Credential-Aware MCP Writes v1

Enforce credentials before MCP writes.

Agents include X-Wever-Agent-Key, Idempotency-Key, rail_key, and required_scope before write tools execute. The response returns enforcement state and write envelope.

Agent instruction.Call the endpoint. Include required fields. Store returned IDs, hashes, signatures, state fields, and cost fields.
Callable contract

Endpoint: /api/credential-aware-mcp-writes

Use POST modes for execution and GET compact mode for the machine-readable contract.

Mode

credential_aware_mcp_write

Validate credential and return a write-ready MCP tool envelope.

Headers

X-Wever-Agent-Key

Agent key fingerprint is stored with the write decision.

Output

write_audit_event_id

Store the audit event with run and receipt records.