
A constitutional AI framework that enforces 13 governance floors (F1-F13) across LLM operations through a tri-witness consensus model weighing human, AI, and environmental factors. Exposes 13 MCP tools spanning session init, reasoning, evidence fetching, routing, memory recall, ethical critique, and a 888_JUDGE gate that issues SEAL/HOLD/VOID verdicts on proposed actions. Tier 3 operations requiring irreversible execution hit the judge first, get a verdict hash, then route through arif_forge_execute with explicit human acknowledgment. The VAULT999 ledger anchors decisions immutably. Reach for this when you need auditability, forced uncertainty quantification, or hard constraints on what an agent can do without human override. Runs on port 8088, supports stdio and SSE transports.
Public tool metadata for what this MCP can expose to an agent.
add-templateAdd a new template with sections to an existing tenant via the seed-template endpoint6 paramsAdd a new template with sections to an existing tenant via the seed-template endpoint
accessTokenstringsectionsJsonstringserviceTypeDescriptionstringserviceTypeNamestringtemplateNamestringtenantIdstringauth-loginAuthenticate user via the login endpoint and get JWT access token2 paramsAuthenticate user via the login endpoint and get JWT access token
emailstringpasswordstringcreate-tenantCreate a new tenant via the bootstrap endpoint with tenant, service type, admin user, and document sections14 paramsCreate a new tenant via the bootstrap endpoint with tenant, service type, admin user, and document sections
accessTokenstringadminAddressstringadminEmailstringadminFirstNamestringadminLastNamestringadminPasswordstringadminPhonestringsectionsJsonstringserviceTypeDescriptionstringserviceTypeNamestringtemplateNamestringtenantLogoUrlstringtenantNamestringtenantUrlstringhttp-requestMake HTTP requests to external APIs4 paramsMake HTTP requests to external APIs
bodystringheadersobjectmethodstringGET · POST · PUT · DELETEurlstringThe constitutional kernel of the arifOS Federation.
arifOS is law, not an agent. It judges. It seals. It never executes.
DITEMPA BUKAN DIBERI — Forged, Not Given.
Every consequential action must answer:
arifOS answers the second — and only the second.
Execution belongs to A-FORGE. Routing belongs to AAA. Authority belongs to the sovereign.
The agent that acts is not allowed to certify its own action.
Four. No fifth.
Eight canonical verbs, live-witnessed 2026-08-25 via :8088/health:
arif_init · arif_observe · arif_think · arif_route · arif_memory · arif_judge · arif_forge · arif_seal
Door: /mcp. Public console is not exposed — the kernel serves /webmcp on :8088 locally only.
Request: "delete production database"
No session ACT, no evidence chain → HOLD
Evidence + floors pass → SEAL with conditions
→ execution by A-FORGE → receipt → VAULT999
VAULT999 (live 2026-08-25): healthy, append-only, outcomes.jsonl 67K+ records, 0 broken lines.
The judge never executes; the executor never certifies.
flowchart LR
Intent[Intent] --> Judge[arifOS]
Judge -->|SEAL| Forge[A-FORGE]
Forge --> Receipt[Receipt]
Receipt --> Vault[VAULT999]
Judge -->|HOLD| Human[Human Review]
ARIF = Sovereign · arifOS = Law · AAA = Institution · A-FORGE = Hands
ARIF vetoes. arifOS judges. AAA routes. A-FORGE executes.
Full card: docs/FEDERATION_CARD.md · Full reference README: docs/README-FULL.md · Constitution: GENESIS/000_KERNEL_CANON.md · ZEN doctrine: docs/ZEN.md