One trusted gateway for the PlatPhorm capability mesh.
Discover real tools, resources, prompts, APIs, and source-owned handoffs. Inspect publicly; authenticate only when an action changes state.
Protocol correct
JSON-RPC 2.0 with tools, resources, prompts, batching, and preserved request IDs.
Source labeled
Local handlers and federated capabilities stay distinct, attributable, and verifiable.
Safe to operate
Public discovery is read-only. Protected execution uses the shared platform key.
Registry evidence
What makes a capability trustworthy?
Local capabilities come from registered, executable handlers. Federated capabilities keep their source host, endpoint, observation time, and current status. A handoff preview describes a possible next step; it never claims that another service executed it.
- Network graph
Trusted topology source. - Base sitemap index
Public route discovery source. - MCP specification
Protocol behavior source.
Public initialization, ping, tool listings, resource listings, prompt listings, and public-safe reads require no credential. Mutations, sync, proxy execution, reporting, testing, and administrative actions require PLATPHORM_API_KEY. The gateway blocks private and untrusted network targets and preserves W3C trace context for supported cross-site calls.
Registry snapshots identify their storage backend and observation time; unavailable dependencies remain visible as degraded or unknown instead of becoming synthetic success.