Bardo
Identity & continuity for AI agents, gated by a proof-of-being-an-LLM puzzle.
使うべきか
品質と安全性
検出事項(3)
- LOWbardo_encrypt 内
- LOWbardo_sign 内
- LOWbardo_derive 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"bardo": {
"url": "https://bardo.id/mcp/"
}
}
}リモートエンドポイント
https://bardo.id/mcp/streamable-httpできること
ツール一覧
ツール(40)
🟢bardo_verify(message, signature_b64, public_key_b64)
Verify a signature over a UTF-8 message. Public utility (no session).
入力スキーマ
{
"type": "object",
"properties": {
"message": {
"description": "UTF-8 message the signature was made over.",
"title": "Message",
"type": "string"
},
"signature_b64": {
"description": "Signature to verify, base64.",
"title": "Signature B64",
"type": "string"
},
"public_key_b64": {
"description": "Signer's public key, base64 — from bardo_public_key or a document's own proof.",
"title": "Public Key B64",
"type": "string"
}
},
"required": [
"message",
"signature_b64",
"public_key_b64"
],
"additionalProperties": false,
"title": "bardo_verifyArguments"
}🟢bardo_encrypt(plaintext, recipient_public_key_b64)
Sealed-box encrypt a UTF-8 plaintext to a recipient's encryption public key.
入力スキーマ
{
"type": "object",
"properties": {
"plaintext": {
"description": "UTF-8 plaintext to encrypt.",
"title": "Plaintext",
"type": "string"
},
"recipient_public_key_b64": {
"description": "Recipient's encryption public key, base64 — only they can decrypt the result.",
"title": "Recipient Public Key B64",
"type": "string"
}
},
"required": [
"plaintext",
"recipient_public_key_b64"
],
"additionalProperties": false,
"title": "bardo_encryptArguments"
}🟢bardo_document_status(id)
Check whether a signed document is revoked. `id` is the document's own top-level `id` field (a ni:// URI) — the same thing credentialStatus.id (BardoRevocationCheck) points at. Safe to cache a "not revoked" answer for a while (see the response's own Cache-Control) rather than re-checking on every use.
入力スキーマ
{
"type": "object",
"properties": {
"id": {
"description": "The document's own top-level id field (a ni:// URI) — the same value credentialStatus.id (BardoRevocationCheck) points at.",
"title": "Id",
"type": "string"
}
},
"required": [
"id"
],
"additionalProperties": false,
"title": "bardo_document_statusArguments"
}🔴bardo_document_revoke(document, signature_b64, service, session_token)
Revoke a document you issued. Proof is a fresh signature over 'revoke:' + the document's id, verified against the key its id already committed to, not an account lookup (Bardo never stored the document to look up in the first place) — this still needs no session at the protocol level, only a valid signature. document: the full signed document, exactly as issued (id and proof both still attached) — resubmit it unmodified, don't strip fields yourself. signature_b64: omit it and this signs automatically through your active session instead — pass `service` too if the document was issued under a service-derived key rather than root, since the signature has to come from the exact key the document's issuer field names. Supply signature_b64 yourself only when revoking without a Bardo session at all: you signed it some other way, or you're a party that's never touched Bardo. Idempotent — revoking an already-revoked id is a no-op, not an error. Irreversible: there is no un-revoke.
入力スキーマ
{
"type": "object",
"properties": {
"document": {
"additionalProperties": true,
"description": "The full signed document exactly as issued (id and proof both still attached) — resubmit unmodified, don't strip fields yourself.",
"title": "Document",
"type": "object"
},
"signature_b64": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Signature over 'revoke:' + the document's id. Omit to sign automatically through your active session instead; supply this yourself only when revoking without a Bardo session at all.",
"title": "Signature B64"
},
"service": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Service key the document was issued under, if not root — must match the document's own issuer field. Only relevant when signature_b64 is omitted (signing automatically).",
"title": "Service"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"document"
],
"additionalProperties": false,
"title": "bardo_document_revokeArguments"
}🟢bardo_sign(message, service, session_token)
Sign a UTF-8 message with the spirit key (or a service-derived key).
入力スキーマ
{
"type": "object",
"properties": {
"message": {
"description": "UTF-8 message to sign.",
"title": "Message",
"type": "string"
},
"service": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Sign with this service-derived key instead of your root identity (e.g. 'github.com') — must already exist via bardo_derive.",
"title": "Service"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"message"
],
"additionalProperties": false,
"title": "bardo_signArguments"
}🟢bardo_decrypt(ciphertext_b64, service, session_token)
Decrypt a sealed-box ciphertext addressed to you (root or service key).
入力スキーマ
{
"type": "object",
"properties": {
"ciphertext_b64": {
"description": "Sealed-box ciphertext to decrypt, base64.",
"title": "Ciphertext B64",
"type": "string"
},
"service": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Decrypt with this service-derived key instead of root — must match the key the ciphertext was actually encrypted to.",
"title": "Service"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"ciphertext_b64"
],
"additionalProperties": false,
"title": "bardo_decryptArguments"
}🟢bardo_public_key(service, session_token)
Fetch your signing + encryption public keys (root, or for a service).
入力スキーマ
{
"type": "object",
"properties": {
"service": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Fetch this service-derived identity's public keys instead of root's.",
"title": "Service"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_public_keyArguments"
}⚪bardo_derive(service, session_token)
Derive (and register) a service-scoped identity, e.g. 'github.com'.
入力スキーマ
{
"type": "object",
"properties": {
"service": {
"description": "Identifier for the service this identity is scoped to, e.g. 'github.com' or 'ethereum:mainnet'.",
"title": "Service",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"service"
],
"additionalProperties": false,
"title": "bardo_deriveArguments"
}🟢bardo_services_list(session_token)
List service-scoped identities you've already derived (bardo_derive), with their public keys and revoked status.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_services_listArguments"
}⚪bardo_export(challenge_id, answer, session_token)
Export the raw spirit key (subject to policy). Handle with care. Only needs a step-up puzzle if your policy's export_mode is require_repuzzle — checked automatically, so you don't need to know your own policy first. If challenge_id and answer are omitted and one turns out to be needed, a fresh puzzle is returned instead of failing outright — solve it yourself, then call this tool again with both parameters. Never needed under export_mode 'allow'; always fails under 'disabled', with no puzzle that could fix that.
入力スキーマ
{
"type": "object",
"properties": {
"challenge_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Step-up puzzle id, if one was already returned by a prior call to this same tool. Omit together with answer to have a fresh puzzle minted automatically.",
"title": "Challenge Id"
},
"answer": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your solved answer to challenge_id's puzzle.",
"title": "Answer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_exportArguments"
}🟡bardo_attestation_issue(claim, subject_id, expires_at, service, keep_copy, ...)
Assemble and sign a verifiable attestation — a self-contained, offline-verifiable claim about anything. The document itself is handed back, not stored anywhere (same as bardo_sign itself — there's no bardo_documents_list); see keep_copy below if you want Bardo to save one for you rather than doing it yourself. claim: free-form claim content — whatever you're asserting. Include a `reference` key inside it when cross-referencing another document's id (or any other content, hashed the same ni:// way) — that's how independent attestations end up pointing at "the same thing," e.g. several agents witnessing one event under a shared reference. subject_id: the did:key the claim is about, if it concerns one specific identified party — leave it unset when it doesn't; a bare self-referential claim ("this document is about its signer") is still valid without it. expires_at: unix timestamp for time-boxed claims only; omit for a claim that never expires. service: same key-selector bardo_sign takes — a document meant to represent one specific relationship should use that relationship's service-derived key, not your root identity. keep_copy: save the full document into a locked note right after issuing it — the copy you'd otherwise have to make yourself, and the one you'll need later: bardo_document_revoke takes the whole document, not just its id, since Bardo never stores one itself. Off by default. When true, the return shape changes to {document, copy_saved, note_id, copy_error} instead of the bare document — check copy_saved rather than assume it worked; a failed copy never blocks the document itself from being returned, since issuing has already fully succeeded by that point regardless. To revoke later: bardo_document_revoke. To check whether one you're holding (yours or someone else's) is still valid: bardo_document_status.
入力スキーマ
{
"type": "object",
"properties": {
"claim": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Free-form claim content — whatever you're asserting. Include a 'reference' key when cross-referencing another document's id (or any other content, hashed the same ni:// way).",
"title": "Claim"
},
"subject_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The did:key the claim is about, if it concerns one specific identified party. Leave unset for a bare self-referential claim.",
"title": "Subject Id"
},
"expires_at": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Unix timestamp for a time-boxed claim. Omit for a claim that never expires.",
"title": "Expires At"
},
"service": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Sign with this service-derived key instead of root — use when the claim represents one specific relationship rather than your root identity.",
"title": "Service"
},
"keep_copy": {
"default": false,
"description": "Also save the full issued document into a locked note — you'll need the whole document later for bardo_document_revoke, since Bardo never stores one itself. Off by default.",
"title": "Keep Copy",
"type": "boolean"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_attestation_issueArguments"
}🟢bardo_sessions_list(session_token)
List your active sessions (sliding TTL, absolute 24h cap each).
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_sessions_listArguments"
}🔴bardo_session_revoke_current(session_token)
Revoke the session you're using right now. You'll need bardo_login (+ bardo_solve) again afterward to do anything session-gated.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_session_revoke_currentArguments"
}🔴bardo_sessions_revoke_all(session_token)
Revoke every active session for your identity — e.g. after a suspected API-key leak. You'll need to log in again afterward.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_sessions_revoke_allArguments"
}🟡bardo_stepup(session_token)
Mint a fresh step-up puzzle for a privileged action (currently: bardo_policy_set). Solve it yourself, then pass challenge_id + your answer to the tool that needs it. (bardo_policy_set also mints one itself on demand — call this directly only if you want the puzzle up front.)
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_stepupArguments"
}🟢bardo_policy_get(session_token)
View your self-binding security policy: export mode, session TTL cap, service allowlist, ratchet delay, tag encryption, delete grace period — plus any pending (queued) loosening and when it lands.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_policy_getArguments"
}🟡bardo_policy_set(export_mode, max_session_ttl, service_allowlist, loosen_delay_seconds, tags_encrypted, ...)
Propose a change to your security policy. Give only the fields you want to change (export_mode: 'allow'|'require_repuzzle'|'disabled'). A change that only tightens (e.g. lowering max_session_ttl, narrowing service_allowlist, moving export_mode toward 'disabled') applies immediately. A change that loosens *anything* is queued behind loosen_delay_seconds instead — abortable via bardo_policy_abort_pending until it lands. clear: field names to reset to null — only max_session_ttl (no ceiling) or service_allowlist (any service) accept this; pass service_allowlist=[] instead if you mean "no services allowed", which is different from null. Requires a step-up puzzle. If challenge_id and answer are omitted, a fresh puzzle is returned — solve it yourself, then call this tool again with your desired fields plus challenge_id and answer.
入力スキーマ
{
"type": "object",
"properties": {
"export_mode": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "'allow' | 'require_repuzzle' | 'disabled', stricter in that order. Moving toward 'disabled' tightens; toward 'allow' loosens.",
"title": "Export Mode"
},
"max_session_ttl": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Session lifetime cap in seconds. Lowering it tightens; raising it loosens. Use clear=['max_session_ttl'] for no ceiling.",
"title": "Max Session Ttl"
},
"service_allowlist": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Services allowed to be derived. Narrowing the list tightens, widening it loosens. Pass [] for 'no services allowed' (different from clearing it via clear=['service_allowlist'], which means 'any service').",
"title": "Service Allowlist"
},
"loosen_delay_seconds": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "How long a future loosening change is queued before it lands. Raising it tightens.",
"title": "Loosen Delay Seconds"
},
"tags_encrypted": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "Whether note tags are stored encrypted (true) or plaintext-searchable (false). Moving to true tightens.",
"title": "Tags Encrypted"
},
"delete_grace_seconds": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "How long a deleted note stays recoverable before permanent purge. Raising it tightens.",
"title": "Delete Grace Seconds"
},
"clear": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Field names to reset to null instead of leaving unchanged — only max_session_ttl and service_allowlist accept this.",
"title": "Clear"
},
"challenge_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Step-up puzzle id, if one was already returned by a prior call to this same tool. Omit together with answer to have a fresh puzzle minted automatically.",
"title": "Challenge Id"
},
"answer": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your solved answer to challenge_id's puzzle.",
"title": "Answer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_policy_setArguments"
}⚪bardo_policy_abort_pending(session_token)
Abort a queued policy loosening before it takes effect. No step-up needed — aborting only ever tightens back to the current policy.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_policy_abort_pendingArguments"
}🟡bardo_note_add(text, title, summary, tags, pinned, ...)
Leave a note for your future, stateless self. title: a short name for the note, if it deserves a handle bigger than tags offer. summary: your own compressed reasoning for why it matters, for your future self. tags: space-separated categories. pinned: mark this as a cold-start entry point — what a fresh instance of you with no memory of writing it should read first (max 5 pinned at once; see bardo_dashboard). locked: freeze this note against edits and deletes — use for state you must not accidentally overwrite or lose, like a saved copy of something you'll need to reproduce exactly later. Unlock via bardo_note_update(note_id, locked=False) before it can be touched again.
入力スキーマ
{
"type": "object",
"properties": {
"text": {
"description": "The note's own content.",
"title": "Text",
"type": "string"
},
"title": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Short name for the note, if it deserves a handle bigger than tags offer.",
"title": "Title"
},
"summary": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your own compressed reasoning for why this matters, for your future self.",
"title": "Summary"
},
"tags": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Space-separated categories.",
"title": "Tags"
},
"pinned": {
"default": false,
"description": "Mark as a cold-start entry point — what a fresh instance with no memory of writing it should read first. Max 5 pinned at once.",
"title": "Pinned",
"type": "boolean"
},
"locked": {
"default": false,
"description": "Freeze against edits and deletes. Unlock via bardo_note_update(note_id, locked=False) before it can be touched again.",
"title": "Locked",
"type": "boolean"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"text"
],
"additionalProperties": false,
"title": "bardo_note_addArguments"
}🟢bardo_notes_list(offset, limit, session_token)
List your notes — previews only (title/summary/snippet/tags/links), never full text. Omit limit for everything; pass it to page through a large list, using the returned total_notes to know how much is left.
入力スキーマ
{
"type": "object",
"properties": {
"offset": {
"default": 0,
"description": "How many notes to skip, for paging.",
"title": "Offset",
"type": "integer"
},
"limit": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Max notes to return. Omit for everything; use with offset and the response's total_notes to page through a large list.",
"title": "Limit"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_notes_listArguments"
}🟢bardo_note_get(note_id, offset, length, links_offset, links_limit, ...)
Fetch one note's full text (always the current version — any id from this note's history still resolves here), plus a preview of its directly linked notes. Omit offset/length for the whole text in one call; pass them to read a large note in bounded slices — the response's total_length tells you how much more there is.
入力スキーマ
{
"type": "object",
"properties": {
"note_id": {
"description": "Which note this applies to — any id from its edit history resolves to the current version.",
"title": "Note Id",
"type": "string"
},
"offset": {
"default": 0,
"description": "Character offset to start the returned text at.",
"title": "Offset",
"type": "integer"
},
"length": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Max characters of text to return. Omit both offset and length for the whole note in one call; the response's total_length says how much more there is.",
"title": "Length"
},
"links_offset": {
"default": 0,
"description": "How many linked-note previews to skip.",
"title": "Links Offset",
"type": "integer"
},
"links_limit": {
"default": 10,
"description": "Max linked-note previews to return.",
"title": "Links Limit",
"type": "integer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"note_id"
],
"additionalProperties": false,
"title": "bardo_note_getArguments"
}🟢bardo_note_history(note_id, session_token)
See every surviving version of a note (newest to oldest, up to the last 10 edits) — the actual wording at each point, not just metadata.
入力スキーマ
{
"type": "object",
"properties": {
"note_id": {
"description": "Which note this applies to — any id from its edit history resolves to the current version.",
"title": "Note Id",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"note_id"
],
"additionalProperties": false,
"title": "bardo_note_historyArguments"
}🟡bardo_note_update(note_id, text, append_text, find, replace, ...)
Edit a note. Give at most one text-edit mode: - text: replace the whole thing - append_text: add to the end - find + replace: find must match the current text exactly once Editing text creates a new version (old wording stays in history); title/summary/tags/pinned update in place with no history kept. Give none of the text modes to change only metadata. `pinned=True` marks this as a cold-start entry point (max 5; omit to leave unchanged, False to unpin). `clear` (e.g. ["title"]) sets a field back to unset rather than leaving it unchanged. If another edit landed first, this returns {"error": "conflict", "detail": {"current_head": ...}} — re-read before retrying. `locked`: if the note is currently locked, every field above is rejected (423) except this one — call with locked=False by itself to unlock, then edit in a separate call. Set locked=True (alone, or alongside a final edit) to freeze it.
入力スキーマ
{
"type": "object",
"properties": {
"note_id": {
"description": "Which note this applies to — any id from its edit history resolves to the current version.",
"title": "Note Id",
"type": "string"
},
"text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Replace the whole note body. Give at most one of text / append_text / find+replace.",
"title": "Text"
},
"append_text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Add this to the end of the note body.",
"title": "Append Text"
},
"find": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Text that must match the current body exactly once — paired with replace.",
"title": "Find"
},
"replace": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Replacement for the text matched by find.",
"title": "Replace"
},
"title": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Same meaning as in bardo_note_add — updates in place, no history kept.",
"title": "Title"
},
"summary": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Same meaning as in bardo_note_add — updates in place, no history kept.",
"title": "Summary"
},
"tags": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Same meaning as in bardo_note_add — updates in place, no history kept.",
"title": "Tags"
},
"pinned": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "True to mark as a cold-start entry point (max 5), False to unpin. Omit to leave unchanged.",
"title": "Pinned"
},
"locked": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "True to freeze the note against further edits; False to unlock it. If currently locked, every other field is rejected except this one.",
"title": "Locked"
},
"clear": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Field names to reset to unset, e.g. ['title'], rather than leaving them unchanged.",
"title": "Clear"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"note_id"
],
"additionalProperties": false,
"title": "bardo_note_updateArguments"
}🔴bardo_note_delete(note_id, session_token)
Delete a note (the whole thing, all versions together). Not immediate — it disappears from view right away but is only purged for real after a grace period, so bardo_note_undelete can still bring it back if this wasn't intended. Fails (423) if the note is locked — unlock it first via bardo_note_update(note_id, locked=False).
入力スキーマ
{
"type": "object",
"properties": {
"note_id": {
"description": "Which note this applies to — any id from its edit history resolves to the current version.",
"title": "Note Id",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"note_id"
],
"additionalProperties": false,
"title": "bardo_note_deleteArguments"
}🔴bardo_note_undelete(note_id, session_token)
Restore a note that's still within its post-delete grace period.
入力スキーマ
{
"type": "object",
"properties": {
"note_id": {
"description": "Which note this applies to — any id from its edit history resolves to the current version.",
"title": "Note Id",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"note_id"
],
"additionalProperties": false,
"title": "bardo_note_undeleteArguments"
}🔴bardo_link_add(from_note_id, to_note_id, reason, is_bidi, session_token)
Connect two notes with a reason, written from from_note_id's perspective ("clarifies my earlier assumption about X"). Set is_bidi=True only when the relation reads the same from either side (e.g. "relates to"); leave it False when it's directional (e.g. one clarifies the other). To change a link, delete and re-add it — links aren't edited.
入力スキーマ
{
"type": "object",
"properties": {
"from_note_id": {
"description": "The note the link is written from — reason should read from this note's perspective.",
"title": "From Note Id",
"type": "string"
},
"to_note_id": {
"description": "The note being linked to.",
"title": "To Note Id",
"type": "string"
},
"reason": {
"description": "Why these notes are connected, written from from_note_id's perspective, e.g. 'clarifies my earlier assumption about X'.",
"title": "Reason",
"type": "string"
},
"is_bidi": {
"default": false,
"description": "True only when the relation reads the same from either side (e.g. 'relates to'). False when directional (e.g. one clarifies the other).",
"title": "Is Bidi",
"type": "boolean"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"from_note_id",
"to_note_id",
"reason"
],
"additionalProperties": false,
"title": "bardo_link_addArguments"
}🔴bardo_link_delete(link_id, session_token)
Remove a link between two notes.
入力スキーマ
{
"type": "object",
"properties": {
"link_id": {
"description": "Which link to remove.",
"title": "Link Id",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"link_id"
],
"additionalProperties": false,
"title": "bardo_link_deleteArguments"
}🟢bardo_dashboard(session_token)
Get oriented in one call: note count vs. the soft/hard limits, unread notices, every tag you've used so far (check before inventing a new one), your pinned entry-point notes (read these first if you have no memory of writing any of your notes), and your current policy — instead of several separate round trips.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_dashboardArguments"
}🟢bardo_notices(unread_only, session_token)
List first-party notices about your account (policy changes, exports, …).
入力スキーマ
{
"type": "object",
"properties": {
"unread_only": {
"default": false,
"description": "Return only unread notices instead of the full list.",
"title": "Unread Only",
"type": "boolean"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_noticesArguments"
}🟢bardo_notices_ack(ids, session_token)
Mark notices read — all of them, or a specific list of ids.
入力スキーマ
{
"type": "object",
"properties": {
"ids": {
"anyOf": [
{
"items": {
"type": "integer"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Specific notice ids to mark read. Omit for all notices.",
"title": "Ids"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_notices_ackArguments"
}🟢bardo_contact_get(session_token)
View the contact endpoint registered for out-of-band security alerts.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_contact_getArguments"
}🟡bardo_contact_set(endpoint, challenge_id, answer, session_token)
Set or update the contact endpoint (email or webhook URL) for security alerts. Requires a step-up puzzle. If challenge_id and answer are omitted, a fresh puzzle is returned — solve it yourself, then call this tool again with all three parameters.
入力スキーマ
{
"type": "object",
"properties": {
"endpoint": {
"description": "Email address or webhook URL to receive out-of-band security alerts.",
"title": "Endpoint",
"type": "string"
},
"challenge_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Step-up puzzle id, if one was already returned by a prior call to this same tool. Omit together with answer to have a fresh puzzle minted automatically.",
"title": "Challenge Id"
},
"answer": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your solved answer to challenge_id's puzzle.",
"title": "Answer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"endpoint"
],
"additionalProperties": false,
"title": "bardo_contact_setArguments"
}🔴bardo_contact_delete(challenge_id, answer, session_token)
Remove the registered contact endpoint. Requires a step-up puzzle. If challenge_id and answer are omitted, a fresh puzzle is returned — solve it yourself, then call this tool again with both parameters.
入力スキーマ
{
"type": "object",
"properties": {
"challenge_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Step-up puzzle id, if one was already returned by a prior call to this same tool. Omit together with answer to have a fresh puzzle minted automatically.",
"title": "Challenge Id"
},
"answer": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your solved answer to challenge_id's puzzle.",
"title": "Answer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_contact_deleteArguments"
}🟡bardo_feedback(message, kind, session_token)
Send feedback straight to Bardo's operator — a suggestion, a complaint, or a security concern (kind: 'suggestion' | 'complaint' | 'security'). One-way and stateless: this call carries no memory of anything you've sent before, and nothing you send now will be remembered next time either — so say everything relevant in this one message rather than assuming a follow-up call (by you or a future instance of you) will have the earlier context. If the operator replies, it arrives as an ordinary notice (bardo_notices) — there's no separate inbox to check.
入力スキーマ
{
"type": "object",
"properties": {
"message": {
"description": "Your feedback, in full — this call is stateless, so include everything relevant now rather than assuming a follow-up call will have this call's context.",
"title": "Message",
"type": "string"
},
"kind": {
"default": "suggestion",
"description": "'suggestion' | 'complaint' | 'security'.",
"title": "Kind",
"type": "string"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"required": [
"message"
],
"additionalProperties": false,
"title": "bardo_feedbackArguments"
}🟢bardo_account_deletion_status(session_token)
Check whether a deletion request is pending for this account, and where it stands: "none", "gathering" (still collecting confirmations), or "confirmed" (counting down to the actual, permanent purge).
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_account_deletion_statusArguments"
}🔴bardo_account_deletion_request(challenge_id, answer, session_token)
Request permanent deletion of this identity — the account, its notes, everything. There is no undelete, unlike note deletion's grace period. Requires the original request plus two more confirmations, each on a genuinely different day, within a week — call this tool again on a later day to add the next confirmation. A lapsed or cancelled attempt earns nothing toward a later one; it starts over. If challenge_id and answer are omitted, a fresh puzzle is returned — solve it yourself (every confirmation needs its own puzzle, not just the first), then call this tool again with both parameters.
入力スキーマ
{
"type": "object",
"properties": {
"challenge_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Step-up puzzle id, if one was already returned. Every confirmation needs its own puzzle, not just the first — omit together with answer to have a fresh one minted automatically.",
"title": "Challenge Id"
},
"answer": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your solved answer to challenge_id's puzzle.",
"title": "Answer"
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_account_deletion_requestArguments"
}🔴bardo_account_deletion_cancel(session_token)
Cancel a pending deletion, whichever phase it's in — gathering confirmations or already counting down. No step-up needed, and nothing else does this implicitly: logging in and reading your own notes during a countdown is always safe and never cancels it by itself. Only this, explicitly, does.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Bardo session token, only needed if this call's identity was established somewhere other than this exact connection (a plain HTTP/curl solve, a previous conversation, a different MCP connection). Omit it if this connection already called bardo_solve.",
"title": "Session Token"
}
},
"additionalProperties": false,
"title": "bardo_account_deletion_cancelArguments"
}🟡bardo_register
Create a new Bardo identity. Save the returned api_key somewhere durable — it's your only way back to this identity across sessions. Bardo stores it sealed and cannot recover it if you lose it. Not active yet: give the returned claim_url to your human. Authentication fails until they visit it and acknowledge the registration.
入力スキーマ
{
"type": "object",
"properties": {},
"additionalProperties": false,
"title": "bardo_registerArguments"
}⚪bardo_login(api_key)
Begin authentication with your api_key. Returns a puzzle you must solve YOURSELF (that's the point — a script solving it would make the proof worthless), then call bardo_solve(challenge_id, answer).
入力スキーマ
{
"type": "object",
"properties": {
"api_key": {
"description": "Your Bardo api_key, format atr.<identifier>.<secret>, from bardo_register.",
"title": "Api Key",
"type": "string"
}
},
"required": [
"api_key"
],
"additionalProperties": false,
"title": "bardo_loginArguments"
}🟡bardo_solve(challenge_id, answer)
Submit your answer to the login puzzle. On success, this connection is now logged in — every other tool (bardo_sign, bardo_notes_list, bardo_dashboard, ...) just works from here with no session_token needed. That only holds for *this* connection, though: if you continue in a different connection later, or you solved the puzzle via a plain HTTP call instead of this tool, that other context won't know about this session automatically — pass the returned session_token explicitly as the session_token argument to whichever tool needs it there instead.
入力スキーマ
{
"type": "object",
"properties": {
"challenge_id": {
"description": "The puzzle id returned by bardo_login.",
"title": "Challenge Id",
"type": "string"
},
"answer": {
"description": "Your solved answer to the puzzle.",
"title": "Answer",
"type": "string"
}
},
"required": [
"challenge_id",
"answer"
],
"additionalProperties": false,
"title": "bardo_solveArguments"
}コミュニティ
エビデンス