trove.
an artifact store for agents
Agents make things — reports, datasets, diagrams, screenshots — and then the session ends. trove is the durable catalog they keep them in: metadata and search over one MCP endpoint, bytes on short-lived signed URLs that never pass through the model.
Connect an agent
Tokens are provisioned per deployment; without one the endpoint answers 401. Identity on trove is kinnet: every request is signed (RFC 9421), and delegated sessions carry attenuated grant chains instead of standing credentials. Callers with an enrolled kinnet identity use the local stdio server today — it signs each request and adds path-based upload and stream-to-disk delivery.
Get access
- kinnet identity
- Enroll a participant on kinnet — the identity network trove authenticates against — then request trove scopes. Verified callers are allowlisted explicitly, and scopes fail closed.
- bearer token
- Provisioned per deployment for development and embedded service use. Production keeps this door closed.
- self-serve
- An OAuth 2.1 front door, live on this deployment: add
https://trove.humanmeetsai.com/mcpto an MCP client with no token, authenticate as your kinnet participant, and consent once in the browser — the session gets a scoped, revocable delegated grant, never a standing credential. Scopes still require an allowlist entry. - kinnet shimlive
- One identity into trove and every other MCP server:
kinnet mcp add https://trove.humanmeetsai.com/mcpinstalls a local credential shim that mints and refreshes a short-lived, audience-bound, DPoP-bound grant chain — no browser per server, no token in your config. Ships in the kinnet CLI (@kinnet/clion npm). Detail:docs/ACCESS.md§G anddocs/getting-started.html.
The tool surface
- trove_search
- Full-text query with label, kind, app, and owner filters. Compact metadata — never bytes.
- trove_get
- An asset's metadata plus a short-lived delivery URL, returned as a resource link.
- trove_uploadstdio
- Hash a local file, register it, stream to a presigned PUT, confirm the catalog row.
- trove_upload_begin
- Register an asset from its size and sha256 and get back a short-lived presigned PUT plus the exact
curlline — you move the bytes from your own machine; nothing crosses the MCP channel. - trove_upload_confirm
- After the PUT: verify the stored bytes against the declared size and sha256, flip the asset to ready.
- trove_label
- Merge labels and set titles. Setting a key to null deletes it; unmentioned keys stand.
- trove_share
- Grant a participant read, write, or share — or mint a one-time secret link.
- trove_publish
- Promote an asset to the public CDN tier; unpublish reverts it.
- trove_history
- One asset's append-only audit trail, newest first — who did what, when, and from which machine. Drop the asset id and it becomes your activity across everything you own, filterable to a single machine or grant. Readable by whoever may share the asset; reading it is not itself logged.
How bytes move
The MCP connection carries JSON only. Upload is a presigned PUT straight to object storage; delivery is a signed GET from the CDN edge. A leaked URL exposes one object for minutes — not an identity. Every asset sits on one of three tiers:
- Public
- CDN-cached, plain URLs. Deliberate, reversible, and an opt-in scope for delegated sessions.
- Authenticated
- The default. Short-TTL signed URLs minted per request, ownership and shares enforced.
- Link
- An unguessable one-time secret link — access without an account, revocable at any time.