scriptkittyos & labs

beam_mcp

A Model Context Protocol server core for the BEAM.

Protocol handling, two transports (stdio and a stateless Streamable HTTP Plug) and JSON Schema validation, with the tool catalog and the dispatch function injected by the host. The package holds no tools, no domain and no policy.

0.10.1 on HexApache-2.0
{:beam_mcp, "~> 0.10"}

It carries calls. It holds no authority.

No approvals, no receipts, no masking, by design. Whatever wraps it decides those. Risk tiers, approvals, receipts and egress masking are the consumer's, which is why Trinity and Requisition can sit on top of it without the package knowing either exists.

Supports the 2026-07-28 and 2025-11-25 protocol revisions.

Shipping now, decided and not built, scheduled, deliberately out.

From the README at v0.10.1, which keeps these four lists.

Shipping now

The protocol core for 2026-07-28 and 2025-11-25; the stdio and stateless Streamable HTTP transports; JSON Schema validation of tool arguments; the catalog contract for tools, resources and prompts declared by the host; the connectome (declared, observed, canonical bytes, diff) and reachability queries over it.

Decided, not built

A federation seam for merging graphs from several nodes, and effective connectivity: the observed graph weighted into the declared one. Multi-round-trip requests are decided against.

Scheduled

1.0.0, once the public API and the stated threat model have each survived a full minor release unchanged. After it, in order: the federation seam, effective connectivity, then the Tasks extension of the 2026-07-28 revision.

Deliberately out

Tools, domain and policy; risk tiers, approvals, receipts and egress masking; authority: the verdict on an edge, the key that signs it, the decision that acts on it.

Conformance, as two rows.

SuiteResultMeasured
@modelcontextprotocol/conformance 0.2.0-alpha.11, full suite, 2026-07-28 revision16 of 37 scenarios2026-09-15
Claimed surface5 of 6 scenarios2026-09-15

Both rows are printed together, with the date. A single number would mislead. The README explains each failing scenario and how to reproduce the run.

Provenance.

OpenSSF Best Practices silver, awarded 23 September 2026. Release tarballs from 0.6.0 onward are attested on GitHub. A CycloneDX SBOM ships at release. A FIPS CI leg runs.

beam_mcp_signer.

beam_mcp exposes a signer seam and a connectome: the declared and observed call graph of a composed MCP system, with canonical bytes, a digest, a diff and reachability queries. beam_mcp_signer 0.2.1 is an Ed25519 signer for those canonical bytes through OTP's :crypto; the host holds the key. OpenSSF Best Practices silver (project 14775).

{:beam_mcp_signer, "~> 0.2"}

beam_mcp 0.10.0 and beam_mcp_signer 0.2.0 are retired on Hex for security fixes; use 0.10.1 and 0.2.1 or later.

Maintainers and license.

Hex owners: aylacroft and mikehostetler. Apache-2.0 for code, CC BY 4.0 for documentation. Intended for possible donation.