mcp server
Raziel
MCP server teaching AI agents to implement TideCloak: auth, E2EE, IGA, security analysis
Description as published by the maintainer. Source
- version 1.9.6
- active
- testing
- security
active — Registry entry last updated 2026-08-06. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
18 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
tide_adapter(name)- Read an adapter instruction file (AGENTS, CLAUDE, replit) Required: name.
tide_blast_radius- Run a Blast Radius Assessment of an EXISTING app: an adversarial, vendor-neutral map of where authority is concentrated to a single point (whoever obtains that one thing obtains everything it governs), scored by blast radius (Total/Systemic/Contained/Limited) across three cores — Identity, Governance, Access — and delivered as a director-facing PDF. Phase 1 names no vendor; an opt-in Phase 2 companion explains how TideCloak shrinks each blast radius. Use this when the user wants to 'assess', 'red team', 'threat model', 'find the security gaps in', or make a before/after security case for an existing application.
tide_branding- How to produce and upload the enclave's branding assets — the LOGO and BACKGROUND_IMAGE the Tide login/approval enclave displays. Returns the VERIFIED upload contract (endpoint, multipart parts, the png/jpg/jpeg/gif/webp allowlist with SVG REJECTED, the 5 MB cap, save-AND-sign via set-branding), the recommended geometry with padding, a dependency-free GENERATOR script for agents that cannot create images, and image-model prompts for agents that can. CALL THIS whenever branding, a logo, a background, theming or 'skinning' the enclave/login screen comes up, and before generating or uploading any image — a wrong format or an unpadded logo wastes an upload and, worse, ships a broken-looking login screen.
tide_canon(name)- Read a canon file (invariants, anti-patterns, concepts, framework-matrix, feature-mapping, troubleshooting, tidecloak-bootstrap, etc.) Required: name.
tide_choose_playbook(situation)- Recommend the right playbook for a given situation Required: situation.
tide_choose_scenario(situation)- Match a user request to a known scenario pattern before falling back to generic playbooks Required: situation.
tide_gaps- Read the gap register — what is still uncertain or unresolved in the pack
tide_hosting- Where TideCloak runs: local Docker vs partner-hosted (Skycloak managed TideCloak-as-a-service). Returns the local-vs-hosted decision with the honest trade-offs, the trust model, the verified Skycloak API reference (correct cluster field names and the required version), and the full provisioning playbook. CALL THIS BEFORE STARTING ANY TIDECLOAK DEPLOYMENT — the choice must be made up front (I-17) because a realm cannot be moved between local and hosted afterwards. Triggers: 'deploy to production', 'deploy TideCloak', 'go live', 'host this somewhere', 'managed option', 'stable URL', 'can someone host TideCloak for us', or any request to stand up an instance where local-vs-hosted has not been settled.
tide_list(category)- List all available content in the Tide agent pack by category Required: category.
tide_list_scenarios- List all available scenario patterns under reference-apps/
tide_playbook(name)- Read a step-by-step playbook for a specific Tide task Required: name.
tide_prompt(name)- Read a reusable starter prompt from the pack Required: name.
tide_scenario(name)- Read a scenario summary from reference-apps/<scenario>/scenario.md Required: name.
tide_scenario_bootstrap(name)- Read a scenario bootstrap sequence from reference-apps/<scenario>/bootstrap-sequence.md Required: name.
tide_scenario_manifest(name)- Read a scenario manifest from reference-apps/<scenario>/manifest.yaml Required: name.
tide_scenario_roles(name)- Read a scenario role-policy matrix from reference-apps/<scenario>/role-policy-matrix.md Required: name.
tide_security_analysis(include_runtime_probes)- Analyze an EXISTING (possibly non-Tide) system for security gaps and map them to Tide capabilities. Returns the Security Analyst role instructions, the security gap mapping table (SG-01…SG-18), and the runtime-probe procedures. Use this when the user asks 'do a security analysis', 'where is my auth weak', or 'what would Tide change about my security'.
tide_skill(name)- Read a composable skill definition Required: name.
Last successful function declaration observed on . Source: https://mcp.tide.org/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.tide.org/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.9.6 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-08-06 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-08-06 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 18 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.tide.org | |
| mcp endpoint status | ok | The server listed 18 functions when asked. | as of probe | mcp.tide.org |
Where to get it
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json