{"kind":"spm.remote_mcp_metadata","protocol_version":"2025-06-18","server":{"name":"spm-remote-mcp","version":"1.0.0"},"endpoint":"https://getspm.com/v1/mcp","transport":"http-json-rpc","requires_auth":true,"auth":{"scheme":"bearer","token_type":"spm_api_token","recommended_profile":"agent-core"},"security":{"project_scoped":"supported","selected_project_set":"supported","org_scoped_project_resolution":true,"external_project_mounts":"supported_with_live_boundary_enforcement","default_project_behavior":"active_project_only","cross_project_behavior":"explicit_request_required","event_bodies":"summaries_only","secret_return":false,"billing_tools_exposed":false,"checkout_tools_exposed":false,"destructive_admin_tools_exposed":false},"profiles":{"agent-readonly":{"mode":"read-only","tool_count":35,"allow_body":false,"allow_secret_return":false},"agent-core":{"mode":"read-write","tool_count":62,"allow_body":false,"allow_secret_return":false},"hardening":{"mode":"read-write","tool_count":10,"allow_body":false,"allow_secret_return":false}},"tools":[{"name":"spm_agent_action_report","description":"Report the actual work outcome and exact permissions used. SPM validates tests, approvals, permissions and hashes, persists evidence, and returns separate execution and compliance results so a completed action is not confused with a process finding.","access":"write","category":"agent_hardening","required_scopes":["agent_hardening:write","objects:write"]},{"name":"spm_agent_policy_pack","description":"Generate a hash-verifiable hardening context pack that combines project memory, active policies, risk, required tests and prohibited actions.","access":"read","category":"agent_hardening","required_scopes":["agent_hardening:read","objects:read"]},{"name":"spm_agent_preflight","description":"Evaluate a proposed agent action before execution. The caller must enumerate the complete operational capability set in action.requested_permissions using stable identifiers such as repo:write or tests:execute, and set permission_scope_declared=true only after that list is complete. An empty list with true means no operational capabilities are planned. action also requires action_type and an intent from read, write, modify_code, run_tests, deploy, share_context, access_data, configure_auth or other. SPM returns policy decision, execution authorization, tests, approvals, checklist and hashes.","access":"write","category":"agent_hardening","required_scopes":["agent_hardening:write","objects:read"]},{"name":"spm_agent_resource_handoff","description":"Record a material file, document, tool result, repository snapshot or endpoint response that directly informed this agent's work. The caller must explicitly provide an authorized redacted body or accurate summary; SPM cannot inspect host files, hidden tool logs or endpoints by itself. The source enters the normal governed journal and smart-memory triage path. Identical content is reused canonically across sessions; changed stable sources are linked as versions.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_resources_list","description":"List body-free evidence for material resources explicitly handed to an agent session. Returns source, kind, provenance, canonical/version links and hash, never the retained body.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_session_association_decide","description":"Confirm SPM's proposed project, reject that candidate for this task, select another authorized local project, or continue this agent task without durable project memory. The decision persists for the task id.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_session_context_inject","description":"Persist an explicitly requested authorized project as read-only injected context for an agent session. The active local project remains the write target; the injected source is tracked by session and can be revoked.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write","projects:read","objects:read"]},{"name":"spm_agent_session_context_revoke","description":"Revoke a previously injected project context from an agent session. Future session reads and context briefings omit the revoked source.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_session_continuation_accept","description":"Continue an SPM agent session in this agent after rechecking the authenticated user's current project and external-mount authorization. The one-time handoff cannot grant access the target connector does not already have.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:read","objects:write","projects:read"]},{"name":"spm_agent_session_continuation_create","description":"Create a short-lived one-time handoff for the current agent session. It carries only the active project and authorized injected-context references; memory bodies and credentials are never copied.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:read","objects:write"]},{"name":"spm_agent_session_continuation_revoke","description":"Revoke a pending one-time agent-session continuation before it is accepted. Only the authenticated user who created the continuation can revoke it.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:read","objects:write"]},{"name":"spm_agent_session_get","description":"Read the active project and authorized project catalog for an existing agent conversation session.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_session_lifecycle_traces","description":"List body-free product lifecycle traces for an agent session: project association, source capture, smart-memory triage, policy exclusions and receipt diagnostics.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_session_receipt_delivery_report","description":"Record body-free connector evidence that the SPM receipt instruction was delivered or that the completion hook ran. It never asserts that a host rendered model text.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_session_receipt_status","description":"Return the latest persisted source-capture and smart-memory status for an agent session when the host UI drops hook-visible receipts.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_session_set_project","description":"Explicitly select the active local project for an agent session. The selected project must be visible to the token; external mounts remain governed context sources and every switch is audited.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_session_start","description":"Start or resume an agent conversation session. SPM resolves an authorized active project, returns the projects visible to the token and refuses to guess when the project is ambiguous.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_turn_ingest","description":"Submit a user or assistant turn to SPM's LLM-first memory triage. SPM automatically records agent/session/turn provenance, applies durable memory decisions only to the active local project and returns without writing when identity is ambiguous or resolves to an external mount.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_work_bundle_finalize","description":"Evaluate a captured user request and captured final agent response together as one completed project-memory outcome. The supplied bodies must match the hash-chained source turns; SPM does not create a second RAW copy. It also checks whether the completed work is adequately covered by the governed project-source inventory. Optional evidence is structured execution evidence, not hidden logs.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_agent_workspace_manifest_list","description":"List safe workspace manifests for one agent session or one authorized project. Results contain hashes and version evidence, never file bodies, credentials or raw diffs.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_agent_workspace_manifest_record","description":"Record body-free workspace identity and version evidence for the active agent session. Use it before cross-agent continuation when local code, files, documents or remote resources materially affect the work.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:read","objects:write"]},{"name":"spm_attention_briefing","description":"Return pending project communications ordered by priority, action and acknowledgement needs. Surfacing is recorded, but SPM never infers that the user read an item.","access":"read","category":"project_attention","required_scopes":["objects:read"]},{"name":"spm_attention_create","description":"Create a source-linked project communication. Agent connectors may address their approving user; human project editors may address authorized project members.","access":"write","category":"project_attention","required_scopes":["objects:write"]},{"name":"spm_attention_inbox","description":"List project-memory communications addressed to the connector user.","access":"read","category":"project_attention","required_scopes":["objects:read"]},{"name":"spm_attention_revoke","description":"Revoke an active project communication as its sender or an administrator.","access":"write","category":"project_attention","required_scopes":["objects:write"]},{"name":"spm_attention_sent","description":"List project-memory communications created by the current user or connector.","access":"read","category":"project_attention","required_scopes":["objects:read"]},{"name":"spm_attention_state_update","description":"Explicitly acknowledge, defer, action, resolve or dismiss a communication receipt. Never call this merely because an item was displayed.","access":"write","category":"project_attention","required_scopes":["objects:write"]},{"name":"spm_connector_access_get","description":"Read this connector's persistent authorization envelope. The response separates local project access from external project access and states the fixed runtime rule: one active project per conversation, with cross-project composition only when the user asks for it.","access":"read","category":"connector_access","required_scopes":[]},{"name":"spm_connector_access_request","description":"Translate a user's conversational connector-access request into a structured proposal. This tool never expands its own permissions: it stores a short-lived, hashed proposal and returns a private-console URL where a human owner or admin must approve it. Resolve or list projects first when the user's references are ambiguous.","access":"write","category":"connector_access","required_scopes":["projects:read"]},{"name":"spm_context_boundaries_list","description":"List reusable context-boundary recipes for audience-specific project memory.","access":"read","category":"context_boundaries","required_scopes":["objects:read"]},{"name":"spm_context_boundary_get","description":"Fetch one context boundary by id or slug.","access":"read","category":"context_boundaries","required_scopes":["objects:read"]},{"name":"spm_context_boundary_pack","description":"Compile a named context boundary into a hash-verifiable context pack.","access":"read","category":"context_boundaries","required_scopes":["objects:read"]},{"name":"spm_cross_project_context_pack","description":"Generate a hash-verifiable context pack from an explicitly requested source project for injection into the active project. The source may be local or a live external mount; its boundary policy, revocation state, provenance and summaries-only contract remain enforced.","access":"read","category":"context_injection","required_scopes":["projects:read","objects:read"]},{"name":"spm_memory_capture_evidence","description":"Read one body-free capture lifecycle projection: effective policy, source-journal outcomes, applied-memory links, review links and hash-chain verification.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_memory_capture_journal_list","description":"List source provenance, capture outcomes and hash-chain evidence for an authorized project. The agent MCP surface never returns retained turn bodies.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_memory_capture_journal_verify","description":"Verify source-journal sequence and hash continuity for an authorized project.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_memory_capture_policy_get","description":"Read the effective source-capture policy for an agent session. Capture controls whether turns are retained in full redacted form, selectively triaged, summarized only or hash-only; it does not make every captured turn eligible for context injection.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_memory_capture_policy_set","description":"Set the capture policy for the current agent session. Agent tokens cannot change project or organization defaults. Complete mode stores only a redacted encrypted source body.","access":"write","category":"agent_memory_lifecycle","required_scopes":["objects:write"]},{"name":"spm_memory_context_compose","description":"Compose governed task context from the canonical memory tree. SPM enumerates authorized evidence and an LLM selects relevant records, temporal signals and optional branches. When the LLM declares an interactive projection insufficient and undisplayed authorized evidence exists, SPM performs one bounded deep composition. An optional agent session adds explicitly injected context packs as read-only, separately hashed sources. Retained redacted source turns remain excluded unless a trusted profile explicitly requests governed raw evidence after selection.","access":"read","category":"memory_retrieval","required_scopes":["objects:read"]},{"name":"spm_memory_lifecycle_overview","description":"Return an owner/admin-only, body-free operational overview of SPM memory capture and smart-memory health. It aggregates lifecycle traces and surfaces actionable provider, budget or repeated processing failures without exposing project memory content.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_memory_tree_get","description":"Read the latest rebuildable memory-tree projection for an authorized project. The tree references governed source records and never returns retained raw turn bodies.","access":"read","category":"memory_retrieval","required_scopes":["objects:read"]},{"name":"spm_memory_tree_rebuild","description":"Build an immutable, hash-bound tree snapshot from canonical capture, memory and temporal records already governed by SPM.","access":"write","category":"memory_retrieval","required_scopes":["objects:write"]},{"name":"spm_memory_tree_verify","description":"Verify stored tree node hashes and report whether a snapshot still reflects current canonical project memory.","access":"read","category":"memory_retrieval","required_scopes":["objects:read"]},{"name":"spm_multi_project_context_pack","description":"Compose independently verifiable, summaries-only context packs from several explicitly requested authorized local projects or live external mounts. Source memories keep separate project ids, boundary decisions, hashes and provenance.","access":"read","category":"context_injection","required_scopes":["projects:read","objects:read"]},{"name":"spm_organization_governance_state","description":"Read owner/admin-only organization authority, mandatory policy, audit and user work evidence. Work evidence reports observed agent actions and validated reports; it is not a productivity score or employee ranking.","access":"read","category":"trust_governance","required_scopes":["productization:read"]},{"name":"spm_project_bootstrap_confirm","description":"Confirm a pending project-memory bootstrap after the user has explicitly chosen create, link or skip. Requires the preview hash, write permission and the original bootstrap id; when a session id is attached, SPM also persists the task-project association.","access":"write","category":"project_resolution","required_scopes":["projects:write"]},{"name":"spm_project_bootstrap_evidence_submit","description":"Submit a bounded, source-grounded project inspection to an existing pending bootstrap. SPM updates the same proposal, versions portable sources, evaluates evidence sufficiency with the configured LLM and returns any specific remaining discovery request. Supplied source bodies or summaries are staged for canonical capture after confirmation; inventory alone is never reported as captured.","access":"write","category":"project_resolution","required_scopes":["projects:bootstrap"]},{"name":"spm_project_bootstrap_execute","description":"Create and associate source-grounded project memory after the user explicitly instructs the agent to create it. authorization_external_turn_id must identify that same authenticated user turn and explicit_user_instruction must contain its exact full text; never paraphrase, strengthen or infer authorization. This operation is idempotent for the agent session: repeat the same call to resume evidence collection or retrieve the completed result, never create a second proposal. A direct connector creates immediately; a connector configured for browser review returns review_required. If evidence_required is returned, inspect only the authorized project resources requested by SPM, submit them to the same bootstrap and call this tool again. Supplied source bodies and summaries are captured through SPM's canonical resource journal after successful creation when a session is attached. resource_inventory is discovery metadata only and never proves that a file was captured. Read material_coverage before describing what SPM preserved.","access":"write","category":"project_resolution","required_scopes":["projects:bootstrap"]},{"name":"spm_project_bootstrap_preview","description":"Prepare a source-grounded project-memory proposal when the user explicitly requests review before creation. This is the optional browser-review path; use spm_project_bootstrap_execute for an explicit create instruction. Authentication resumes the same proposal, and the next agent turn must read its status rather than create another. Sources declare whether content is a body or summary; inventory-only resources remain pending in material_coverage.","access":"write","category":"project_resolution","required_scopes":["projects:bootstrap"]},{"name":"spm_project_bootstrap_status","description":"Read a pending or completed project-memory bootstrap proposal and its confirmation URL.","access":"read","category":"project_resolution","required_scopes":["projects:bootstrap"]},{"name":"spm_project_resolve","description":"Resolve which accessible project an agent request refers to. Ambiguous results require confirmation instead of silently mixing project memory. Local projects and governed external mounts use the same resolution contract.","access":"read","category":"project_resolution","required_scopes":[]},{"name":"spm_project_semantic_identity_get","description":"Read the source-backed semantic identity used to resolve an authorized project. It distinguishes the project's own purpose and work from external references, retrospectives and cross-project context.","access":"read","category":"project_resolution","required_scopes":["objects:read"]},{"name":"spm_project_semantic_identity_refresh","description":"Rebuild an authorized project's derived semantic identity from canonical memory. It never alters journal, temporal events or memory objects.","access":"write","category":"project_resolution","required_scopes":["projects:write","objects:read"]},{"name":"spm_projects_list","description":"List every local project and live external project mount this MCP token can access. Project tokens return one project, selected-set tokens return only approved projects/mounts, and organization tokens remain limited by user, organization and mount authorization.","access":"read","category":"project_resolution","required_scopes":[]},{"name":"spm_providers_status","description":"Return the owner/admin-only operational state of configured AI providers, including body-free circuit state, typed incidents, retry timing and administration alert delivery.","access":"read","category":"agent_memory_lifecycle","required_scopes":["objects:read"]},{"name":"spm_temporal_context_pack","description":"Generate a scoped, hash-verifiable context pack for an agent task.","access":"read","category":"context_injection","required_scopes":["objects:read"]},{"name":"spm_temporal_context_pack_verify","description":"Verify that an injected temporal context pack is still current before agent use.","access":"read","category":"context_injection","required_scopes":["objects:read"]},{"name":"spm_temporal_event_create","description":"Persist a durable project-memory event from an authorized agent. Raw bodies are stripped on the hosted remote MCP surface; use summaries, hashes and evidence refs.","access":"write","category":"temporal_memory","required_scopes":["objects:write"]},{"name":"spm_temporal_graph_query","description":"Query related project memory across temporal events, topics, tags and graph edges.","access":"read","category":"context_graph","required_scopes":["objects:read"]},{"name":"spm_temporal_state","description":"Read a project-scoped temporal state report with optional topic, tag, context-area, temporal-validity and authority weighting filters.","access":"read","category":"temporal_memory","required_scopes":["objects:read"]},{"name":"spm_trust_remediation_plan","description":"Read the operator-grade remediation plan for trust blockers, including acceptance criteria, safe automation level and verification endpoint.","access":"read","category":"trust","required_scopes":["productization:read"]},{"name":"spm_trust_status","description":"Read tenant trust posture before context injection: trust score, control status, high-severity gaps and latest audited activity.","access":"read","category":"trust","required_scopes":["productization:read"]}]}