KYA-OS MCP Server
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@KYA-OS MCP Servercheck the checkpoint status of this server"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
KYA-OS MCP Server
A ready-to-deploy Model Context Protocol server, protected by KYA-OS Checkpoint. Deploy it in one click, point an MCP client at it, and every agent that connects is verified by the KYA-OS detection engine — running in-process, no gateway round-trip — before it can reach your tools.
Railway: a one-click button is coming — Railway deploys published templates by code (
railway.com/new/template/<code>), so it needs this repo published as a Railway template first. For now, deploy it on Railway from the repo directly (New Project → Deploy from GitHub repo).
What you get
A working MCP server at
/api/mcp(streamable HTTP) with two example tools — swap in your own.Checkpoint protection via
withCheckpointfrom@kya-os/checkpoint-nextjs— the Rust detection engine runs in-process (WASM), and enforcement is driven by your dashboard policy.Zero-config deploy — a standard Next.js 16 App Router app; Vercel / Railway / Netlify detect and build it automatically.
Related MCP server: production-grade-mcp-agentic-system
One-click deploy
Click a Deploy button above.
When prompted, paste two values from your Checkpoint project settings:
CHECKPOINT_PROJECT_ID— binds this server to your project's policy.CHECKPOINT_API_KEY— authenticates the policy fetch.
Deploy. Your MCP endpoint is live at
https://<your-deployment>/api/mcp.
Secrets are entered on the platform, never in a URL. Without them the server still runs, using the engine's default detection instead of your dashboard policy.
Connect an MCP client
Point any MCP client at your endpoint. For example, in a client that uses mcp.json:
{
"mcpServers": {
"kya-os": {
"url": "https://<your-deployment>/api/mcp"
}
}
}Then call the checkpoint_status tool to confirm which project is protecting the server.
Local development
cp .env.example .env.local # add your CHECKPOINT_* values
npm install
npm run dev # http://localhost:3000 · MCP at /api/mcpHow Checkpoint protects it
middleware.ts wires withCheckpoint across every route (including /api/mcp). The engine
verifies each request locally and applies your project's policy — block, challenge-for-delegation,
or observe — which you configure in the dashboard. Because verification is in-process, there's no
per-request network hop.
// middleware.ts
import { withCheckpoint } from '@kya-os/checkpoint-nextjs';
export default withCheckpoint({
tenantHost: process.env.CHECKPOINT_TENANT_HOST ?? 'localhost:3000',
projectId: process.env.CHECKPOINT_PROJECT_ID,
apiKey: process.env.CHECKPOINT_API_KEY,
});Add your own tools
Tools live in app/api/[transport]/route.ts. Each server.tool(...) becomes callable by any
connected MCP client:
server.tool(
'get_weather',
'Return the current weather for a city.',
{ city: z.string() },
async ({ city }) => ({
content: [{ type: 'text', text: `It's sunny in ${city}.` }],
})
);Going further — verifiable agent delegation
This template uses Checkpoint's detection layer. If you want agents to present a
cryptographically verifiable, capability-scoped delegation (a user grants an agent a
time-boxed, read-vs-write-separated credential from their own passkey-backed identity), see the
Hobbsidian reference app, which builds on @kya-os/id and
@kya-os/mcp.
Learn more
Checkpoint dashboard & docs — kya.vouched.id
Model Context Protocol — modelcontextprotocol.io
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceMCP Server for AI agent identity and authorization. Create, verify, and manage agent identities with trust scores and scoped authorization tokens.Last updatedMIT
- Alicense-qualityDmaintenanceA production-grade MCP server designed for multi-tenant, authenticated, and observable AI agent systems, enabling secure tool execution across heterogeneous data sources.Last updated52MIT
- Alicense-qualityCmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.Last updated1MIT

Outfitofficial
Alicense-qualityAmaintenanceAn MCP server that enforces agent persona permissions by acting as a gateway, scoping tool access and denying unauthorized capabilities.Last updated286MIT
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
An MCP Server that provides identity verification and anti-fraud tools for AI agents via deepidv.
The MCP server for Azure DevOps, bringing the power of Azure DevOps directly to your agents.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/kya-os/mcp-server-template'
If you have feedback or need assistance with the MCP directory API, please join our Discord server