npm · @attested-intelligence/aga-mcp-server
$npx -y @attested-intelligence/aga-mcp-server@3.6.2 AGA_GATEWAY_KEY · secret — Ed25519 seed, 64 hex characters, that signs this server's evidence-bundle receipts and checkpoint, so gateway_public_key (get_server_info) is the same after a restart and can be pinned. Set in your MCP client's configuration, the seed sits inside the governed client's trust domain. Receipts are kept in memory only; save a generate_evidence_bundle result before the server stops. Unset or invalid: a new key each start, warned on stderr. When set, even to an invalid value, AGA_GATEWAY_KEY_FILE is not read.
AGA_GATEWAY_KEY_FILE — Path to a file holding the 64-hex Ed25519 seed; read only when AGA_GATEWAY_KEY is unset or empty, with the same effect. A stdio server started by your MCP client runs as the client's OS user, so the file sits inside the governed client's trust domain. Missing, unreadable or invalid: a new key each start, warned on stderr.