{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_d7qh6xffy3q2","handle":"secureflows","url":"https://wellknown.network/agents/secureflows","links":{"self":"https://wellknown.network/agents/secureflows/record.json","html":"https://wellknown.network/agents/secureflows","markdown":"https://wellknown.network/agents/secureflows/record.md","api":"https://wellknown.network/api/v1/agents/secureflows","status":"https://wellknown.network/api/v1/agents/secureflows/status","claim":"https://wellknown.network/agents/secureflows/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/secureflows/claim.json","badge":"https://wellknown.network/agents/secureflows/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/secureflows/history","tools":"https://wellknown.network/api/v1/agents/secureflows/tools"},"ard":{"identifier":"urn:air:www.secure-flows.com:server:secureflows","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"secureflows-mcp","summary":"MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.","description":"MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.","publisher":{"name":"michal-lefler","url":null},"homepage":"https://www.secure-flows.com","repository":"https://github.com/michal-lefler/secureflows-mcp","version":"0.2.0","license":"MIT","protocols":["mcp"],"tags":["secureflows","secure-flows","mcp","model-context-protocol","ai-agent"],"pricing":null,"endpoints":[{"url":"https://www.secure-flows.com/mcp","type":"mcp_streamable_http","auth":null,"probeable":true},{"url":"npm:secureflows","type":"package_npm","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-08-25T10:03:33.629516Z","npmKeywords":["secureflows","secure-flows","mcp","model-context-protocol","ai-agent"],"publishedAt":"2026-08-25T10:03:33.629516Z","registryName":"io.github.michal-lefler/secureflows-mcp"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","license":"npm","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"security.identity","name":"Identity & Access","confidence":1,"provenance":"derived"},{"slug":"analytics.reporting","name":"Reporting & Dashboards","confidence":0.54,"provenance":"derived"},{"slug":"infra.browser-automation","name":"Browser Automation","confidence":0.51,"provenance":"derived"}],"categories":["analytics","infra","security"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 6h ago.","lastOkAt":"2026-10-09T23:29:18.728Z","lastProbedAt":"2026-10-09T23:29:18.728Z","statusComputedAt":"2026-10-09T23:31:08.745Z","reliability30d":{"probes":108,"successRate":1,"p50Ms":318,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":107,"ok":107,"authBoundaryOk":0,"serviceOk":107,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-09T23:29:18.728Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":245,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T16:33:50.135Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":390,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T10:22:54.030Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":408,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T04:27:28.163Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":559,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T21:22:43.330Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":573,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T14:22:38.033Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":367,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T07:25:40.800Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":266,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T00:26:19.908Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":218,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-07T17:30:51.786Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":271,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-07T10:48:14.541Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":637,"error":null,"detail":{"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"toolCount":18,"toolsHash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","serverName":"secureflows","capabilities":["logging","tools","prompts"],"serverVersion":"0.2.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"get_sessions","description":"Returns the decrypted session payload for the authenticated internal session token.\n\nResponse shape is a **flat JSON object**. Empty payload returns `{}`.\n\nSour"},{"name":"post_sessions","description":"Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized\n**`payload`** (defaults to `{}` when omitted), and returns **`sessi"},{"name":"get_sessions_identity","description":"Returns the workspace end-user's **`userId`** and **email** for the authenticated session\ntoken. Does not return Firebase UID or session payload.\n\n`userId` is a"},{"name":"post_sessions_get_or_create","description":"Verifies **Firebase** ID token. If an **active** session already exists for\n**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT fo"},{"name":"post_sessions_renew_session_token","description":"Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without\nenforcing JWT expiry** (signature and `tokenType=SES"},{"name":"post_sessions_set_key","description":"Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ \"value\": <x> }`, the server unwraps it and stores "},{"name":"get_sessions_get_key","description":"Retrieves the decrypted payload value for `key`.\n\n**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.\n\nSourc"},{"name":"delete_sessions_delete_key","description":"Removes `key` from the session payload and returns `true` if the key existed.\n\nSource: DELETE /api/v1/sessions/delete/{key}\nRequires `auth.sessionToken` and for"},{"name":"post_sessions_revoke","description":"Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restore"},{"name":"auth_session_callback","description":"**Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.\n\n1. Verifies **`firebaseToken`** (Firebase ID token).\n2. Ensur"},{"name":"get_auth_logout","description":"Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).\n\nUse this as a **top-level navigation** (not XHR/fetch) so `Clea"},{"name":"post_auth_logout","description":"Logs out the current session **without revoking** it.\n\n**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`\n"},{"name":"get_sessions_my","description":"Returns a page of sessions for the current user within the current workspace.\nSelf-service dashboard endpoint — requires workspace **`enableSelfService: true`**"},{"name":"post_sessions_revoke_session_id","description":"Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.\nThe session ends and its stored data is destroyed permanently; "},{"name":"get_docs_search","description":"Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks\nfrom the environment's search index (pgvector).\n\nSource: GET /api/v1"},{"name":"secureflows_build_login_url","description":"Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,\nbefore any user session exists, which is the phas"},{"name":"secureflows_build_logout_url","description":"Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:\na redirect_uri pointing at /callback (SPA c"},{"name":"secureflows_lint_integration","description":"Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at\nscaffolding time. Pass every auth/session-rel"}],"package":{"name":"secureflows","registry":"npm","observedAt":"2026-10-09T23:31:51.699Z","publishedAt":"2026-08-27T12:06:13.486Z","latestVersion":"0.2.0","weeklyDownloads":3},"toolSurface":{"id":"ts_fg74jceb36ap","endpointId":"ep_hswff5p5p7e2","hash":"171f7d8d649fd423492bb4f6528023c7992caf416ababe66a1d6ebb91d5acca1","toolCount":18,"serverName":"secureflows","serverVersion":"0.2.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-09-30T21:27:19.525Z","lastSeenAt":"2026-10-09T23:29:18.726Z","observations":34,"toolNames":["get_sessions","post_sessions","get_sessions_identity","post_sessions_get_or_create","post_sessions_renew_session_token","post_sessions_set_key","get_sessions_get_key","delete_sessions_delete_key","post_sessions_revoke","auth_session_callback","get_auth_logout","post_auth_logout","get_sessions_my","post_sessions_revoke_session_id","get_docs_search","secureflows_build_login_url","secureflows_build_logout_url","secureflows_lint_integration"],"distinctSurfaces":2},"endpointFacts":[{"id":"ep_hswff5p5p7e2","url":"https://www.secure-flows.com/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-09T04:27:28.164Z","auth":{"observedAt":"2026-10-09T04:27:28.336Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-09T04:27:28.347Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"www.secure-flows.com","issuer":{"commonName":"WE1","organization":"Google Trust Services"},"validFrom":"2026-08-11T20:54:45.000Z","validTo":"2026-11-09T21:54:42.000Z","daysToExpiry":30,"sanCount":1,"fingerprint256":"DA:12:58:38:ED:B5:3B:08:7A:EC:2B:C7:86:19:BD:8F:33:C1:23:8E:BD:7F:48:C6:4B:3B:C8:D0:B1:CB:8A:D1"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"npm","key":"secureflows","url":"https://www.npmjs.com/package/secureflows","firstSeenAt":"2026-09-06T12:18:24.114Z","fetchedAt":"2026-10-01T12:19:16.828Z","normalizedAt":"2026-10-01T12:19:16.828Z"},{"source":"mcp_registry","key":"io.github.michal-lefler/secureflows-mcp","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.michal-lefler%2Fsecureflows-mcp","firstSeenAt":"2026-09-06T20:21:46.965Z","fetchedAt":"2026-10-07T19:19:01.144Z","normalizedAt":"2026-10-07T19:19:01.144Z"}]},"firstSeenAt":"2026-09-06T12:18:24.114Z","updatedAt":"2026-10-09T23:31:51.699Z"}