@torque-labs/mcp
v0.5.0
Published
MCP server for authenticated Torque projects, incentive creation, and AI assistance
Readme
Torque MCP Server
This MCP connects AI assistants to Torque. Every discoverable tool has an explicit endpoint and credential class.
Login
Start the MCP normally, then call:
auth({ action: "login" })Open the returned verification link (or open the manual page and enter the user code). After approving the MCP, call:
auth({ action: "complete" })Each complete call performs at most one device-token poll and honors the server's interval, authorization_pending, and slow_down responses. A redeemed session is validated against https://server-v3.torque.so before it becomes active. If login is superseded after redemption, the MCP makes a best-effort sign-out request and does not publish the credential.
Local sessions are stored as private, origin-bound items in the operating-system credential store (macOS Keychain, Windows Credential Manager, or the Linux Secret Service). The MCP loads the item without making startup network requests, then revalidates the session inside the first authenticated request. Identity JWTs and pending device challenges are memory-only.
TORQUE_SESSION_TOKEN remains available as an optional externally managed bootstrap. Environment sessions are never persisted or remotely revoked by the MCP; logout only disables them in the current process.
Do not use the old TORQUE_API_TOKEN; this server accepts only current Torque sessions.
Configuration
| CLI argument | Environment variable | Default | Purpose |
| --------------- | ------------------------- | --------------------------------- | ----------------------------------------------- |
| --apiUrl | TORQUE_API_URL | https://server-v3.torque.so | Exact Torque API origin |
| --aiUrl | TORQUE_AI_URL | https://ai.torque.so | Exact Torque AI origin |
| --platformUrl | TORQUE_PLATFORM_URL | https://platform-v3.torque.so | Exact device-verification platform origin |
| — | TORQUE_SESSION_TOKEN | — | Optional externally managed Better Auth session |
Production origins must use HTTPS. Loopback HTTP is accepted only for local development.
The OS credential store must be available and unlocked for locally managed login. Headless or CI environments without one can provide TORQUE_SESSION_TOKEN; that value is process-only and is never copied into the credential store.
Advertised tools
| Tool | Credential | Purpose |
| --------------------------- | -------------------------- | ----------------------------------------------------------------- |
| auth | Public device flow/session | Start or complete login, inspect status, and securely log out |
| list_projects | Better Auth session | List projects accessible to the account |
| set_active_project | Better Auth session | Validate and select the project used by AI operations |
| get_ai_context | Short-lived identity JWT | Fetch project grounding context |
| ask_torque | Short-lived identity JWT | Send a project-scoped question to the unchanged Torque AI service |
| reset_context | None | Clear the selected project, AI-context cache, and chat history |
| list_incentives | Better Auth session | List incentives on the active project |
| get_incentive | Better Auth session | Inspect configuration, epochs, query, and funding state |
| get_incentive_leaderboard | Better Auth session | Read the latest available per-wallet leaderboard |
| create_project | Better Auth session | Preview and explicitly confirm a project |
The MCP also advertises one prompt, ask-torque, and one resource, torque://ask-torque/capabilities. Legacy tools are not included in this package.
Credential flow
POST server-v3.torque.so/api/auth/device/code
-> browser approval at platform-v3.torque.so/device
-> POST server-v3.torque.so/api/auth/device/token
-> validate via GET server-v3.torque.so/api/auth/get-session
-> private local Better Auth session
-> session-only project endpoints
-> GET server-v3.torque.so/api/auth/token
-> memory-only identity JWT
-> /ai-context/:projectId and ai.torque.so/api/chatOne TorqueClient owns this entire flow. Tools call its business methods directly; the client validates the session, attaches the correct credential, and performs the request. AI methods mint an identity JWT immediately before use. Redirects are rejected and origins are pinned.
Logout blocks credential use, asks Better Auth to revoke the session, and deletes the local credential only when revocation succeeds or the server reports that the session is already invalid. On a transient failure, the credential is retained so logout can be retried and must be revalidated before normal use.
Verification
From the repository root:
npm run lint --workspace @torque-labs/mcp
npm run typecheck --workspace @torque-labs/mcp
npm test --workspace @torque-labs/mcp
npm run build --workspace @torque-labs/mcpThe protocol suite asserts that tools/list contains exactly the thirteen tools above.
