npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@torque-labs/mcp

v0.5.0

Published

MCP server for authenticated Torque projects, incentive creation, and AI assistance

Readme

Torque MCP Server

This MCP connects AI assistants to Torque. Every discoverable tool has an explicit endpoint and credential class.

Login

Start the MCP normally, then call:

auth({ action: "login" })

Open the returned verification link (or open the manual page and enter the user code). After approving the MCP, call:

auth({ action: "complete" })

Each complete call performs at most one device-token poll and honors the server's interval, authorization_pending, and slow_down responses. A redeemed session is validated against https://server-v3.torque.so before it becomes active. If login is superseded after redemption, the MCP makes a best-effort sign-out request and does not publish the credential.

Local sessions are stored as private, origin-bound items in the operating-system credential store (macOS Keychain, Windows Credential Manager, or the Linux Secret Service). The MCP loads the item without making startup network requests, then revalidates the session inside the first authenticated request. Identity JWTs and pending device challenges are memory-only.

TORQUE_SESSION_TOKEN remains available as an optional externally managed bootstrap. Environment sessions are never persisted or remotely revoked by the MCP; logout only disables them in the current process.

Do not use the old TORQUE_API_TOKEN; this server accepts only current Torque sessions.

Configuration

| CLI argument | Environment variable | Default | Purpose | | --------------- | ------------------------- | --------------------------------- | ----------------------------------------------- | | --apiUrl | TORQUE_API_URL | https://server-v3.torque.so | Exact Torque API origin | | --aiUrl | TORQUE_AI_URL | https://ai.torque.so | Exact Torque AI origin | | --platformUrl | TORQUE_PLATFORM_URL | https://platform-v3.torque.so | Exact device-verification platform origin | | — | TORQUE_SESSION_TOKEN | — | Optional externally managed Better Auth session |

Production origins must use HTTPS. Loopback HTTP is accepted only for local development.

The OS credential store must be available and unlocked for locally managed login. Headless or CI environments without one can provide TORQUE_SESSION_TOKEN; that value is process-only and is never copied into the credential store.

Advertised tools

| Tool | Credential | Purpose | | --------------------------- | -------------------------- | ----------------------------------------------------------------- | | auth | Public device flow/session | Start or complete login, inspect status, and securely log out | | list_projects | Better Auth session | List projects accessible to the account | | set_active_project | Better Auth session | Validate and select the project used by AI operations | | get_ai_context | Short-lived identity JWT | Fetch project grounding context | | ask_torque | Short-lived identity JWT | Send a project-scoped question to the unchanged Torque AI service | | reset_context | None | Clear the selected project, AI-context cache, and chat history | | list_incentives | Better Auth session | List incentives on the active project | | get_incentive | Better Auth session | Inspect configuration, epochs, query, and funding state | | get_incentive_leaderboard | Better Auth session | Read the latest available per-wallet leaderboard | | create_project | Better Auth session | Preview and explicitly confirm a project |

The MCP also advertises one prompt, ask-torque, and one resource, torque://ask-torque/capabilities. Legacy tools are not included in this package.

Credential flow

POST server-v3.torque.so/api/auth/device/code
  -> browser approval at platform-v3.torque.so/device
  -> POST server-v3.torque.so/api/auth/device/token
  -> validate via GET server-v3.torque.so/api/auth/get-session
  -> private local Better Auth session
  -> session-only project endpoints
  -> GET server-v3.torque.so/api/auth/token
  -> memory-only identity JWT
  -> /ai-context/:projectId and ai.torque.so/api/chat

One TorqueClient owns this entire flow. Tools call its business methods directly; the client validates the session, attaches the correct credential, and performs the request. AI methods mint an identity JWT immediately before use. Redirects are rejected and origins are pinned.

Logout blocks credential use, asks Better Auth to revoke the session, and deletes the local credential only when revocation succeeds or the server reports that the session is already invalid. On a transient failure, the credential is retained so logout can be retried and must be revalidated before normal use.

Verification

From the repository root:

npm run lint --workspace @torque-labs/mcp
npm run typecheck --workspace @torque-labs/mcp
npm test --workspace @torque-labs/mcp
npm run build --workspace @torque-labs/mcp

The protocol suite asserts that tools/list contains exactly the thirteen tools above.