🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@usekaval/mcp

Package Overview
Dependencies
Maintainers
1
Versions
11
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@usekaval/mcp

MCP server for Kaval action verification: proof audit/gate plus compatibility currentness tools over the hosted API.

Source
npmnpm
Version
0.3.1
Version published
Weekly downloads
436
279.13%
Maintainers
1
Weekly downloads
 
Created
Source

@usekaval/mcp

The Kaval action-verification layer as an MCP server. It builds durable, action-bound proof packets and returns ALLOW, BLOCK, or REVIEW before an agent sends, quotes, approves, updates, grants, or transacts. Compatibility currentness tools remain available for a cached fact, stored field, retrieved RAG chunk, or prior answer.

This package is a thin client over the hosted Kaval API. All classification, grounding, and retrieval run server-side, so you bring just a Kaval API key — no model or search keys, no local engine.

Billable tool calls automatically carry a unique operation key. The underlying client reuses it for one bounded retry only when the transport outcome is ambiguous or the API is still finalizing the same operation, preventing duplicate billing without retrying terminal errors.

If both attempts remain ambiguous, the tool error includes idempotency_key. Retry later by passing that exact value back as the optional idempotency_key argument on the same billable tool. Omit it for a genuinely new operation.

Run it

npx -y @usekaval/mcp

It speaks MCP over stdio. Point any MCP client at it.

Client config

{
  "mcpServers": {
    "kaval": {
      "command": "npx",
      "args": ["-y", "@usekaval/mcp"],
      "env": {
        "KAVAL_API_KEY": "kv_live_…",
      },
    },
  },
}

Tools

ToolWhat it does
currentness_verifyPre-action gate: returns act (boolean) + a typed verdict + proof. Call before acting on a held belief.
currentness_checkThe raw freshness verdict without the act/don't-act decision.
currentness_extract_and_checkPull the checkable beliefs out of a paragraph and re-ground each.
currentness_scan_storeSweep a batch of beliefs for drift (summary + the riskiest).
currentness_monitorSweep + POST the newly-risky beliefs to a webhook (run on a schedule).
proof_auditBuild a complete action-bound ProofPacket with exact evidence, policy, lineage, risk, and expiry.
proof_gateApply a durable proof to the exact action and return staged enforcement without repeating research.
report_outcomeReport what actually happened for a prior check so the service can calibrate.

For consequential actions, call proof_audit, then proof_gate immediately before execution. Only when enforcement.controlApplied is true may Kaval control the action; then honor enforcement.executionAllowed exactly. In shadow mode controlApplied is false, executionAllowed is null, and wouldAllow is counterfactual telemetry—the customer's existing action path remains authoritative. If enforcement is absent, a direct integration should fail closed unless the proof state is current and the decision is ALLOW.

A verdict status is one of: current, stale, contradicted, unsupported, conflicting, insufficient. Treat anything other than current (or act === false) as "re-research before relying on it".

Environment

VarRequiredPurpose
KAVAL_API_KEYyesBearer key for the hosted Kaval API (create one at https://usekaval.com)
KAVAL_BASE_URLnoOverride the API base URL (self-hosted / staging). Defaults to https://api.usekaval.com

The marketing site uses KAVAL_API_URL for its /api/verify proxy — not KAVAL_BASE_URL.

Programmatic use

This package is primarily a CLI (kaval-mcp). It also exports the server factory for embedding:

import { createMcpServer, createClientFromEnv } from "@usekaval/mcp";

const server = createMcpServer(createClientFromEnv());
// connect `server` to your own MCP transport

Or pass your own configured client:

import { createMcpServer } from "@usekaval/mcp";
import { Kaval } from "@usekaval/kaval";

const server = createMcpServer(
  new Kaval({ apiKey: process.env.KAVAL_API_KEY }),
);

Keywords

kaval

FAQs

Package last updated on 11 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts