{"app":"13flow","contract":["Public tools must not require browser auth, cookies or checkout.","Private tools must be absent from the default public MCP profile.","MCP responses must expose product status, validation boundary and data-quality warnings.","Tool output must not claim validated alpha, probabilities or expected returns.","Agent statistics must remain aggregate-only and must never retain IP addresses, User-Agents, client versions, arguments, prompts, responses or keys.","Private MCP tools call the isolated private API service rather than reading the private DB directly."],"generated_at":"2026-08-12T11:02:25+00:00","git_sha":"292bf187d3d5015ad897747f9e35ee4c9d0a3e62","operator_checks":["Run public smoke after deployment.","Verify MCP tools/list public contract.","Verify private and payment MCP tools are absent from tools/list.","If a separate private profile is enabled, test its dedicated X-13FLOW-Key path.","Record key id, scopes, limits and rotation date in the operator note."],"references":[{"name":"Product status","url":"/api/product-status"},{"name":"Agent statistics","url":"/api/agent-stats"},{"name":"Public OpenAPI","url":"/api/openapi.json"}],"scope":"Read-only Model Context Protocol access to public 13FLOW resources. Private and payment tools are absent from the default public Registry profile.","security":{"audit":"accepted, denied and rate-limited private API requests create audit rows","authorization_passthrough":false,"cache_policy":"Private API responses are private/no-store and vary by credential header","credential_headers":["X-13FLOW-Key: <token>"],"x402":"implemented but disabled until production payment details are configured"},"surfaces":[{"auth":"none for public read-only tools","name":"public MCP","tools":["get_live_status","get_product_status","get_research_readiness","list_funds","get_fund","get_stock","preview_watchlist","discover_watchlist","get_confluence_signals","get_signal_history","get_confluence_methodology","get_data_quality","get_agent_stats"],"url":"/api/mcp"},{"auth":"disabled by default; when isolated and enabled, X-13FLOW-Key only","name":"Optional private MCP profile","tools":["pro.list_funds","pro.get_fund","pro.get_data_quality"],"url":"/api/mcp"}],"title":"13FLOW MCP methodology"}
