navigate via MCP. Instead of parsing DOM trees or taking screenshots, agents get named screens with typed actions — a CLI for the web.
Install
pip install -e ".[dev]"
pytest evals/ conformance/ -vRelated MCP server: ai-agent-layer
What it does
Compiler reads your route definitions from source code (10 web frameworks)
Contract wraps discovered routes in governance (permissions, rate limits, spend ceilings, trust tiers)
Terminal exposes the contract as MCP tools over JSON-RPC
Agent navigates the terminal to complete tasks
Trust model
Trust is derived from cryptographically signed credentials, never self-declared.
An operator generates an Ed25519 key pair, registers the public key with the terminal, and signs JWTs for their agents. The terminal verifies the signature, checks expiration, validates the audience, rejects replayed tokens, and caps the trust tier at the operator's registered maximum.
No field in the connect request lets an agent choose its own permissions.
See docs/trust-model.md for the full architecture.
Governance enforcement
Every contract field actually binds at runtime:
Field | Enforcement |
| Sliding window on audit log |
| Checked at connect |
| Validated against quantity params |
| min(operator claim, contract ceiling) |
| Rolling 24h accumulator, capped by contract |
| Expired contracts refuse all connections |
| Required for actions in |
Contract validation catches dangerous omissions: a contract that permits transactions but omits max_transaction_amount fails validation.
MCP server
The server uses the official MCP Python SDK (v2.2.0) and speaks JSON-RPC 2.0:
Transport | Use case |
Streamable HTTP | Web-accessible terminal |
stdio | Claude Desktop, local MCP clients |
Five tools: tessera_connect, tessera_get_screen, tessera_execute, tessera_audit_log, tessera_disconnect.
Supported frameworks
Framework | Pattern | Tested on |
FastAPI |
| RealWorld, FastAPI Full-Stack |
Rails |
| Forem/dev.to (341 routes) |
Go (Chi/Echo) |
| Gitea (162 routes) |
NestJS |
| Twenty CRM (101 routes) |
Next.js files |
| Cal.com (131 routes) |
Next.js App Router |
| Medusa (51 routes) |
Next.js pages |
| Papermark (379 routes) |
tRPC |
| Documenso (102 routes) |
PHP/Utopia |
| Appwrite (186 routes) |
Laravel |
| Firefly III (502 routes) |
Benchmarks
Source parser tested against 13 real GitHub repos: 2,203 routes extracted, 100% precision (zero false positives).
Full evaluation data: BENCHMARKS.md. Governance eval results: RESULTS.md.
Test suite
pytest evals/ conformance/ -v162 tests across 8 test files:
File | Tests | What it covers |
| 19 | Schema, parser, package hygiene |
| 23 | Sign, verify, audience, replay, TTL, validation |
| 10 | Self-declared trust is rejected |
| 23 | MCP tools, sessions, errors |
| 38 | Every governance field binds |
| 15 | Enforcement through terminal engine |
| 18 | Governance boundary eval (15 tasks) |
| 16 | MCP protocol conformance |
Project structure
tessera-project/
├── tessera/ # Python package (Apache-2.0)
│ ├── compiler/ # Route discovery (source parser, HTTP probing, OpenAPI)
│ ├── contract/ # Schema, resolver, enforcement, credentials, validation
│ ├── terminal/ # Engine, agents, registry
│ └── mcp/ # MCP server (official SDK)
├── simulations/ # 18 test sites (525+ endpoints)
├── evals/ # Test suite + Phase 5 governance eval harness
├── conformance/ # MCP protocol conformance tests
├── docs/ # Published documentation
│ └── trust-model.md # Trust model architecture
├── BENCHMARKS.md # Compiler evaluation data
├── RESULTS.md # Governance eval results
├── SECURITY.md # Security policy, fixed vulnerabilities
└── CONTRIBUTING.md # Contributor guide + boundary ruleKnown limitations
Workflow inference: The compiler extracts routes, not workflows. It knows
GET /productsandPOST /ordersexist but doesn't know the orderingsearch → cart → checkout → payment.LLM agent evals: The governance eval suite uses scripted sequences. pass@1 with real LLM agents (Phase 5b) requires Ollama and is not yet built.
License
Apache-2.0 — see LICENSE.
The open core is fully functional standalone. Commercial features (registry, analytics, audit) live in a separate repository and import tessera as a dependency — never the inverse.
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed app access for AI agents: 1,000+ apps & 12,000+ tools via Code Mode MCP.
Turn any public website into an MCP server for agents to search, read and navigate.
Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Related MCP Servers
- FlicenseBqualityCmaintenanceCompiles any website into typed, callable tools for AI agents, enabling discovery and invocation of live web APIs and UI actions without custom MCP servers.81-
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to interact with any website through MCP, providing structured knowledge graph contexts, generated actions, and readiness scoring.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to interact with websites by capturing browser traffic and exposing them as named MCP tools, requiring no public API.Apache 2.0
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to semantically inspect, search, and navigate web application pages through MCP, with security guardrails and nested route awareness.-