Alter Onboarding
Guide developers from setup through a verified, policy-aware, audited Alter API call.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"alter-onboarding": {
"url": "https://mcp.alterauth.com/mcp"
}
}
}Puntos de conexión remotos
https://mcp.alterauth.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (14)
🟢list_phases
List the lifecycle phases this server serves (setup, modify) and what each is for.
Esquema de entrada
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_skills
List the guidance Skills available on this server, with the phase each serves. Read a skill via its resource (skill://alter/<name>).
Esquema de entrada
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡get_started(phase, use_case, goal)
Begin or change an Alter integration. Without args: lists the phases. With `phase`: returns that phase's flows + a heuristic hint — classify the use case YOURSELF and call again with `goal` for the plan. If the use case spans multiple flows, run them sequentially.
Esquema de entrada
{
"type": "object",
"properties": {
"phase": {
"description": "setup (integrate from scratch) or modify (change an existing integration).",
"type": "string",
"enum": [
"setup",
"modify"
]
},
"use_case": {
"description": "Plain-English description of what the developer wants.",
"type": "string",
"maxLength": 2000
},
"goal": {
"description": "The flow id YOU classified. Returns that flow's full plan.",
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent",
"add-provider",
"add-secret",
"add-agent",
"rotate-key",
"manage-grant",
"set-policy"
]
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪next_step(goal, after)
Return the next step for a flow. Pass the goal (flow id) and the id of the last completed step (omit `after` for the first step). Run each step's detect command FIRST and skip the run command when detection passes. The design step also returns that flow's complete starter ALTER_INTEGRATION.md.
Esquema de entrada
{
"type": "object",
"properties": {
"goal": {
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent",
"add-provider",
"add-secret",
"add-agent",
"rotate-key",
"manage-grant",
"set-policy"
],
"description": "The flow id (setup goal or modify operation)."
},
"after": {
"description": "Id of the last completed step (e.g. \"2\", \"3a\").",
"type": "string",
"maxLength": 10
}
},
"required": [
"goal"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡sdk_integration(language, goal)
Return the Alter SDK wiring (install + client init + request) to write into the developer's codebase, for a language and setup goal.
Esquema de entrada
{
"type": "object",
"properties": {
"language": {
"type": "string",
"enum": [
"python",
"typescript"
],
"description": "Target language."
},
"goal": {
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent"
],
"description": "The setup goal (user-data | backend-secret | agent)."
}
},
"required": [
"language",
"goal"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪sdk_pattern(language, pattern)
Return a runnable Alter SDK call pattern for a language: `proxy-call` (zero-egress proxy_request + HITL), `resolve-grant-by-user` (call as an end user via their delegated grant), `delegate-managed-secret` (the operator-side delegation step), or `resolve-ambiguous-grant` (an identity-mode call matched several of one user's grants: choose deliberately, never the first, and persist it; ask the developer at design time whether users can hold several accounts per provider). Use AFTER `sdk_integration` has wired the client.
Esquema de entrada
{
"type": "object",
"properties": {
"language": {
"type": "string",
"enum": [
"python",
"typescript"
],
"description": "Target language."
},
"pattern": {
"type": "string",
"enum": [
"proxy-call",
"resolve-grant-by-user",
"delegate-managed-secret",
"resolve-ambiguous-grant"
],
"description": "proxy-call | resolve-grant-by-user | delegate-managed-secret | resolve-ambiguous-grant."
}
},
"required": [
"language",
"pattern"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪troubleshoot(exit_code, error)
Map a @alter-ai/cli exit code or error message to a remediation.
Esquema de entrada
{
"type": "object",
"properties": {
"exit_code": {
"description": "The CLI process exit code.",
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
},
"error": {
"description": "The stderr / error message.",
"type": "string",
"maxLength": 10000
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪verify_integration(scenario)
Return a copy-pasteable recipe to VERIFY an integration works: `first-call` (code↔design, an audit row, correct attribution) or `per-user-isolation` (a multi-user/broker server runs two users under different credentials and rejects cross-user access). Guidance only — you run the commands.
Esquema de entrada
{
"type": "object",
"properties": {
"scenario": {
"type": "string",
"enum": [
"first-call",
"per-user-isolation"
],
"description": "first-call | per-user-isolation."
}
},
"required": [
"scenario"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢fetch_doc(slug)
Fetch any page of the Alter documentation by slug (e.g. "quickstart"). The whole published docs site is bundled here, skill pages included, so every page a doc, a skill or a flow step links to can be read in-band. Accepts any spelling the docs use: a bare slug, a leading slash, a #section anchor, a full docs.alterauth.com URL, or an older path that now redirects. Omit the slug to list every page.
Esquema de entrada
{
"type": "object",
"properties": {
"slug": {
"description": "Doc slug, e.g. \"guides/call-apis-on-behalf-of-users\".",
"type": "string",
"maxLength": 200
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢search_docs(query, limit)
Search every bundled page of the Alter documentation (docs and skill pages) by keywords: returns the best-matching pages with the section and a snippet that matched. Use it when a flow step or doc did not point you at the page you need, instead of guessing slugs or listing every page; then read one with fetch_doc and its slug.
Esquema de entrada
{
"type": "object",
"properties": {
"query": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Keywords or a short phrase, e.g. \"connect widget popup\" or \"PAT scopes login\"."
},
"limit": {
"description": "Maximum results (default 8, at most 20).",
"type": "integer",
"minimum": 1,
"maximum": 20
}
},
"required": [
"query"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_providers(kind)
List every provider with an ingested API spec in Alter's provider-spec catalog, with each spec's source and freshness. Optionally filter by `kind`. Start here, then call list_operations for a provider's operations.
Esquema de entrada
{
"type": "object",
"properties": {
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_operations(provider_id, kind, search, limit, offset)
List the API operations a provider exposes, live from Alter's provider-spec catalog (e.g. "what can I call on google?"). Returns operation ids + methods/paths, plus the spec's source and freshness. Omit `kind` to auto-detect the provider family; when the id exists in both oauth and managed you'll be asked to pass `kind`. Machine-readable rows ride in `structuredContent` (see this tool's outputSchema) — read those rather than parsing the prose.
Esquema de entrada
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Provider id, e.g. \"google\" or \"github\"."
},
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
},
"search": {
"description": "Case-insensitive filter over operation ids/paths/summaries.",
"type": "string",
"maxLength": 200
},
"limit": {
"description": "Max operations to return (backend default 100, max 500).",
"type": "integer",
"minimum": 1,
"maximum": 500
},
"offset": {
"description": "Zero-based offset for paging through large operation lists.",
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"provider_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}Esquema de salida
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"description": "Resolved provider id the rows belong to."
},
"provider_kind": {
"type": "string",
"enum": [
"oauth",
"managed"
],
"description": "Resolved provider family: oauth or managed."
},
"spec_version": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Alter's ingested spec version these rows came from."
},
"total": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Total operations matching the query (before limit/offset)."
},
"offset": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Zero-based offset of the first row."
},
"operations": {
"type": "array",
"items": {
"type": "object",
"properties": {
"operation_id": {
"type": "string",
"description": "Pass to get_operation_schema for the full contract."
},
"method": {
"type": "string",
"description": "HTTP method, e.g. GET."
},
"path_template": {
"type": "string",
"description": "Path with {placeholders}, e.g. /repos/{owner}/{repo}."
},
"summary": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "One-line description, or null when the spec omits it."
}
},
"required": [
"operation_id",
"method",
"path_template",
"summary"
],
"additionalProperties": false
},
"description": "This page of operations, in the catalog's serving order."
}
},
"required": [
"provider_id",
"provider_kind",
"spec_version",
"total",
"offset",
"operations"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}🟢get_operation_schema(provider_id, operation_id, kind)
Fetch one provider API operation's full contract — method, path, parameters, request/response schemas — live from Alter's provider-spec catalog, plus the spec's source and freshness. Get operation ids from list_operations first.
Esquema de entrada
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Provider id, e.g. \"google\" or \"github\"."
},
"operation_id": {
"type": "string",
"minLength": 1,
"maxLength": 500,
"description": "Operation id from list_operations, e.g. \"gmail.users.messages.list\"."
},
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
}
},
"required": [
"provider_id",
"operation_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡policy_language(rule_type)
The authoritative grammar of Alter's runtime-policy language, live from the deployed backend: every authorable rule type with its JSON body schema, caps, authorable levels, worked examples, and fail-closed semantics. Call with no arguments for the overview; pass `rule_type` (e.g. "content_match") for one type's full grammar. Use it before authoring rules with `alter policy rules create` — never guess a body shape. Vocabulary: the dashboard's "Runtime policies" surface, the docs' "policy", and `alter policy` are one feature, and the dashboard's "Require human approval" type is the `require_approval` rule type (its grant-editor block is the grant-level baseline of the same gate). The same grammar is what policy files carry: `alter policy validate|test|plan|apply` review rules in Git and CI, and a rule with a `code_owner` is changed through its file, never with `rules update`. Workflow prose: the `set-policy` modify flow (`get_started` with phase=modify), fetch_doc("guides/set-policies"), fetch_doc("guides/add-human-in-the-loop-approvals"), fetch_doc("guides/policy-as-code"), and fetch_doc("reference/cli/commands/policy").
Esquema de entrada
{
"type": "object",
"properties": {
"rule_type": {
"description": "One rule type's full grammar, e.g. \"content_match\" or \"quota\".",
"type": "string",
"minLength": 1,
"maxLength": 50
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}Comunidad
Evidencia