AI Agent Integration (MCP)
AI Agent Integration (MCP)
Section titled “AI Agent Integration (MCP)”Any Aster service you deploy can be instantly available to AI agents. The aster mcp command runs an MCP (Model Context Protocol) server that exposes your services as tools – with full type information, dynamic discovery, and capability-based security.
No OpenAPI specs. No REST gateways. No SDK generation. The contract IS the tool definition.
Quick start
Section titled “Quick start”# Terminal 1: run your servicepython producer.py
# Terminal 2: expose it to AI agents via MCPaster mcp <endpoint-addr>That’s it. Claude (or any MCP-compatible agent) can now discover and call your service methods.
How it works
Section titled “How it works”Diagram source
graph TD
A["Claude / AI Agent"] -->|"stdio (JSON-RPC 2.0)"| B["aster mcp (MCP server)"]
B -->|"Aster RPC (QUIC)"| C["Your Service (P2P via Iroh)"]
aster mcpconnects to the producer and runs the admission handshake- It reads contract manifests from the registry to discover method schemas
- Each method becomes an MCP tool with a JSON Schema derived from the request type fields
- Tool calls are forwarded as Aster RPC calls; results returned as JSON
The MCP server does not merely list available methods – it uses dynamic type synthesis to actually invoke them. Contract manifests include Fory wire tags for every field, so the server can build correctly serialized typed requests directly from the agent’s JSON arguments. No local Python type definitions or generated stubs are needed.
The agent sees tools like:
HelloService.say_hello - name (string, required) - greeting (string, default: "Hello")
FileStore.get (unary)FileStore.list (server_stream, returns array)FileStore.upload (client_stream, accepts _items array)Security model
Section titled “Security model”MCP has no built-in security. Aster fills the gap with three layers.
Layer 1: Credential-based filtering (default)
Section titled “Layer 1: Credential-based filtering (default)”The MCP server is just another consumer. Give it a restricted credential:
# Mint a credential specifically for AI agent useaster trust sign --root-key root.key --type consumer \ --attributes '{"aster.role": "ai-reader"}' --out ai-agent.token
# MCP server uses the AI's credential, not yoursaster mcp <peer> --rcan ai-agent.tokenOn the producer, declare which methods the AI role can access:
@service(name="DataService")class DataService: @rpc(requires=ANY_OF("reader", "ai-reader")) # AI can read async def get_record(self, req): ...
@rpc(requires=ROLE("admin")) # AI cannot see this async def delete_record(self, req): ...Result: the agent sees DataService.get_record but never knows delete_record exists.
Layer 2: Allow/deny patterns
Section titled “Layer 2: Allow/deny patterns”Local glob patterns as a safety net, even if the credential allows more:
# Only expose read methodsaster mcp <peer> --allow "DataService.get_*" --deny "*.delete_*"
# Only specific servicesaster mcp <peer> --allow "HelloService.*" --allow "StatusService.*"Layer 3: Human-in-the-loop
Section titled “Layer 3: Human-in-the-loop”Require operator approval before executing sensitive calls:
# Confirm every callaster mcp <peer> --confirm "*"
# Or just specific patternsaster mcp <peer> --confirm "*.write_*" --confirm "*.admin_*"The MCP server pauses, prints the call details to stderr, and waits for you to approve.
Streaming methods
Section titled “Streaming methods”| Aster Pattern | MCP Behavior |
|---|---|
unary |
Direct request/response (1:1 mapping) |
server_stream |
Collects items into a JSON array. Control with _max_items (default 100) and _timeout (default 30s) |
client_stream |
Pass items via _items array parameter |
bidi_stream |
Not exposed as tools (Phase 1) |
Example: calling a server-streaming method:
{ "name": "Analytics.watchMetrics", "arguments": { "interval": 5, "_max_items": 10, "_timeout": 15 }}Returns a JSON array of up to 10 items collected over 15 seconds.
Configuration with Claude Code
Section titled “Configuration with Claude Code”Add to your .claude/settings.json:
{ "mcpServers": { "my-service": { "command": "aster", "args": ["mcp", "<endpoint-addr>"], "env": {} } }}With credentials:
{ "mcpServers": { "my-service": { "command": "aster", "args": ["mcp", "<endpoint-addr>", "--rcan", "ai-agent.token", "--deny", "*.delete_*"] } }}CLI reference
Section titled “CLI reference”aster mcp <address> [options]
Arguments: address Peer address (aster1... ticket)
Options: --rcan PATH Enrollment credential for the AI agent --allow PATTERN Glob for allowed tools (repeatable) --deny PATTERN Glob for denied tools (repeatable) --confirm PATTERN Glob for tools requiring human approval (repeatable)What’s next
Section titled “What’s next”- Phase 2:
AsterServer(mcp=True)– producer-side sidecar, zero network hop - Phase 3: Contract manifests as MCP resources, blobs as resources, bidirectional agent-to-agent workflows