Admin KayWat Observer (MCP)

Solopreneur & multi-business Streamable HTTP Model Context Protocol server for AI observation, operations telemetry & management

Transport: Online (24ms) MCP Mode: Active Auth Boundary: Verified (RS256) Protocol: v2024-11-05 Tools: 12 Read-Only Business: KayWat (Master Scope)

Connection & Metadata Endpoints

Streamable Model Context Protocol endpoints, RFC 8414 metadata discovery, and public RSA key sets.

MCP Service URL
https://admin.kaywat.me/mcp
Streamable HTTP protocol endpoint for AI observers (Claude, ChatGPT, Codex, Antigravity).
OAuth Protected Resource
OAuth 2.1 RFC 8414 metadata discovery for resource server capabilities.
OAuth Authorization Server
Authorization & token endpoint discovery for cryptographic scopes.
JWKS Public Key URI
Public RS256 key set for zero-trust cryptographic token verification.
RSA Public Key Structure (JWKS Verification)
JWKS Verified (RS256 3072-bit Public)
Key ID (kid): kaywat-admin-observer-rsa-v1
Key Type (kty): RSA
Algorithm (alg): RS256
Usage (use): sig
Modulus Size: 3072 bits
Private Fields: None (Public Only)

Observer Credentials & OAuth Tokens

Manage business-scoped RS256 Observer access tokens for AI assistants.

Credential / Scope Type / Algorithm Business Scoped Expires Status Actions
KayWat Admin Master Token
admin:read, overview:read, ads:read, blogs:read, crm:read, servers:read
RS256 (RSA-3072) kaywat-master 30 Days Active

Authorization Boundary Verification

Exercise live security gates (401 unauthenticated, 200 valid business, 403 cross-tenant).

1. Unauthenticated Request Pending

Missing Authorization bearer token header.

Expected: HTTP 401 Unauthorized
2. Current Business Scope Pending

Legitimate Observer token for active business.

Expected: HTTP 200 OK
3. Cross-Tenant Scope Pending

Valid token requesting outside target scope (e.g. 'unauthorized-external-org').

Expected: HTTP 403 Forbidden

Read-Only & Operations MCP Tool Explorer

Inspect and execute the 12 canonical Model Context Protocol tools dynamically.

Available Tools (12)

get_admin_health

Returns dashboard health, active business entities, router status & operational metrics.

Tool Response Output (Sanitized & Redacted):
Click "Execute Tool" to run the selected tool against the observer backend.

Recent Observer Audit Logs (kaywat_mcp_audit_logs)

Zero-trust audit trail of tool invocations, token verifications, and agent accesses.

Timestamp Tool Name Status Code Duration Client / Agent IP
1:1 Framework MCP Observer Studio