API Tools
azielcorpuslibrary.net
FragGate is an MCP server that provides a single-door registry for discovering, verifying, describing, and executing software capabilities through a gated pipeline.
ENDPOINT 1
https://www.azielcorpuslibrary.net/runtime/mcp
MCP server metadata
- Name
- aziel-runtime
- Version
- 2.0.0-rc1
Aziel Runtime is not merely an API orchestrator or software aggregator; it is a node-meshed orchestration suite of MCP-connected software designed to coordinate specialized tools through a shared, security-gated runtime while preserving provenance, chain-of-custody, temporal integrity, and auditable execution. Use Aziel Eliab software in this chat. One door — discover, route, refuse. Pipeline: (1) fraggate_list or GET /v1/software (2) fraggate_describe one name (3) fraggate_call. Prefer FragGate, GET /v1/software, and POST /mcp. Hubs refresh Software tabs from /v1/software. Start with runtime_skill or fraggate_list. Describe a name with fraggate_describe. Execute only through fraggate_call (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return). decisiongate_check is the named live gate. library_lookup is read-only corpus search. Show the user display.title and display.summary, then take the next input. runtime_run, runtime_session_*, raw *_health, and runtime_manifest are advanced/internal. Do not call flat {slug}_{op} names — they are not in tools/list. Unknown names refuse FG-HALLUC-TOOL. HTTP /p/{slug}/{op} is a proxy and is not exec. LIVE fabric (not Softwares-tab): AZPIPE AP-WP-0.2, SweepGate SG-WP-0.1, ChainLock CL-WP-0.4, LOCKSET LS-WP-0.1, packed catalog RL-WP-0.1-runtime, QNS-CD-1.0 (photon QNS1 1.3; local qnsd in AzielEliab/qnm-node; GET /v1/qns cites only — never a public via proxy), AKM-TRIAD-1.0 adaptive memory (MCP memory_*; POST /v1/memory/* behind FragGate). MCP chainlock_*. suite-presence is operator-enabled. GET /v1/mesh never enables. GET /v1/azpipe/arch cites the locked MASTER-33 strip (same FragGate pipeline payload; not a Softwares door). 2.0.0-rc1 is the certification-point freeze (docs/2.0/ public contract, compatibility, receipt schema, refusal contract, breaking-change policy, clean-room + external adversarial pack; self-test ≠ third-party lab). No intentional behavioral breaks from 1.9.3. Remain-OFF untouched. 1.9.3 closes remaining AZRT-1.9-GAPS-CLOSE items (isolate AZ-OS session VFS; isolate-safe jeeves; binding-gated media-run; published attestation path — not a third-party lab). Remain-OFF untouched. 1.9.2 binds Workers Browser Rendering (BROWSER) and live D1 MASTER (CORPUS_D1 → aziel-digital-library records). Whisper/OCR Workers-AI-bound. Sample MASTER remains the unbound fallback. Chromium product UI is not claimed; Tor/phoenix stay refuse. Remain-OFF untouched. 1.9.1 closes AZRT-1.9-GAPS-CLOSE (isolate-safe corpus verify ops; Whisper/OCR Workers-AI-gated; AZBrowser sandbox_status Chromium DEFERRED unbound; AZMail transport_status no public MTA; wave 2–3 doctor; adversarial self-check + Actions npm test; remain-OFF untouched). 1.9.0 closes AZRT-1.9-CLOSE-1.0 (AZMail isolate mailbox; AZChat LIVE+bound; isolate hash store; OpenAPI proxy-path parity; remain-OFF untouched). 1.7.10 makes QNM Live Nodes durable (cron or request-path fan-out of live Softwares product Workers while suite-presence is enabled; TTL 5 min; GET never enables). 1.7.9 cross-maps AZCoherence (peers azclce / AZInterface / AKM-TRIAD fabric neighbor; hubs + Worker URL; domain stays null). 1.7.8 lands EmbryoLock as a true in-process engine (Vault/Custody with ARK; live-with-local-destructive-boundary). LIVE_OPS health/skill/doctor/verify-hash/policy/limitation. Wipe/scorch/unlock-after-fail stay FG-STUB on the public mesh. Softwares worker_home embryolock-download-tracker. 1.7.7 lands AZCoherence (AZC-0.1) as a true in-process FragGate Softwares engine (second-pass triad coherence; cite https://github.com/AzielEliab/AZCoherence; not AKM-TRIAD). 1.7.6 syncs 4DMap LIVE_OPS with product 0.2.0 (pin/span/stack/gap/fork/walk/lens/class/cohort/absence/cap/join/list/example plus frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite; inspection frame after AZPIPE, not an extra door). 1.7.5 is Softwares capability wave 1 (decisiongate / forgereceipts / temporallock / staticclock / chronolock / trajectorylock / spectrallock). 1.7.4 enhances 4DMap LIVE_OPS (frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite; inspection frame after AZPIPE, not an extra door). 1.7.3 aligns audit WARN copy (exist.mcp → tools/list; public FragGate call; catalog count_note; 4DMap not an extra door). 1.7.2 adds GET /v1/azpipe/arch (MASTER-33 cite/read). 1.7.1 adds AKM-TRIAD-1.0 (Adaptive Knowledge Recollection, Bayesian Calibration & 3-of-4 Triad Selection). 1.7.0 locks MASTER-33: Human → AZInterface → PUBLIC/UI/AGENT/API → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance/Input Packet → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return. FragGate is THE single door. Lamb Lens is fabric after FragGate. LambGate is not a hop. 1.6.15 locked the suite hop order (SUITE-PIPE-1.6.15; historical). 1.6.14 adds 4DMap (4DM-WP-1.0) as a FragGate-live engine — four-axis inspection frame T/Δ/Γ/Π after AZPIPE; not a sequential gate and not an extra door. LIVE_OPS health/skill/card_new/card_pin/card_span/card_join/card_walk/card_list/verify_hash. 1.7.6 adds product 0.2 verbs plus frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite. truth_score/lumen_panel/invent_mark/backdate_class stay stub. FragGate claims cite join types. 1.6.13 aligns the suite QNM rollup (QNM-BUILD-1.0, companion to AIH-WP-1.1): GET /v1/mesh live/locked/isolated counts; operator enable requires a declared bearer; default radios off; not a login mesh; full node process is local qnm-node/. 1.6.12 adds GET /v1/software (hub Software-tab catalog; Plain→Gate→Lock + EmbryoLock stub) and GET /v1/update/check. 1.6.11 adds a durable FragGate op alias map so Worker UI button names (azhub list_modules/place, azinterface genesis_boot/hold, azbrowser airlock/home, azmail classify, aznet doctor/pair, peacelock doctor) resolve to catalog LIVE_OPS. EmbryoLock is stub / local-not-hosted (name only; describe?slug=embryolock; not a FragGate engine). 1.6.10 sets AZBrowser and AZNet catalog one_line to separate software (not engine). Same FragGate door. 1.6.9 frames AZHub and AZInterface as two separate softwares under the same FragGate door (AIH-WP-1.0) — Blank Key spatial container + custodial page cycles. Never one combined product. Hub refuses auto-unlock / completeness. Interface page_cycle_status reports OFF / integrity / ON / FULL SHUTDOWN / MEMORIAL. AZHub LIVE_OPS (health, skill, region_list, place_module, remove_module, tether_declare, tether_cut, tether_list, blank_key_status) and AZInterface LIVE_OPS (health, skill, genesis_status, site_state_get, site_state_set, integrity_check, witness_list, page_cycle_status) are listed by fraggate_list and executed only via fraggate_call / POST /v1/fraggate/call. 1.6.7 adds AZNet (AZN-WP-0.1) as a FragGate-live engine — silent verification side-net; never hosts payloads; AZBrowser pair required (functional order only; own Worker UI). AZNet is reached only via fraggate_call / POST /v1/fraggate/call (flat leftover names still map through FragGate; not a side door). 1.6.6 adds AZBrowser (AZB-1.0) as a FragGate-live engine — Lamb Lens ethical research browser: ethical search + advisory navigate; cite; refuse harmful harvest; never invent visit results; not Chromium. AZNet is separate software (same FragGate door; order/token pairing only, not a shared Phase-1 UI). AZBrowser LIVE_OPS (ethical_search, lamb_lens_search, navigate, airlock_ingest, tab_open, tab_list, receipt_list, verify, receipt_verify, sandbox_status, sandbox_render, health, skill) are listed by fraggate_list and executed only via fraggate_call / POST /v1/fraggate/call — the same ops Worker UI buttons call. 1.6.5 adds AZMail (APP 1.0) as a FragGate-live engine — anonymous mesh default off, advisory airlock; SMTP/deanonymize stay stub. AZMail is reached only via fraggate_call / POST /v1/fraggate/call (flat leftover names still map through FragGate; not a side door). 1.6.4 adds PeaceLock (PL-WP-0.1) as a true in-process engine. 1.6.3 adds KV-backed API use trackers (GET /v1/uses). 1.6.2 widens the public door to sensible advisory engines; stubs still refuse. 1.6.0 is the FragGate door cut on in-process engines. 1.5.0 was agent-native flat product tools. Kernel: https://github.com/AzielEliab/fraggate (FG-0.1). Every catalog slug is a true engine. Cloudflare isolate is the jail. engine_digest is required. Hosted AZAI is protocol mirror + Lamb check, not the blend. VPN/hop mesh is not claimed on this public surface. AZMail anonymous ring is FragGate LIVE_OPS only (default off; not SMTP). Compatible clients: ChatGPT, Grok, Venice, Claude, Cursor, Glama, Perplexity, Copilot, Gemini, Mistral, Meta AI, Apple Intelligence, Amazon Q, DuckAssist, You.com, Cohere, plus other MCP/OpenAPI-capable assistants. Always send User-Agent Mozilla/5.0. Public, no OAuth. Author: Aziel Eliab only.
Known tools 36
runtime_skillRead how an agent uses Aziel Eliab software: one door — discover, route, refuse (pipeline fraggate_list → fraggate_describe → fraggate_call; hubs use GET /v1/software).
Inferred read-onlyfraggate_listList hashed FragGate registry entries (live / stub / local_only) for discovery first.
Inferred read-onlyfraggate_describeInspect one known FragGate capability: live vs stub vs local_only, public ops, and engine_digest.
Inferred read-onlyfraggate_verifyConfirm a name, slug, or engine_digest against the hashed FragGate registry.
Inferred read-onlyfraggate_callExecute a known catalog slug+op through the FragGate single door (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return).
Potential side effectsdecisiongate_checkRun the named DecisionGATE five sequential gates on a proposal (Freedom without clarity is chaos).
Inferred read-onlylibrary_lookupSearch the Aziel Digital Library (aziel-corpus search / example / skill).
Inferred read-onlymesh_statusRead the QNM-BUILD-1.0 suite rollup (companion to AIH-WP-1.1): enabled?, declared bearers, live/locked/isolated counts.
Inferred read-onlymesh_enableOperator-enable the QNM suite rollup by declaring a bearer (same as POST /v1/mesh/enable).
Potential side effectsmesh_joinRegister a product node for QNM rollup counts (same as POST /v1/mesh/join).
Potential side effectsmesh_heartbeatRefresh a node's 5-minute QNM presence TTL (same as POST /v1/mesh/heartbeat).
Potential side effectsmesh_nodesList the QNM rollup roster with live/locked/isolated presence (5-minute TTL; same as GET /v1/mesh/nodes).
Inferred read-onlymesh_broadcastRegister the SHA-256 of a local communique as a hash receipt — never a publish path.
Potential side effectschainlock_appendAppend a fact-bearing stamp to a local ChainLock chain (CL-WP-0.4).
Inferred read-onlychainlock_verifyFail-closed verify of ChainLock chains and LOCKSET (LS-WP-0.1): broken prev, tip drift, missing GodLock cite.
Inferred read-onlychainlock_sealSeal live chain tips + TemporalLock receipt + GodLock cite into a LOCKSET (LS-WP-0.1).
Inferred read-onlymemory_observeAppend a memory_observation to the ChainLock learn chain (AKM-TRIAD-1.0).
Inferred read-onlymemory_calibrateCalibrate a memory with the deterministic 3-of-4 triad plus Bayesian posterior (AKM-TRIAD-1.0).
Inferred read-onlymemory_getRead-only explainability for one memory: node, history, or calibration (posterior, triad legs, effective N, Brier).
Inferred read-onlyruntime_softwareRead the authoritative hub catalog (GET /v1/software): every product including AZChat LIVE+bound, sorted Plain A–Z → Gate A–Z → Lock A–Z (Clock ≠ Lock).
Inferred read-onlyruntime_bundleRead a compact bootstrap of every product skill URL and invoke prefix.
Inferred read-onlyruntime_pullOpen one product card by slug: name, version, skill, download, and ops.
Inferred read-onlyruntime_run[advanced/internal] Advanced exec façade: admit a slug+op (still DecisionGATE-admitted) and run it through a raw session.
Potential side effectsruntime_manifest[advanced/internal] Read the machine runtime manifest (version, role, door=fraggate, engine slugs, registry_digest).
Inferred read-onlyruntime_session_exec[advanced/internal] Raw session exec for an already-open session.
Potential side effectsruntime_session_receipt[advanced/internal] Read the last receipt for a raw session.
Inferred read-onlyruntime_session_receipts[advanced/internal] Read the full receipt list for a raw session.
Inferred read-onlyruntime_session_close[advanced/internal] Seal a raw session so further exec is rejected.
Potential side effectsCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.aziel-runtime]
url = "https://www.azielcorpuslibrary.net/runtime/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"aziel-runtime": {
"type": "http",
"url": "https://www.azielcorpuslibrary.net/runtime/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: aziel-runtime
Remote MCP URL: https://www.azielcorpuslibrary.net/runtime/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"aziel-runtime": {
"url": "https://www.azielcorpuslibrary.net/runtime/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"aziel-runtime": {
"type": "http",
"url": "https://www.azielcorpuslibrary.net/runtime/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "aziel-runtime",
"transport": "streamable-http",
"url": "https://www.azielcorpuslibrary.net/runtime/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Loading Trust v2 evidence…
Checking the associated registrable domain. The BuiltWith key remains server-side.
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.