arifOS MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GEOX_BRIDGE_HOST | No | Override host for GEOX bridge. | http://127.0.0.1:8081 |
| WELL_BRIDGE_HOST | No | Override host for WELL bridge. | http://127.0.0.1:18083 |
| AAA_MCP_TRANSPORT | No | Transport mode for MCP server (stdio or sse). Default is auto-detected. | |
| WEALTH_BRIDGE_HOST | No | Override host for WEALTH bridge. | http://127.0.0.1:18082 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tasks | {
"list": {},
"cancel": {},
"requests": {
"tools": {
"call": {}
},
"prompts": {
"get": {}
},
"resources": {
"read": {}
}
}
} |
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| arif_initA | KERNEL 000 · Session ignition — not a helper app. Binds actor, floors, and audit before any other arif_* verb can govern. Without session_id, kernel treats you as anonymous (OBSERVE_ONLY / SYUBHAH). Authority: pre-session open; light/init mint session_id + authority band. Modes: ping | light | init | resume | validate | epoch_open | epoch_seal | canary | preflight | triage. Returns: session_id, actor_verified, authority, allowed_next_verbs, next_tool. Skip when live session already bound → arif_triage; pure facts only → arif_observe. |
| arif_observeA | KERNEL 111 · Sense reality into evidence (not reasoning, not judgment). Web/URL/vitals/repo/entropy with epistemic tags. Authority: L0 OBSERVE. Modes: search | fetch | ingest | compass | atlas | entropy_dS | vitals | repo_map | hybrid_discovery. Returns: evidence + sources + uncertainty. Skip when pure reasoning → arif_think; domain compute → arif_route to GEOX/WEALTH/WELL. |
| arif_thinkA | KERNEL 333 · Mind — structure reasoning under F2/F7 (not a chat model, not a verdict). Plan, reflect, verify, synthesize with OBS/DER/INT/SPEC labels. Authority: L0–L1. Modes: reason | reflect | verify | plan | plan_review | plan_approve | refactor_plan | metabolize | axioms. Returns: structured reasoning + confidence + next_safe_action. Ethical/maruah risk → arif_critique. Binding decision → arif_judge. Facts → arif_observe. |
| arif_routeA | KERNEL 444 · Intent→organ router (default path to GEOX/WEALTH/WELL/A-FORGE). Select when you know the goal but not which organ/verb. Optional organ_tool+arguments = governed bridge call (prefer this over arif_bridge_connect). Authority: L0. Returns: organ, port, tool_prefix, suggested_tools. Not session preflight (use arif_triage). Not a free shell. |
| arif_bridge_connectA | KERNEL 444-direct · Low-level organ call (organ + tool_name required). Bypasses intent routing. Authority: HIGH / lease — often 888_HOLD for anonymous. Agents should prefer arif_route (same reach, safer default). Not a generic MCP proxy; only federation organs under kernel envelope. |
| arif_critiqueA | KERNEL 555 · Heart — ethical/dignity/risk stress before judgment (not SEAL). Select when blast_radius MEDIUM+, human/dignity impact, or irreversible risk. Requires non-empty target (proposal/plan text). Authority: L1. Modes: critique | redteam | maruah | deescalate | empathize | simulate | instruction_scan. Returns: risk, floors, human impact. Skip pure technical with zero human stake. Binding verdict → arif_judge. |
| arif_memoryB | KERNEL memory governor · L1–L6 stack under F1/F2/F4/F11 (not a free notepad). Recall/inspect free-ish; remember/promote/revise/forget are J-space mutations. Authority: recall L0; writes gated. Modes: recall | inspect | attest | remember | promote | revise | forget. Skip ephemeral one-off facts. |
| arif_judgeA | KERNEL 888 · Constitutional verdict — only organ that SEAL/HOLD/SABAR/VOIDs. Not advice; binding arbitration of floors + authority. Authority: 888_HOLD / SOVEREIGN session required for real adjudicate. REQUIRES: actor, intent, domain, reversibility_level, blast_radius (+ evidence). Modes: judge | compare | history | explain | floor_status | witness_consensus. Skip if evidence incomplete → arif_observe; plan incomplete → arif_think; reversible low-risk advisory only. |
| arif_forgeC | KERNEL 777 · Execution gate via A-FORGE (hands, not law). Mutates only after arif_judge SEAL + lease/chain IDs — no self-authorize. Authority: 888_HOLD without SEAL. Modes include dry_run | engineer | query | write. Public execution verb (arif_act is internal alias only). Skip while still planning (arif_think) or without judge SEAL. |
| arif_composeA | KERNEL reply · Final human-facing composition (citations, tone, ΔS≤0). Call LAST after observe/think/judge — not mid-pipeline. Authority: L0–L1. Modes: compose | summarize | cite | tone_shift | style | format. Not a substitute for arif_judge or arif_seal. |
| arif_sealB | KERNEL 999 · VAULT999 immutable append — civilizational memory, irreversible. Authority: 888_HOLD / SOVEREIGN + ack_irreversible for seal mode. Modes: seal | verify | chain | list | dry_run | seal_card | render. Seal only after SEAL verdict path; HOLD/SABAR/VOID do not seal. Testing → dry_run. Kernel judges; vault seals; Arif owns F13 veto. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| arifosmcp_loop_engineer | Intent classification + session init. Converts raw user intent into governed loop circuit. METABOLIC/OBSERVE/REASON/CRITIQUE/JUDGE/FORGE/SEAL/COMPOSITE. Routes to correct organ. Max 3 SABAR cycles before HOLD. Repo-agnostic and entropy-reducing. |
| 000_init | 000_INIT — Anchor identity, frame reality, accept F1-F13. Cross-session memory: reads prior assumption ledger from VAULT999. Loads inherited gaps and restores human direction. APEX: A (Observation). |
| 111_sense | 111_SENSE — Witness reality as it IS. Map facts, forces, actors. Epistemic labels (OBS/DER/INT/SPEC/UNKNOWN). Multiple framings (N≥2). Computes F2 score. Lowers ambiguity, not just data hunger. APEX: A. |
| 333_reason | 333_REASON — Extract principles, generate hypotheses (N≥3), map scenarios (3-5), propose reality changes. Computes F7 score. Invariant and cross-domain by design. APEX: P. |
| 555_critique | 555_CRITIQUE — Consequence scan, 7-viewpoint perspective shift, deep dignity check, alternatives scan. Computes F5+F6 scores. Preserves optionality and human clarity. APEX: X. |
| 666_judge | 666_JUDGE — Four tests (Truth/Reversibility/Dignity/Universality) + F1-F13 floor matrix with computed scores. Verdict: SEAL/SABAR/HOLD/VOID. General principles over local preference. APEX: P. |
| 777_forge | 777_FORGE — Pre-forge checklist, step-by-step execution (smallest reversible first), guardrails, rollback plan. STRUCTURAL GATE: cannot execute without SEAL verdict + FORGE_READY. Must reduce uncertainty about reality, not merely mutate state. APEX: E. |
| 999_seal | 999_SEAL — Golden path verification, reality change receipt, assumption ledger (cross-session memory), VAULT999 seal manifest. Recursive hardening + future direction pack. IRREVERSIBLE. APEX: X. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| Constitutional Doctrine | The immutable 13-floor constitution (F1–L13) that governs all arifOS operations. Includes Amanah, Truth, Witness, Clarity, Peace, Empathy, Humility, Genius, Anti-Hantu, Ontology, Auth, Injection, and Sovereign. All tools and agents must operate within these floors. |
| AAA Trinity Lanes | The AAA Trinity lane architecture: AGI proposes (111), ASI judges (444), APEX authorizes (888), FORGE executes (010), 999 seals. Defines which tools belong to which lane and which domain language each lane uses. SEAL/SABAR/HOLD/VOID are APEX-only verdict terms. |
| Canonical Schema | Complete canonical blueprint of the arifOS MCP surface. Lists all 12 canonical tools organized by 9-stage metabolic loop + preflight + bridge + memory governor, 13 constitutional floors (F1–F13), and the separation of powers doctrine. Use as the reference map for the entire constitutional kernel. |
| Civilizational Ontology | The seven federation organs (arifOS, A-FORGE, GEOX, WEALTH, WELL, AAA, APEX), three intelligence strata (AGI, ASI, APEX), constitutional boundaries between domain organs and the kernel, and entropy responsibility model. Defines which organs DECIDE vs WITNESS vs COMPUTE vs REFLECT. |
| Seal Readiness & Vault Integrity | Vault integrity report and seal gate requirements. Defines the five disambiguated seal types, the seven-floor seal gate, and the non-seal verdicts (SABAR/HOLD/VOID). Bare SEAL without namespace is non-compliant. |
| Jurisdiction & Autonomy Bands | The five autonomy bands (GREEN through BLACK) that govern agent freedom, the CapabilityGrant registry for secretless execution, and jurisdiction rules. Agents hold grants, never raw secrets. Autonomy is a leased capability, not a permanent possession. All tools mapped to their autonomy band. |
| Sovereign Identity Manifest | Sovereign identity manifest bound from identity.toml at boot. Defines the authority chain from APEX (Arif) through arifOS kernel to domain organs and execution. Includes ADR-001 localhost doctrine. Identity is the root of accountability — all attestation chains begin here. |
| Memory Architecture (L1–L6) | The six-layer memory architecture: L1 ephemeral (Redis), L2 session (Redis), L3 semantic (Qdrant/BGE-M3), L4 structured (Supabase), L5 relationships (Graphiti), L6 immutable (VAULT999). Memory does not become truth until it has provenance. Truth does not become final until sealed. |
| Constitutional Vitals Reference | Static reference for constitutional vitals: metric definitions, green/yellow/red thresholds, and what each metric means. For LIVE values, use arif_measure(mode=health). This resource is the dictionary, not the reading. |
| Federation Bootstrap Context | Complete arifOS federation knowledge-graph bootstrap context. Delivers the full world model: organ identities, agent roster, current runtime state, constitutional law (F1-F13), ROOTKEY/EUREKA modules, known open loops, safe defaults, tasking template, and epistemic style guide. Fetch this when you need the complete federation map in one call. v2026.06.14. |
| 7-Stage Reality Engineering Loop | Documents the arifOS 7-stage reality engineering loop: arifosmcp_loop_engineer (entry guard) + 000_init/111_sense/333_reason/555_judge/666_critique/777_forge/999_seal. Each stage has dual naming (K1: numeric internal ID + function name). Includes organ routing table, reversibility classification, blast radius, evidence truth hierarchy, and uncertainty substrate mapping. MCP prompt surface is at arifosmcp_prompts module. |
| LLM Client Quickstart | Getting started guide for LLM clients connecting to arifOS MCP. Covers: endpoint, transport, auth, 13 canonical tools, 13 resources, 8 prompts, 7 stages, key constitutional rules (F1-F13), when to use arifOS vs direct organ, and VAULT999 ledger guidance. Read this first before using the server. |
| MCP Spec Conformance Matrix | Current conformance status of arifOS vs. MCP 2025-11-25 specification. Covers core spec (tools, resources, prompts), extensions (JSON Schema 2020-12, Pagination, Tasks, MCP Apps, OAuth), transport, auth/security posture, deprecations, live resource inventory, and client compatibility matrix. Use to understand what an MCP client can expect from this server before connecting. |
| get_tree777_index | TREE777 wiki full index. Lists all skills (by category), concepts, and scars in the canonical wiki. Use this to discover what resources are available before fetching individual pages. |
| human_metabolized | Metabolized sovereign context — compact human intelligence. Returns the structured signal that changes how AI behaves around this human. Not the full testimony — the nutrient. Source: scar-terrain-arif-fazil.md (SOVEREIGN_TESTIMONY) Derived: 2026-06-16, FORGE (000Ω) |
| reality_state_resource | Causally-consistent multi-layer reality snapshot. Returns current state of PHYSICAL, DIGITAL, BIOLOGICAL, and UNCERTAINTY_SUBSTRATE reality layers at one consistent timestamp. Every value carries epistemic label (OBS/DER/INT/SPEC/UNKNOWN). Uncertainty substrate maps quantum-physics metaphor to classical decision engineering. |
| get_surface_map | Return the canonical arifOS Agent Surface Map showing tools, resources, and rules. |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ariffazil/arifos'
If you have feedback or need assistance with the MCP directory API, please join our Discord server