Alter Onboarding
Guide developers from setup through a verified, policy-aware, audited Alter API call.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"alter-onboarding": {
"url": "https://mcp.alterauth.com/mcp"
}
}
}원격 엔드포인트
https://mcp.alterauth.com/mcpstreamable-http할 수 있는 일
도구 목록
도구 (14)
🟢list_phases
List the lifecycle phases this server serves (setup, modify) and what each is for.
입력 스키마
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_skills
List the guidance Skills available on this server, with the phase each serves. Read a skill via its resource (skill://alter/<name>).
입력 스키마
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡get_started(phase, use_case, goal)
Begin or change an Alter integration. Without args: lists the phases. With `phase`: returns that phase's flows + a heuristic hint — classify the use case YOURSELF and call again with `goal` for the plan. If the use case spans multiple flows, run them sequentially.
입력 스키마
{
"type": "object",
"properties": {
"phase": {
"description": "setup (integrate from scratch) or modify (change an existing integration).",
"type": "string",
"enum": [
"setup",
"modify"
]
},
"use_case": {
"description": "Plain-English description of what the developer wants.",
"type": "string",
"maxLength": 2000
},
"goal": {
"description": "The flow id YOU classified. Returns that flow's full plan.",
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent",
"add-provider",
"add-secret",
"add-agent",
"rotate-key",
"manage-grant",
"set-policy"
]
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪next_step(goal, after)
Return the next step for a flow. Pass the goal (flow id) and the id of the last completed step (omit `after` for the first step). Run each step's detect command FIRST and skip the run command when detection passes. The design step also returns that flow's complete starter ALTER_INTEGRATION.md.
입력 스키마
{
"type": "object",
"properties": {
"goal": {
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent",
"add-provider",
"add-secret",
"add-agent",
"rotate-key",
"manage-grant",
"set-policy"
],
"description": "The flow id (setup goal or modify operation)."
},
"after": {
"description": "Id of the last completed step (e.g. \"2\", \"3a\").",
"type": "string",
"maxLength": 10
}
},
"required": [
"goal"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡sdk_integration(language, goal)
Return the Alter SDK wiring (install + client init + request) to write into the developer's codebase, for a language and setup goal.
입력 스키마
{
"type": "object",
"properties": {
"language": {
"type": "string",
"enum": [
"python",
"typescript"
],
"description": "Target language."
},
"goal": {
"type": "string",
"enum": [
"user-data",
"backend-secret",
"agent"
],
"description": "The setup goal (user-data | backend-secret | agent)."
}
},
"required": [
"language",
"goal"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪sdk_pattern(language, pattern)
Return a runnable Alter SDK call pattern for a language: `proxy-call` (zero-egress proxy_request + HITL), `resolve-grant-by-user` (call as an end user via their delegated grant), `delegate-managed-secret` (the operator-side delegation step), or `resolve-ambiguous-grant` (an identity-mode call matched several of one user's grants: choose deliberately, never the first, and persist it; ask the developer at design time whether users can hold several accounts per provider). Use AFTER `sdk_integration` has wired the client.
입력 스키마
{
"type": "object",
"properties": {
"language": {
"type": "string",
"enum": [
"python",
"typescript"
],
"description": "Target language."
},
"pattern": {
"type": "string",
"enum": [
"proxy-call",
"resolve-grant-by-user",
"delegate-managed-secret",
"resolve-ambiguous-grant"
],
"description": "proxy-call | resolve-grant-by-user | delegate-managed-secret | resolve-ambiguous-grant."
}
},
"required": [
"language",
"pattern"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪troubleshoot(exit_code, error)
Map a @alter-ai/cli exit code or error message to a remediation.
입력 스키마
{
"type": "object",
"properties": {
"exit_code": {
"description": "The CLI process exit code.",
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
},
"error": {
"description": "The stderr / error message.",
"type": "string",
"maxLength": 10000
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪verify_integration(scenario)
Return a copy-pasteable recipe to VERIFY an integration works: `first-call` (code↔design, an audit row, correct attribution) or `per-user-isolation` (a multi-user/broker server runs two users under different credentials and rejects cross-user access). Guidance only — you run the commands.
입력 스키마
{
"type": "object",
"properties": {
"scenario": {
"type": "string",
"enum": [
"first-call",
"per-user-isolation"
],
"description": "first-call | per-user-isolation."
}
},
"required": [
"scenario"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢fetch_doc(slug)
Fetch any page of the Alter documentation by slug (e.g. "quickstart"). The whole published docs site is bundled here, skill pages included, so every page a doc, a skill or a flow step links to can be read in-band. Accepts any spelling the docs use: a bare slug, a leading slash, a #section anchor, a full docs.alterauth.com URL, or an older path that now redirects. Omit the slug to list every page.
입력 스키마
{
"type": "object",
"properties": {
"slug": {
"description": "Doc slug, e.g. \"guides/call-apis-on-behalf-of-users\".",
"type": "string",
"maxLength": 200
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢search_docs(query, limit)
Search every bundled page of the Alter documentation (docs and skill pages) by keywords: returns the best-matching pages with the section and a snippet that matched. Use it when a flow step or doc did not point you at the page you need, instead of guessing slugs or listing every page; then read one with fetch_doc and its slug.
입력 스키마
{
"type": "object",
"properties": {
"query": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Keywords or a short phrase, e.g. \"connect widget popup\" or \"PAT scopes login\"."
},
"limit": {
"description": "Maximum results (default 8, at most 20).",
"type": "integer",
"minimum": 1,
"maximum": 20
}
},
"required": [
"query"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_providers(kind)
List every provider with an ingested API spec in Alter's provider-spec catalog, with each spec's source and freshness. Optionally filter by `kind`. Start here, then call list_operations for a provider's operations.
입력 스키마
{
"type": "object",
"properties": {
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢list_operations(provider_id, kind, search, limit, offset)
List the API operations a provider exposes, live from Alter's provider-spec catalog (e.g. "what can I call on google?"). Returns operation ids + methods/paths, plus the spec's source and freshness. Omit `kind` to auto-detect the provider family; when the id exists in both oauth and managed you'll be asked to pass `kind`. Machine-readable rows ride in `structuredContent` (see this tool's outputSchema) — read those rather than parsing the prose.
입력 스키마
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Provider id, e.g. \"google\" or \"github\"."
},
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
},
"search": {
"description": "Case-insensitive filter over operation ids/paths/summaries.",
"type": "string",
"maxLength": 200
},
"limit": {
"description": "Max operations to return (backend default 100, max 500).",
"type": "integer",
"minimum": 1,
"maximum": 500
},
"offset": {
"description": "Zero-based offset for paging through large operation lists.",
"type": "integer",
"minimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"provider_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}출력 스키마
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"description": "Resolved provider id the rows belong to."
},
"provider_kind": {
"type": "string",
"enum": [
"oauth",
"managed"
],
"description": "Resolved provider family: oauth or managed."
},
"spec_version": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Alter's ingested spec version these rows came from."
},
"total": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Total operations matching the query (before limit/offset)."
},
"offset": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991,
"description": "Zero-based offset of the first row."
},
"operations": {
"type": "array",
"items": {
"type": "object",
"properties": {
"operation_id": {
"type": "string",
"description": "Pass to get_operation_schema for the full contract."
},
"method": {
"type": "string",
"description": "HTTP method, e.g. GET."
},
"path_template": {
"type": "string",
"description": "Path with {placeholders}, e.g. /repos/{owner}/{repo}."
},
"summary": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"description": "One-line description, or null when the spec omits it."
}
},
"required": [
"operation_id",
"method",
"path_template",
"summary"
],
"additionalProperties": false
},
"description": "This page of operations, in the catalog's serving order."
}
},
"required": [
"provider_id",
"provider_kind",
"spec_version",
"total",
"offset",
"operations"
],
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false
}🟢get_operation_schema(provider_id, operation_id, kind)
Fetch one provider API operation's full contract — method, path, parameters, request/response schemas — live from Alter's provider-spec catalog, plus the spec's source and freshness. Get operation ids from list_operations first.
입력 스키마
{
"type": "object",
"properties": {
"provider_id": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Provider id, e.g. \"google\" or \"github\"."
},
"operation_id": {
"type": "string",
"minLength": 1,
"maxLength": 500,
"description": "Operation id from list_operations, e.g. \"gmail.users.messages.list\"."
},
"kind": {
"description": "Provider family: oauth (user-authorized) or managed (API-key).",
"type": "string",
"enum": [
"oauth",
"managed"
]
}
},
"required": [
"provider_id",
"operation_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡policy_language(rule_type)
The authoritative grammar of Alter's runtime-policy language, live from the deployed backend: every authorable rule type with its JSON body schema, caps, authorable levels, worked examples, and fail-closed semantics. Call with no arguments for the overview; pass `rule_type` (e.g. "content_match") for one type's full grammar. Use it before authoring rules with `alter policy rules create` — never guess a body shape. Vocabulary: the dashboard's "Runtime policies" surface, the docs' "policy", and `alter policy` are one feature, and the dashboard's "Human in the loop (HITL)" type is the `require_approval` rule type (its grant-editor block is the grant-level baseline of the same gate). Workflow prose: the `set-policy` modify flow (`get_started` with phase=modify), fetch_doc("guides/set-policies"), fetch_doc("guides/add-human-in-the-loop-approvals"), and fetch_doc("reference/cli/commands/policy").
입력 스키마
{
"type": "object",
"properties": {
"rule_type": {
"description": "One rule type's full grammar, e.g. \"content_match\" or \"quota\".",
"type": "string",
"minLength": 1,
"maxLength": 50
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}커뮤니티
증거