
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@tryrival/regulatory-toolkit
Advanced tools
SDK, CLI, MCP server, and schemas for Rival's source-grounded regulatory retrieval API.
Open-source SDK, CLI, MCP server, and schemas for connecting AI agents to Rival's source-grounded regulatory retrieval API.
https://api.tryrival.aiThis repository is the developer and agent connectivity layer for Rival. It is intentionally read-only in its first release: agents can search, retrieve source text, trace citations, list authorities, and inspect recent filings. Workspace actions, document review, evidence requests, filings, and task creation remain behind managed Rival access and human review gates.
npm install @tryrival/regulatory-toolkit
For local development from source:
npm install
npm run build
export RIVAL_API_KEY="rv_live_..."
export RIVAL_API_BASE_URL="https://api.tryrival.ai"
For local evaluation without API access:
export RIVAL_FIXTURE_MODE=true
import { RivalRegulatoryClient } from '@tryrival/regulatory-toolkit';
const rival = new RivalRegulatoryClient({
apiKey: process.env.RIVAL_API_KEY,
});
const results = await rival.searchRegulatoryCorpus({
query: '49 CFR 195.573',
limit: 5,
});
console.log(results.results[0]?.source.citation);
rival-regulatory search "49 CFR 195.573"
rival-regulatory source "cfr-49-195-573"
rival-regulatory trace "49 CFR 195.573"
rival-regulatory authorities
Fixture mode:
rival-regulatory search "pipeline corrosion" --fixture
Run from npm:
npx -y @tryrival/regulatory-toolkit mcp
Run from the public GitHub repo:
RIVAL_FIXTURE_MODE=true npx -y github:rival-intelligence/rival-regulatory-toolkit mcp
Fixture mode:
RIVAL_FIXTURE_MODE=true npx -y @tryrival/regulatory-toolkit mcp
Claude Desktop example:
{
"mcpServers": {
"rival-regulatory": {
"command": "npx",
"args": ["-y", "@tryrival/regulatory-toolkit", "mcp"],
"env": {
"RIVAL_API_KEY": "rv_live_...",
"RIVAL_API_BASE_URL": "https://api.tryrival.ai"
}
}
}
}
Available MCP tools:
search_regulatory_corpusretrieve_source_texttrace_citationlist_authoritiesget_recent_filingsDocker belongs in this repository because many compliance, legal, consulting, energy, and infrastructure teams will run agent tools inside controlled environments. The image runs the MCP server and reads credentials from environment variables.
docker build -t rival-regulatory-toolkit .
docker run --rm -i \
-e RIVAL_API_KEY="$RIVAL_API_KEY" \
-e RIVAL_API_BASE_URL="https://api.tryrival.ai" \
rival-regulatory-toolkit
Fixture mode:
docker run --rm -i -e RIVAL_FIXTURE_MODE=true rival-regulatory-toolkit
See docs/self-hosting.md for deployment notes.
The API contract starts with five read-only endpoints:
GET /api/v1/searchGET /api/v1/sources/{source_id}GET /api/v1/citations/traceGET /api/v1/authoritiesGET /api/v1/filings/recentThe contract lives in openapi/rival-regulatory-api.yaml.
This toolkit does not submit filings, alter compliance records, close corrective actions, delete evidence, or take workspace actions. It is a source retrieval and citation layer for agents and developer systems. Regulated work still requires qualified human review.
This toolkit is not legal, engineering, environmental, safety, or compliance advice. Teams are responsible for validating applicability, obligations, filings, and operational decisions with qualified professionals.
npm install
npm run build
npm test
Apache-2.0
FAQs
SDK, CLI, MCP server, and schemas for Rival's source-grounded regulatory retrieval API.
The npm package @tryrival/regulatory-toolkit receives a total of 13 weekly downloads. As such, @tryrival/regulatory-toolkit popularity was classified as not popular.
We found that @tryrival/regulatory-toolkit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.