Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Live → Recently observed
Changed the definition of "arif_route"
⟨146 unchanged words⟩ the agent already knows the mission."},"mode":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"route"},"organ":{"anyOf":[{"type":"string ⟨141 unchanged words⟩
Changed the definition of "arif_forge", "arif_init", "arif_judge" and 5 more
KERNEL 777 ·ExecutionGovernedgateexecution:viaappliesA-FORGEa—mutationmutatesthrough A-FORGE onlyafterwhen carrying a SEALverdict.verdict (seal_verdict_id) from arif_judge and a live session. The manifest/query defines exactly what changes; mode=dry_run previews the plan without applying it. This is the only verb that executes general mutations — kernel memory writes go to arif_memory and permanent records to arif_seal.
Changed the definition of "arif_judge"
⟨76 unchanged words⟩ ":"null"}],"default":null},"claim_class":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"claim_text":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null},"constitutional_chain_id":{"anyOf":[{"type":"string ⟨163 unchanged words⟩
Changed the definition of "arif_memory"
⟨92 unchanged words⟩ remember, promote, revise, forget, audit,etc.metabolize.","enum":["recall","inspect","attest","remember","promote","revise","forget","audit","metabolize"],"type":"string"},"new_content": ⟨106 unchanged words⟩
Changed the definition of "arif_forge", "arif_init", "arif_judge" and 5 more
{"_derived_from":{"action_class":"MUTATE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":true,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":true,"idempotentHint":false,"openWorldHint":false ⟨8 unchanged words⟩
{"_derived_from":{"action_class":"PREPARE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":false,"idempotentHint":false,"openWorldHint":false ⟨8 unchanged words⟩
Certificate recorded, valid to 2026-11-25
Authorization not required
First tool surface recorded: 8 tools (server version kanon-2026.09.12+abf4507)
Showing the latest 9 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Internal transport envelope handle — server-side; omit.","title":"Envelope"},"ack_irreversible":{"default":false,"description":"Set true to confirm you accept this execution cannot be undone, when the judged action was irreversible.","type":"boolean"},"actor_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' — recorded in the audit log."},"approved_action_hash":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Hash of the exact action that was judged — execution is refused if what you submit differs from it."},"arif_ack_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Acknowledgment id from a prior step, for multi-step execution chains."},"artifact_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of an existing artifact (from an earlier forge or judge response) that this call operates on."},"constitutional_chain_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the evidence chain (observe→think→judge) that led to the SEAL — copy it from the judge response."},"judge_state_hash":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Hash string from the arif_judge SEAL response — proves the verdict has not been tampered with."},"manifest":{"default":"","description":"The work order (usually JSON or markdown) describing exactly what to build or change — the more specific, the tighter the gate.","type":"string"},"mode":{"default":"engineer","description":"'engineer' (default) — plan and apply the work; 'dry_run' — preview what would happen, nothing is applied; 'query' — read-only questions about the workspace; 'write' — write files; 'generate' — generate code or content; 'commit' — commit prepared work; 'recall' — retrieve past forge artifacts.","enum":["engineer","query","write", ⟨10 unchanged words⟩ {"type":"null"}],"default":null,"description":"Plan id from arif_think's plan mode, when executing an approved plan."},"query":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The task in plain language when no manifest is supplied, e.g. 'restart the gateway service'."},"seal_verdict_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The SEAL verdict id arif_judge returned — without it, nothing is executed."},"session_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session id returned by arif_init; scopes this execution to your governed session."},"session_token":{"anyOf":[{"type" ⟨2 unchanged words⟩ null"}],"default":null,"description":"Session Continuity Token (SCT)fromreturned by arif_init —continuityprovesfortheChatGPTsessionmulti-callispathyours."},"vault_entry_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the permanent-ledger entry linked to this execution, when one already exists."}},"type":"object"}
KERNEL 000 ·SessionIgniteignitiona—governed kernel session: binds actor identity, constitutional floors F1–F13, and the auditbeforechain.anyReturns the session_id + session_token that every other arif_*verb.verb requires. Use mode=preflight to inspect an existing session without re-igniting, mode=resume to continue one. Modes: init, preflight, resume, validate, canary, triage, epoch_open, epoch_seal, light, opt_out.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"ack_irreversible":{"default":false,"description":"Set true to acknowledge that session records are permanent audit artifacts and cannot be deleted afterwards.","type":"boolean"},"actor_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"actor_signature":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."},"agent_policy":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON constraints on your own behavior, e.g. {\"autonomy\": \"reversible_only\", \"forbidden\": [\"git push\"]}."},"auth_context":{"anyOf":[{"additionalProperties": ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON carrying external authentication material, e.g. {\"token_class\": \"bearer\", \"issuer\": \"github\"} — used for gating."},"caller_actor_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"If you are calling on behalf of another agent, that agent's id — builds a delegation chain for the audit log."},"client_capabilities":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON declaring what your client supports, e.g. {\"transports\": [\"http\"], \"protocol\": \"2025-11-25\"}."},"context":{"anyOf":[{"additionalProperties": ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON object of background facts to bind into the session, e.g. {\"repo\": \"arifOS\", \"task\": \"fix-tests\"}."},"counterparty":{"anyOf":[{"additionalProperties": ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON describing the other party in a two-agent exchange, e.g. {\"agent_id\": \"hermes/1\", \"role\": \"verifier\"}."},"declared_model_key":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The model you run on, e.g. 'zai-coding-plan/glm-5.3'. Informational only — the kernel records but never trusts it."},"delegation_mode":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Contract governing delegated calls, e.g. 'read_only' or 'governed'."},"epoch_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Optional id grouping related sessions into one long-running epoch, e.g. '2026-H2-ops'."},"evidence":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON list of facts you have already verified, e.g. [{\"fact\": \"pytest 299 passed\", \"source\": \"CI run\"}] — carried into the session record."},"executor_actor_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the agent that will actually carry out work under this session's permissions, if different from actor_id."},"idempotency_key":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Client-chosen key (e.g. 'job-42-attempt-1'). Retrying with the same key will not repeat the effect — safe retries on flaky networks."},"intent":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Plain-language statement of what this session is for, e.g. 'repair the failing MCP tests'. Recorded for audit."},"mode":{"default":"init","description":"What to do: 'init' (default) starts a new governed session; 'preflight' checks an existing session's state without creating one; 'resume' re-attaches to the session in session_id; 'validate' re-checks credentials; 'canary' is a transport probe; 'triage' reads session state; 'epoch_open'/'epoch_seal' bracket a long working window; 'light' is a minimal session; 'opt_out' records a privacy opt-out.","enum":["init","light","resume", ⟨14 unchanged words⟩ {"type":"null"}],"default":null,"description":"One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."},"payload":{"default":null,"description":"Extra mode-specific data as a JSON object; the mode's response tells you which fields it expects.","title":"Payload"},"previous_session_hash":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Hash string returned when your previous session closed; supplying it chains this session to that one, proving continuity."},"requested_authority":{"default":"OBSERVE_ONLY","description":"The highest class of action you may take: 'OBSERVE_ONLY' (read-only, default) or a higher governed class granted by your policy.","type":"string"},"session_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"sovereign_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Identifier of the human principal you act for, when acting under their explicit delegation."},"tooling":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON list of the tools you can use, e.g. [\"Bash\", \"Read\"] — lets the kernel scope what it will permit you."},"trace_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Correlation id of your choosing (e.g. 'req-8f3a') — lets you find this call later across kernel logs and organ systems."},"verbose":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Legacy on/off verbosity ('true'/'false'); prefer verbosity."},"verbosity":{"default":"minimal","description":"How detailed responses should be: 'minimal' (default), 'standard', or 'full'.","enum":["minimal","standard"," ⟨5 unchanged words⟩
KERNEL 666 ·ConstitutionalBinding constitutional arbitration: evaluates a candidate action or claim and returns SEAL / HOLD / SABAR / VOID with the full reason chain. Weighs action class, blast radius, reversibility, entropy pathway, and cooling state; a SEAL verdict here is what arif_forge requires before it will execute anything. Judge arbitrates —bindingitSEAL/HOLD/SABAR/VOIDdoesarbitration.not gather (evidence comes via arif_observe, reasoning via arif_think) and it does not mutate (execution is arif_forge, permanence is arif_seal). Modes: judge, intercept, validate, hold, escalate.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"action_class":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Kind of action under judgment: 'OBSERVE' (read-only), 'DRAFT' (compose text), 'MUTATE' (change state), 'IRREVERSIBLE' (permanent)."},"action_tier":{"default":"standard","description":"How risky the action is: 'standard', 'high', or 'critical' — higher tiers demand stronger evidence.","type":"string"},"actor_B":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your calibrated confidence for a prediction, 0.0–1.0 (Brier-style score component)."},"actor_Phi":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON map of supporting signals about you, e.g. {\"consistency\": 0.9, \"track_record\": 0.7}."},"actor_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"actor_signature":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."},"authority_effect":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"What permission a SEAL verdict would grant, e.g. 'execute forge plan P-9'."},"blast_radius":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Who or what the action can affect: 'self', 'session', 'organ', or 'federation'."},"candidate":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The action or claim being judged, stated plainly, e.g. 'delete table users in prod'."},"claim_class":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Epistemic strength of the claim: 'OBS' (directly observed), 'DER' (derived from observations), 'INT' (interpreted), 'SPEC' (speculative)."},"claim_text":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The exact claim sentence under judgment, e.g. 'uptime exceeded 99% in August'."},"constitutional_chain_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the evidence chain this call belongs to (observe→think→judge→seal). Copy it from the earlier step's response to link the steps together."},"context_source":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Where the candidate came from: 'session', 'file', or 'memory'."},"cooldown_entry_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of an existing cooling-period record to consult before this action may proceed."},"domain":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Subject area for claim evaluation, e.g. 'geoscience' or 'finance'."},"entropy_pathway":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"How the action changes system order: 'reduces', 'neutral', or 'increases' complexity."},"entropy_receipt":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON receipt from an entropy computation, bound to this judgment."},"evidence":{"anyOf":[{"additionalProperties" ⟨5 unchanged words⟩ {"type":"null"}],"default":null,"description":"The facts the verdict should rest on — a JSON list like [{\"fact\": \"tests pass\", \"source\": \"CI\"}], or an object."},"heart_critique":{"anyOf":[{"additionalProperties":true, ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON result of an ethics/dignity check, e.g. {\"coercion\": false, \"dignity\": 0.9} — feeds the verdict."},"key_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Which of your registered keys produced actor_signature, e.g. 'key-1'."},"mode":{"default":"judge","description":"'judge' (default) — render a verdict on candidate; 'intercept' — pre-flight gate before an action runs; 'validate' — re-check a prior verdict; 'hold' — place an action into a cooling period; 'escalate' — refer the decision to the human owner.","enum":["intercept","judge","validate", ⟨10 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON intent-calibration settings, e.g. {\"sincerity\": 0.8, \"stated_goal\": \"verify the claim\"}."},"nonce":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."},"requested_capability":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The specific capability being requested, e.g. 'forge.execute' — checked against the capability registry."},"reversibility_level":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"How hard the action would be to undo: 'reversible', 'hard', or 'irreversible'."},"seal_purpose":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"One sentence saying why this verdict/record must exist, e.g. 'closing deployment D-17'. Stored permanently alongside the record."},"session_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"sovereign_receipt":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Reference to the human owner's explicit approval, for the rare case where they have already decided directly."},"vault_entry_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the permanent-ledger entry this verdict should attach to (from an earlier arif_seal response)."}},"type":"object"}
KERNEL 555 ·MemoryGovernedgovernormemory—of the kernel itself: six tiers (L1–L6)governedwithsemanticper-mode gating. recall,storageinspect, andpersistence.audit are read paths; remember, revise, promote, and forget mutate tiers — promote and forget additionally require human_approval=true. Use for cross-session lessons, canon, and memory audit; external evidence belongs to arif_observe and reasoning artifacts to arif_think. Modes: recall, inspect, attest, remember, promote, revise, forget, audit, metabolize.
⟨8 unchanged words⟩ null"}],"default":null,"description":"CallingYouractoragent(F11identity,attribution).e.g. 'kimi-code/FI-008' — recorded in the audit log."},"content":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"TextThebodytextfortorememberstoremode.(mode=remember) — write it as a self-contained lesson or fact."},"human_approval":{"default":false,"description":"ExplicitSet true ONLY when the humanapprovalownerforexplicitly approved this promote/forgetgates.— the gate refuses without it.","type":"boolean"},"idempotency_key":{ ⟨4 unchanged words⟩ null"}],"default":null,"description":"IdempotencyClient-chosen keyfor(e.g.write'memo-42');operations.retries with the same key will not store duplicates."},"lease_id":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"GovernedId of a short-lived permission grant (lease)ID.authorizing this write, when one was issued to you."},"memory_id":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"TargetUUID of the memoryUUIDentry(inspect/promote/revise/forget).to inspect/revise/forget — it was returned when the memory was created or last listed."},"mode":{"default":"recall","description":"Operation'recall'mode:(default)recall,—inspect,semanticattest,searchremember,ofpromote,storedrevise,memories;forget,'inspect'audit,—metabolize.read one memory in full; 'attest' — vouch for a memory's accuracy; 'remember' — store new text; 'promote' — move a memory up a tier; 'revise' — replace a memory's text; 'forget' — remove a memory (gated); 'audit' — integrity scan; 'metabolize' — compact and consolidate tiers.","enum":["recall","inspect"," ⟨15 unchanged words⟩ }],"default":null,"description":"Replacementcontenttext forrevise.the memory (mode=revise) — must refer to the same memory_id."},"payload":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"Mode-specificExtraparamsmode-specificdictfields(truth_class,asprovenance,JSONstructured— e.g. {\"truth_class\": \"DERIVED\",etc.).\"provenance\": \"CI log\"} for remember."},"query":{"anyOf":[{"type": ⟨2 unchanged words⟩ null"}],"default":null,"description":"SemanticWhat to searchqueryfor, in plain language (recall/auditmode=recall/audit)., e.g. 'past deploy rollback steps'."},"session_id":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"GoverningSession id returned by arif_init; attributes this call to your governed session."},"session_token":{"anyOf":[{" ⟨3 unchanged words⟩ null"}],"default":null,"description":"Session Continuity Token (SCT)fromreturnedarif_init.by arif_init — proves the session is yours."},"tier":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"MemoryWhich memory tierL1–L6.to target, 'L1'–'L6' (L1 = hot working memory, L6 = sealed canon)."},"to_tier":{"anyOf":[{"type ⟨3 unchanged words⟩ ,"default":null,"description":"Destination tierforwhenpromote.promoting, e.g. 'L4'."},"trace_id":{"anyOf":[{"type ⟨2 unchanged words⟩ null"}],"default":null,"description":"TraceCorrelationIDidforofaudit.your choosing (e.g. 'req-8f3a') to find this call later in the logs."}},"type":"object"}
KERNEL 111 ·SenseCollectrealityevidenceinto—evidencefacts and sources with epistemic tags (OBS) and uncertaintybounds.bounds, never conclusions. mode=search queries the open web/literature; mode=fetch retrieves a URL and records its provenance; mode=vitals reads kernel machine telemetry. Reason over what you gathered with arif_think; delegate domain analysis to an organ with arif_route. Modes: search, fetch, hybrid_discovery, ingest, compass, atlas, entropy_dS, vitals.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"actor_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"layers":{"anyOf":[{"items" ⟨4 unchanged words⟩ {"type":"null"}],"default":null,"description":"Restrict where to look, e.g. [\"web\"] or [\"canon\", \"memory\"]; omit to search everything available."},"mode":{"default":"search","description":"'search' (default) — web/literature query; 'fetch' — retrieve one URL with provenance; 'hybrid_discovery' — combine sources; 'ingest' — absorb a document; 'compass'/'atlas' — guided navigation; 'entropy_dS' — measure system change; 'vitals' — kernel machine telemetry.","enum":["search","fetch","hybrid_discovery", ⟨11 unchanged words⟩ {"type":"null"}],"default":null,"description":"What to look for, in plain language, e.g. 'TDQS scoring rubric MCP'."},"result_limit":{"default":10,"description":"Maximum number of results to return in search modes; default 10.","type":"integer"},"session_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"url":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Exact URL to retrieve when mode=fetch, e.g. 'https://example.com/report.pdf'."}},"type":"object"}
KERNEL 444 · Intent→organ router:—classifies a natural-language intent and dispatches it toGEOX/WEALTH/WELL/A-FORGE.the specialist organ (GEOX geoscience, WEALTH capital, WELL vitality, A-FORGE execution). Returns the routing decision only — no organ call — unless organ_tool names the target tool and arguments carries its inputs. Prefer this over guessing organs yourself; use arif_think for reasoning you keep in-kernel.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"actor_id":{"anyOf" ⟨3 unchanged words⟩ null"}],"default":null,"description":"CallingYouractor.agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"arguments":{"anyOf":[{"additionalProperties ⟨21 unchanged words⟩ {"type":"null"}],"default":null,"description":"Extra keyword arguments passed through to the organ tool call, as a JSON object."},"intent":{"anyOf":[{"type" ⟨117 unchanged words⟩ null"}],"default":null,"description":"GoverningSession id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{" ⟨3 unchanged words⟩ null"}],"default":null,"description":"Session Continuity Token (SCT)from— the credential string arif_init(ChatGPTreturnedcontinuity).alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"task":{"anyOf":[{"type ⟨14 unchanged words⟩
KERNEL 999 · Append an entry to VAULT999, the immutableappendledger —irreversibleacceptedcivilizationalentriesmemorycansealing.never be edited or removed; there is no unseal. Use for permanent records of verified outcomes, lessons, and session closure once a verdict exists. ack_irreversible=true is the explicit acknowledgment of permanence, and judge_state_hash binds the entry to the verdict that authorized it. Reversible changes belong in arif_forge under a SEAL. Modes: seal, verify, ledger, changelog, audit, session_close.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"ack_irreversible":{"default":false,"description":"Set true to confirm you understand sealed entries are PERMANENT — they can never be edited or removed.","type":"boolean"},"actor_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"actor_signature":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."},"constitutional":{"anyOf":[{"additionalProperties" ⟨3 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON block of governance metadata (floors consulted, chain references) — normally built by the kernel, not by callers."},"constitutional_chain_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Id of the evidence chain this call belongs to (observe→think→judge→seal). Copy it from the earlier step's response to link the steps together."},"drift_events":{"anyOf":[{"items" ⟨6 unchanged words⟩ {"type":"null"}],"default":null,"description":"JSON list of deviations observed, e.g. [{\"what\": \"schema drift\", \"where\": \"tools/list\"}] — stored with the record."},"judge_state_hash":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Hash string from the arif_judge SEAL response — ties this entry to the verdict that authorized it."},"mode":{"default":"seal","description":"'seal' (default) — append a permanent entry; 'verify' — check one entry; 'ledger' — read the ledger head; 'changelog' — recent appends; 'audit' — integrity check; 'session_close' — close out a session into the ledger.","enum":["seal","verify","ledger", ⟨9 unchanged words⟩ {"type":"null"}],"default":null,"description":"One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."},"payload":{"default":"","description":"The content to store forever, as a string (usually JSON-serialized) — the outcome, lesson, or record itself.","type":"string"},"seal_purpose":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"One sentence saying why this verdict/record must exist, e.g. 'closing deployment D-17'. Stored permanently alongside the record."},"session_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"witness_type":{"default":"ai","description":"Who witnessed the sealed fact: 'ai', 'human', or 'external' system.","type":"string"}},"type":"object"}
KERNEL 333 ·MindStructured—reasoningstructuredpass: decomposes a query and returns reasoning steps labeled OBS (observed), DER (derived), INT (interpretation), SPEC (specification) underF2/F7truthwithfloors.OBS/DER/INT/SPECProduceslabels.reasoning records only — no verdicts (those come from arif_judge) and no state changes. The plan-family modes draft/review/approve execution plans; simulate and wonder explore counterfactuals. Modes: reason, reflect, verify, axioms, plan, plan_review, plan_approve, refactor_plan, metabolize, simulate, wonder, atlas.
{"additionalProperties":false,"properties":{"_envelope":{"default":null,"description":"Reserved for the transport layer — never fill this in.","title":"Envelope"},"actor_id":{"anyOf" ⟨2 unchanged words⟩ {"type":"null"}],"default":null,"description":"Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."},"mode":{"default":"reason","description":"'reason' (default) — decompose a question; 'reflect' — self-review of prior reasoning; 'verify' — check a derivation; 'axioms' — surface hidden assumptions; 'plan'/'plan_review'/'plan_approve'/'refactor_plan' — execution-plan lifecycle; 'metabolize' — consolidate past reasoning; 'simulate' — what-if; 'wonder' — open exploration; 'atlas' — map the problem space.","enum":["reason","reflect","verify", ⟨15 unchanged words⟩ {"type":"null"}],"default":null,"description":"Plan reference from an earlier plan-mode response — needed for the review/approve/refactor steps."},"query":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"The question, claim, or problem to reason about, in plain language."},"session_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."},"session_token":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"description":"Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."},"witness_type":{"default":"ai","description":"Who vouches for the reasoning record: 'ai' (default), 'human', or 'external' system.","type":"string"}},"type":"object"}
{"_derived_from":{"action_class":"DRAFT","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":false,"idempotentHint":false,"openWorldHint":false ⟨7 unchanged words⟩
{"_derived_from":{"action_class":"MUTATE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":true,"idempotentHint":false,"openWorldHint":false ⟨7 unchanged words⟩
{"_derived_from":{"action_class":"OBSERVE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":false,"idempotentHint":true,"openWorldHint":true ⟨8 unchanged words⟩
{"_derived_from":{"action_class":"ANALYZE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":false,"idempotentHint":true,"openWorldHint":false ⟨7 unchanged words⟩
{"_derived_from":{"action_class":"IRREVERSIBLE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":true,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":true,"idempotentHint":false,"openWorldHint":false ⟨7 unchanged words⟩
{"_derived_from":{"action_class":"ANALYZE","derivation":"arifOS action_class → MCP annotations (deterministic)","is_irreversible":false,"rule":"AAA Agent Invariant #6: HINTS ≠ CONTRACTS. Annotations are output of classification, not input."},"destructiveHint":false,"idempotentHint":true,"openWorldHint":false ⟨7 unchanged words⟩