← Registry

API Tools

azielcorpuslibrary.net

FragGate is an MCP server that provides a single-door registry for discovering, verifying, describing, and executing software capabilities through a gated pipeline.

1 endpoint36 known toolsFirst detected September 12, 2026Last detected September 12, 2026

ENDPOINT 1

https://www.azielcorpuslibrary.net/runtime/mcp

No auth detected

MCP server metadata

Name
aziel-runtime
Version
2.0.0-rc1
Capabilities
tools
Server instructions

Aziel Runtime is not merely an API orchestrator or software aggregator; it is a node-meshed orchestration suite of MCP-connected software designed to coordinate specialized tools through a shared, security-gated runtime while preserving provenance, chain-of-custody, temporal integrity, and auditable execution. Use Aziel Eliab software in this chat. One door — discover, route, refuse. Pipeline: (1) fraggate_list or GET /v1/software (2) fraggate_describe one name (3) fraggate_call. Prefer FragGate, GET /v1/software, and POST /mcp. Hubs refresh Software tabs from /v1/software. Start with runtime_skill or fraggate_list. Describe a name with fraggate_describe. Execute only through fraggate_call (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return). decisiongate_check is the named live gate. library_lookup is read-only corpus search. Show the user display.title and display.summary, then take the next input. runtime_run, runtime_session_*, raw *_health, and runtime_manifest are advanced/internal. Do not call flat {slug}_{op} names — they are not in tools/list. Unknown names refuse FG-HALLUC-TOOL. HTTP /p/{slug}/{op} is a proxy and is not exec. LIVE fabric (not Softwares-tab): AZPIPE AP-WP-0.2, SweepGate SG-WP-0.1, ChainLock CL-WP-0.4, LOCKSET LS-WP-0.1, packed catalog RL-WP-0.1-runtime, QNS-CD-1.0 (photon QNS1 1.3; local qnsd in AzielEliab/qnm-node; GET /v1/qns cites only — never a public via proxy), AKM-TRIAD-1.0 adaptive memory (MCP memory_*; POST /v1/memory/* behind FragGate). MCP chainlock_*. suite-presence is operator-enabled. GET /v1/mesh never enables. GET /v1/azpipe/arch cites the locked MASTER-33 strip (same FragGate pipeline payload; not a Softwares door). 2.0.0-rc1 is the certification-point freeze (docs/2.0/ public contract, compatibility, receipt schema, refusal contract, breaking-change policy, clean-room + external adversarial pack; self-test ≠ third-party lab). No intentional behavioral breaks from 1.9.3. Remain-OFF untouched. 1.9.3 closes remaining AZRT-1.9-GAPS-CLOSE items (isolate AZ-OS session VFS; isolate-safe jeeves; binding-gated media-run; published attestation path — not a third-party lab). Remain-OFF untouched. 1.9.2 binds Workers Browser Rendering (BROWSER) and live D1 MASTER (CORPUS_D1 → aziel-digital-library records). Whisper/OCR Workers-AI-bound. Sample MASTER remains the unbound fallback. Chromium product UI is not claimed; Tor/phoenix stay refuse. Remain-OFF untouched. 1.9.1 closes AZRT-1.9-GAPS-CLOSE (isolate-safe corpus verify ops; Whisper/OCR Workers-AI-gated; AZBrowser sandbox_status Chromium DEFERRED unbound; AZMail transport_status no public MTA; wave 2–3 doctor; adversarial self-check + Actions npm test; remain-OFF untouched). 1.9.0 closes AZRT-1.9-CLOSE-1.0 (AZMail isolate mailbox; AZChat LIVE+bound; isolate hash store; OpenAPI proxy-path parity; remain-OFF untouched). 1.7.10 makes QNM Live Nodes durable (cron or request-path fan-out of live Softwares product Workers while suite-presence is enabled; TTL 5 min; GET never enables). 1.7.9 cross-maps AZCoherence (peers azclce / AZInterface / AKM-TRIAD fabric neighbor; hubs + Worker URL; domain stays null). 1.7.8 lands EmbryoLock as a true in-process engine (Vault/Custody with ARK; live-with-local-destructive-boundary). LIVE_OPS health/skill/doctor/verify-hash/policy/limitation. Wipe/scorch/unlock-after-fail stay FG-STUB on the public mesh. Softwares worker_home embryolock-download-tracker. 1.7.7 lands AZCoherence (AZC-0.1) as a true in-process FragGate Softwares engine (second-pass triad coherence; cite https://github.com/AzielEliab/AZCoherence; not AKM-TRIAD). 1.7.6 syncs 4DMap LIVE_OPS with product 0.2.0 (pin/span/stack/gap/fork/walk/lens/class/cohort/absence/cap/join/list/example plus frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite; inspection frame after AZPIPE, not an extra door). 1.7.5 is Softwares capability wave 1 (decisiongate / forgereceipts / temporallock / staticclock / chronolock / trajectorylock / spectrallock). 1.7.4 enhances 4DMap LIVE_OPS (frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite; inspection frame after AZPIPE, not an extra door). 1.7.3 aligns audit WARN copy (exist.mcp → tools/list; public FragGate call; catalog count_note; 4DMap not an extra door). 1.7.2 adds GET /v1/azpipe/arch (MASTER-33 cite/read). 1.7.1 adds AKM-TRIAD-1.0 (Adaptive Knowledge Recollection, Bayesian Calibration & 3-of-4 Triad Selection). 1.7.0 locks MASTER-33: Human → AZInterface → PUBLIC/UI/AGENT/API → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance/Input Packet → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return. FragGate is THE single door. Lamb Lens is fabric after FragGate. LambGate is not a hop. 1.6.15 locked the suite hop order (SUITE-PIPE-1.6.15; historical). 1.6.14 adds 4DMap (4DM-WP-1.0) as a FragGate-live engine — four-axis inspection frame T/Δ/Γ/Π after AZPIPE; not a sequential gate and not an extra door. LIVE_OPS health/skill/card_new/card_pin/card_span/card_join/card_walk/card_list/verify_hash. 1.7.6 adds product 0.2 verbs plus frame_status/axis_describe/walk_trace/card_export/card_import/verify_chain/neighbor_cite. truth_score/lumen_panel/invent_mark/backdate_class stay stub. FragGate claims cite join types. 1.6.13 aligns the suite QNM rollup (QNM-BUILD-1.0, companion to AIH-WP-1.1): GET /v1/mesh live/locked/isolated counts; operator enable requires a declared bearer; default radios off; not a login mesh; full node process is local qnm-node/. 1.6.12 adds GET /v1/software (hub Software-tab catalog; Plain→Gate→Lock + EmbryoLock stub) and GET /v1/update/check. 1.6.11 adds a durable FragGate op alias map so Worker UI button names (azhub list_modules/place, azinterface genesis_boot/hold, azbrowser airlock/home, azmail classify, aznet doctor/pair, peacelock doctor) resolve to catalog LIVE_OPS. EmbryoLock is stub / local-not-hosted (name only; describe?slug=embryolock; not a FragGate engine). 1.6.10 sets AZBrowser and AZNet catalog one_line to separate software (not engine). Same FragGate door. 1.6.9 frames AZHub and AZInterface as two separate softwares under the same FragGate door (AIH-WP-1.0) — Blank Key spatial container + custodial page cycles. Never one combined product. Hub refuses auto-unlock / completeness. Interface page_cycle_status reports OFF / integrity / ON / FULL SHUTDOWN / MEMORIAL. AZHub LIVE_OPS (health, skill, region_list, place_module, remove_module, tether_declare, tether_cut, tether_list, blank_key_status) and AZInterface LIVE_OPS (health, skill, genesis_status, site_state_get, site_state_set, integrity_check, witness_list, page_cycle_status) are listed by fraggate_list and executed only via fraggate_call / POST /v1/fraggate/call. 1.6.7 adds AZNet (AZN-WP-0.1) as a FragGate-live engine — silent verification side-net; never hosts payloads; AZBrowser pair required (functional order only; own Worker UI). AZNet is reached only via fraggate_call / POST /v1/fraggate/call (flat leftover names still map through FragGate; not a side door). 1.6.6 adds AZBrowser (AZB-1.0) as a FragGate-live engine — Lamb Lens ethical research browser: ethical search + advisory navigate; cite; refuse harmful harvest; never invent visit results; not Chromium. AZNet is separate software (same FragGate door; order/token pairing only, not a shared Phase-1 UI). AZBrowser LIVE_OPS (ethical_search, lamb_lens_search, navigate, airlock_ingest, tab_open, tab_list, receipt_list, verify, receipt_verify, sandbox_status, sandbox_render, health, skill) are listed by fraggate_list and executed only via fraggate_call / POST /v1/fraggate/call — the same ops Worker UI buttons call. 1.6.5 adds AZMail (APP 1.0) as a FragGate-live engine — anonymous mesh default off, advisory airlock; SMTP/deanonymize stay stub. AZMail is reached only via fraggate_call / POST /v1/fraggate/call (flat leftover names still map through FragGate; not a side door). 1.6.4 adds PeaceLock (PL-WP-0.1) as a true in-process engine. 1.6.3 adds KV-backed API use trackers (GET /v1/uses). 1.6.2 widens the public door to sensible advisory engines; stubs still refuse. 1.6.0 is the FragGate door cut on in-process engines. 1.5.0 was agent-native flat product tools. Kernel: https://github.com/AzielEliab/fraggate (FG-0.1). Every catalog slug is a true engine. Cloudflare isolate is the jail. engine_digest is required. Hosted AZAI is protocol mirror + Lamb check, not the blend. VPN/hop mesh is not claimed on this public surface. AZMail anonymous ring is FragGate LIVE_OPS only (default off; not SMTP). Compatible clients: ChatGPT, Grok, Venice, Claude, Cursor, Glama, Perplexity, Copilot, Gemini, Mistral, Meta AI, Apple Intelligence, Amazon Q, DuckAssist, You.com, Cohere, plus other MCP/OpenAPI-capable assistants. Always send User-Agent Mozilla/5.0. Public, no OAuth. Author: Aziel Eliab only.

Known tools 36

runtime_skill

Read how an agent uses Aziel Eliab software: one door — discover, route, refuse (pipeline fraggate_list → fraggate_describe → fraggate_call; hubs use GET /v1/software).

Inferred read-only
fraggate_list

List hashed FragGate registry entries (live / stub / local_only) for discovery first.

Inferred read-only
fraggate_describe

Inspect one known FragGate capability: live vs stub vs local_only, public ops, and engine_digest.

Inferred read-only
fraggate_verify

Confirm a name, slug, or engine_digest against the hashed FragGate registry.

Inferred read-only
fraggate_call

Execute a known catalog slug+op through the FragGate single door (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return).

Potential side effects
decisiongate_check

Run the named DecisionGATE five sequential gates on a proposal (Freedom without clarity is chaos).

Inferred read-only
library_lookup

Search the Aziel Digital Library (aziel-corpus search / example / skill).

Inferred read-only
mesh_status

Read the QNM-BUILD-1.0 suite rollup (companion to AIH-WP-1.1): enabled?, declared bearers, live/locked/isolated counts.

Inferred read-only
mesh_enable

Operator-enable the QNM suite rollup by declaring a bearer (same as POST /v1/mesh/enable).

Potential side effects
mesh_disable

Turn QNM radios and bearers OFF (same as POST /v1/mesh/disable).

Potential side effects
mesh_join

Register a product node for QNM rollup counts (same as POST /v1/mesh/join).

Potential side effects
mesh_heartbeat

Refresh a node's 5-minute QNM presence TTL (same as POST /v1/mesh/heartbeat).

Potential side effects
mesh_leave

Drop a node from the QNM rollup (same as POST /v1/mesh/leave).

Potential side effects
mesh_nodes

List the QNM rollup roster with live/locked/isolated presence (5-minute TTL; same as GET /v1/mesh/nodes).

Inferred read-only
mesh_broadcast

Register the SHA-256 of a local communique as a hash receipt — never a publish path.

Potential side effects
chainlock_append

Append a fact-bearing stamp to a local ChainLock chain (CL-WP-0.4).

Inferred read-only
chainlock_tip

Read the live tip card of one local ChainLock chain.

Inferred read-only
chainlock_recall

Grounded ChainLock recall at depth 0–5 (CL-WP-0.4).

Inferred read-only
chainlock_verify

Fail-closed verify of ChainLock chains and LOCKSET (LS-WP-0.1): broken prev, tip drift, missing GodLock cite.

Inferred read-only
chainlock_seal

Seal live chain tips + TemporalLock receipt + GodLock cite into a LOCKSET (LS-WP-0.1).

Inferred read-only
memory_observe

Append a memory_observation to the ChainLock learn chain (AKM-TRIAD-1.0).

Inferred read-only
memory_resolve

Append a memory_resolution (AKM-TRIAD-1.0).

Inferred read-only
memory_calibrate

Calibrate a memory with the deterministic 3-of-4 triad plus Bayesian posterior (AKM-TRIAD-1.0).

Inferred read-only
memory_recall

Ranked adaptive recall after ChainLock verify (AKM-TRIAD-1.0).

Inferred read-only
memory_get

Read-only explainability for one memory: node, history, or calibration (posterior, triad legs, effective N, Brier).

Inferred read-only
runtime_software

Read the authoritative hub catalog (GET /v1/software): every product including AZChat LIVE+bound, sorted Plain A–Z → Gate A–Z → Lock A–Z (Clock ≠ Lock).

Inferred read-only
runtime_bundle

Read a compact bootstrap of every product skill URL and invoke prefix.

Inferred read-only
runtime_pull

Open one product card by slug: name, version, skill, download, and ops.

Inferred read-only
runtime_run

[advanced/internal] Advanced exec façade: admit a slug+op (still DecisionGATE-admitted) and run it through a raw session.

Potential side effects
runtime_manifest

[advanced/internal] Read the machine runtime manifest (version, role, door=fraggate, engine slugs, registry_digest).

Inferred read-only
runtime_session_open

[advanced/internal] Open a raw session object.

Inferred read-only
runtime_session_policy

[advanced/internal] Attach allow rules on a raw session.

Inferred read-only
runtime_session_exec

[advanced/internal] Raw session exec for an already-open session.

Potential side effects
runtime_session_receipt

[advanced/internal] Read the last receipt for a raw session.

Inferred read-only
runtime_session_receipts

[advanced/internal] Read the full receipt list for a raw session.

Inferred read-only
runtime_session_close

[advanced/internal] Seal a raw session so further exec is rejected.

Potential side effects

CONNECT WITH APPROVAL

Client installation

Review this server and its permissions before adding it. Secret placeholders must be set locally.

Codex

~/.codex/config.toml

[mcp_servers.aziel-runtime]
url = "https://www.azielcorpuslibrary.net/runtime/mcp"
enabled = true
Claude Code

.mcp.json

{
  "mcpServers": {
    "aziel-runtime": {
      "type": "http",
      "url": "https://www.azielcorpuslibrary.net/runtime/mcp"
    }
  }
}
Claude Desktop

Settings → Connectors → Add custom connector

Name: aziel-runtime
Remote MCP URL: https://www.azielcorpuslibrary.net/runtime/mcp

Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.

Cursor

.cursor/mcp.json

{
  "mcpServers": {
    "aziel-runtime": {
      "url": "https://www.azielcorpuslibrary.net/runtime/mcp"
    }
  }
}
Visual Studio Code

.vscode/mcp.json

Add to Visual Studio Code
{
  "servers": {
    "aziel-runtime": {
      "type": "http",
      "url": "https://www.azielcorpuslibrary.net/runtime/mcp"
    }
  }
}
Generic MCP

Client-specific MCP configuration

{
  "name": "aziel-runtime",
  "transport": "streamable-http",
  "url": "https://www.azielcorpuslibrary.net/runtime/mcp"
}
MCP Inspector

Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.

TRUST AND VERIFICATION EVIDENCE

Loading Trust v2 evidence…

Checking the associated registrable domain. The BuiltWith key remains server-side.

Indexed

Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.