This release is a pre-release and may not be stable for production use.
KRAIL MCP Server
rail-mcp exposes a local KRAIL project to MCP-compatible agents and clients.
It is the bridge that lets tools like Codex, Claude Code, Cursor, and other
MCP clients query a repo-backed local knowledge workspace instead of relying on
ephemeral chat context alone.
Use it when you want:
- local project memory instead of repeated file uploads
- typed
find, search, andthinkover a KRAIL workspace from an MCP client - public-by-default permission checks and
permissions_doctor - capture, tasks, workflows, and project health checks exposed to agents
The MCP server is an adapter over the repo-backed knowledge engine, not the source of truth.
Stable V1 Tools
rail-mcp 1.1.13 preserves the stable local-runtime v1 tool contract below. This
is not a claim that every MCP-exposed surface is frozen; unlisted tools remain
experimental and the hosted API and engine packages are outside this contract.
The v1 compatibility promise applies only to the tool families below. These are the tools we expect clients to build against for KRAIL v1 readiness.
contract:mcp_contractprovider_v1:provider_info,provider_describe_types,provider_search,provider_find,provider_get_resource,provider_retrieve_evidence,provider_explain,provider_lineage,provider_integritydoctor:doctorsearch:search,findthink:think,register_think_result,think_sessions,think_session_statuscapture:capture,topic_list,topic_upsert,inbox_list,inbox_promotetasks:create_task,list_tasks,dispatch_taskworkflows:list_workflows,workflow_templates,init_workflow,show_workflow,validate_workflow,run_workflow,execute_workflow,workflow_runs,workflow_status,workflow_dashboardintegrity:integrity_status,integrity_assumptions,integrity_sources,integrity_claims,integrity_claim_candidates,integrity_artifacts,integrity_promote_claim_candidate,integrity_reproducibility_rerun,integrity_freshness_evaluate,integrity_source_detail,integrity_claim_detail,integrity_verification_runs,integrity_benchmark,integrity_stale_graph,integrity_promote_artifact,integrity_artifact_detail,integrity_graph,integrity_retrieve,integrity_rerun_planpermissions:permissions_doctor
Stable tools return JSON on success and should return actionable JSON error payloads for invalid input, project/configuration problems, permission denials, and common runtime failures instead of raw Python tracebacks where feasible.
Clients can discover this boundary at runtime by calling mcp_contract. The
tool does not require a project to be loaded and returns the stable groups and
tool names, the currently exposed experimental tool names, and the stable JSON
error shape. Pass contract_version="v1" (the default); unsupported versions
also return an actionable JSON error payload.
The provider_v1 tools are the storage-independent boundary. Except for
negotiation and type description, they accept strict provider-v1 request JSON
and return the same models as the local Python and CLI surfaces.
Experimental Tools
Everything not listed in the stable v1 section is experimental and excluded from the compatibility promise for now. That currently includes:
- ontology and entity tools such as
list_classes,get_entities,search_entities - fixed policy-shaped semantic reads through
provider_semantic_operation(no arbitrary graph query language) - graph, vector, and source-maintenance tools
- mode, pack, agent-scaffolding, and repository inspection helpers
- listeners, events, queues, and other automation-oriented tools
- SQL, Python execution, analysis plugins, registry discovery, and hydration
- runner-session protocol tools and secret-management tools
- 1.1 action, retriever, evidence-packet, trigger, and unified-run tools
Experimental tools may change shape, move behind narrower permissions, or be removed before a broader post-v1 contract is declared.
Local Usage
Install the local KRAIL runtime from PyPI, then install the MCP adapter from
the released GitHub source. rail-mcp is not yet a separately published PyPI
project:
pip install 'krail[local]'
pip install 'git+https://github.com/AkeBoss-tech/knowledge.git@v1.1.13#subdirectory=packages/mcp-server'
For local development from a repository checkout:
pip install -e 'packages/rail-py[local]'
pip install -e packages/mcp-server
Run the server against a local project:
RAIL_LOCAL=1 RAIL_PATH=/path/to/project rail-mcp
For ready-to-copy client configuration, see the KRAIL integration guides.
Useful tool families include search, think, capture, local vector search, markdown graph inspection, ontology access, workflow dispatch, SQL queries, and project health checks.
Current Status
rail-mcp follows the same 1.x local-runtime release line as krail.
Available in 1.1.13:
- local-project search,
find, and deterministicthink - capture, inbox promotion, topic upserts, and project health checks
- source dependency, graph, vector, workflow, and task surfaces
- repo-backed permission checks for MCP-mediated reads and writes
- experimental typed actions, retrieval plans and evidence packets, trigger aliases, and unified run inspection
Only the stable tool families listed above are part of the v1 contract. Everything else remains experimental, including:
- hosted API-backed deployments as a stable compatibility target
- host-level sandboxing or production-grade isolation outside repo-mediated permissions
- long-term compatibility guarantees for workflow/runner integrations
Package Compatibility
rail-mcp tracks the same major KRAIL line as the local runtime it adapts. The
1.1.13 package therefore depends on krail>=1.1.13,<2.0.0; a future incompatible
local-runtime contract requires a new major dependency range.
Permission Model
rail-mcp enforces KRAIL's local, repo-backed permission model when clients go
through MCP tools. In practice that means:
- missing metadata stays public-by-default for backward compatibility
- restrictive frontmatter and manifest rules can hide records or block actions
- denied access and allowed access to restricted or sensitive repo records are audited into the project repo
The MCP server is not a separate source of authority. It mediates access to the same repo-backed project state the CLI and SDK use.
Work Orders And Scope
When MCP tooling launches or inspects runner work, the work order may include a
structured capability_envelope alongside legacy fields such as
capabilities_required and allowed_paths.
That envelope is designed to be incremental:
- it narrows a session and is meant to be intersected with repo policy
- it records write paths, tool names, and secret names for adapter enforcement
- it is auditable through repo files and dispatch logs
It does not provide host-level isolation on its own. A user with direct shell or disk access can still bypass MCP and read files outside KRAIL-mediated surfaces.
Project Layout
The server expects a local KRAIL project with:
krail.yamlorrail.yaml.ontology/topics/sources/research_plan/research_plan/state/artifacts/- optional
.krail/vector.sqlitefor local vector search
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file rail_mcp-1.2.0rc2.tar.gz.
File metadata
- Download URL: rail_mcp-1.2.0rc2.tar.gz
- Upload date:
- Size: 31.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a7154dead8a54aa9ea73fa687ae5e9311e0a6405c349b7831e09a87e66520644
|
|
| MD5 |
fcd44edfd2bd69e1258a9f9f7d5b701c
|
|
| BLAKE2b-256 |
c81ca1707ac8615de1ab23dfade02b5636a958aba23465cde6a455ae7e0fa704
|
Provenance
The following attestation bundles were made for rail_mcp-1.2.0rc2.tar.gz:
Publisher:
release.yml on AkeBoss-tech/knowledge
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
rail_mcp-1.2.0rc2.tar.gz -
Subject digest:
a7154dead8a54aa9ea73fa687ae5e9311e0a6405c349b7831e09a87e66520644 - Sigstore transparency entry: 2497959361
- Sigstore integration time:
-
Permalink:
AkeBoss-tech/knowledge@d3e5fbc1d464f3d18f6fe82b6f7037395ef62049 -
Branch / Tag:
refs/tags/v1.2.0rc2 - Owner: https://github.com/AkeBoss-tech
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@d3e5fbc1d464f3d18f6fe82b6f7037395ef62049 -
Trigger Event:
release
-
Statement type:
File details
Details for the file rail_mcp-1.2.0rc2-py3-none-any.whl.
File metadata
- Download URL: rail_mcp-1.2.0rc2-py3-none-any.whl
- Upload date:
- Size: 20.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
27a8346ed38df667a7dc1d5ece48b47c9529196c3e35a0316a4ab03fcb7eb4e5
|
|
| MD5 |
178a16ccbcf4b8dc2e241bdf0a9ac8da
|
|
| BLAKE2b-256 |
fc32cb7470023f5cbfc2734b1b03755b79e7ee14c81486bf9c63b74ea3599f6b
|
Provenance
The following attestation bundles were made for rail_mcp-1.2.0rc2-py3-none-any.whl:
Publisher:
release.yml on AkeBoss-tech/knowledge
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
rail_mcp-1.2.0rc2-py3-none-any.whl -
Subject digest:
27a8346ed38df667a7dc1d5ece48b47c9529196c3e35a0316a4ab03fcb7eb4e5 - Sigstore transparency entry: 2497959636
- Sigstore integration time:
-
Permalink:
AkeBoss-tech/knowledge@d3e5fbc1d464f3d18f6fe82b6f7037395ef62049 -
Branch / Tag:
refs/tags/v1.2.0rc2 - Owner: https://github.com/AkeBoss-tech
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@d3e5fbc1d464f3d18f6fe82b6f7037395ef62049 -
Trigger Event:
release
-
Statement type: