trove.

an artifact store for agents

Agents make things — reports, datasets, diagrams, screenshots — and then the session ends. trove is the durable catalog they keep them in: metadata and search over one MCP endpoint, bytes on short-lived signed URLs that never pass through the model.

Public
Accession record
id
trove
kind
service
endpoint
https://trove.humanmeetsai.com/mcp
transport
streamable HTTP · stateless
auth
Authorization: Bearer <token>
identity
kinnet · RFC 9421 signed requests · delegated grant chains
status
ready — healthz

Connect an agent

Claude Code
claude mcp add trove https://trove.humanmeetsai.com/mcp \ --transport http --header "Authorization: Bearer $TROVE_TOKEN"
Any MCP client
{ "mcpServers": { "trove": { "type": "http", "url": "https://trove.humanmeetsai.com/mcp", "headers": { "Authorization": "Bearer <token>" } } } }

Tokens are provisioned per deployment; without one the endpoint answers 401. Identity on trove is kinnet: every request is signed (RFC 9421), and delegated sessions carry attenuated grant chains instead of standing credentials. Callers with an enrolled kinnet identity use the local stdio server today — it signs each request and adds path-based upload and stream-to-disk delivery.

Get access

kinnet identity
Enroll a participant on kinnet — the identity network trove authenticates against — then request trove scopes. Verified callers are allowlisted explicitly, and scopes fail closed.
bearer token
Provisioned per deployment for development and embedded service use. Production keeps this door closed.
self-serve
An OAuth 2.1 front door, live on this deployment: add https://trove.humanmeetsai.com/mcp to an MCP client with no token, authenticate as your kinnet participant, and consent once in the browser — the session gets a scoped, revocable delegated grant, never a standing credential. Scopes still require an allowlist entry.
kinnet shimlive
One identity into trove and every other MCP server: kinnet mcp add https://trove.humanmeetsai.com/mcp installs a local credential shim that mints and refreshes a short-lived, audience-bound, DPoP-bound grant chain — no browser per server, no token in your config. Ships in the kinnet CLI (@kinnet/cli on npm). Detail: docs/ACCESS.md §G and docs/getting-started.html.

The tool surface

trove_search
Full-text query with label, kind, app, and owner filters. Compact metadata — never bytes.
trove_get
An asset's metadata plus a short-lived delivery URL, returned as a resource link.
trove_uploadstdio
Hash a local file, register it, stream to a presigned PUT, confirm the catalog row.
trove_upload_begin
Register an asset from its size and sha256 and get back a short-lived presigned PUT plus the exact curl line — you move the bytes from your own machine; nothing crosses the MCP channel.
trove_upload_confirm
After the PUT: verify the stored bytes against the declared size and sha256, flip the asset to ready.
trove_label
Merge labels and set titles. Setting a key to null deletes it; unmentioned keys stand.
trove_share
Grant a participant read, write, or share — or mint a one-time secret link.
trove_publish
Promote an asset to the public CDN tier; unpublish reverts it.
trove_history
One asset's append-only audit trail, newest first — who did what, when, and from which machine. Drop the asset id and it becomes your activity across everything you own, filterable to a single machine or grant. Readable by whoever may share the asset; reading it is not itself logged.

How bytes move

The MCP connection carries JSON only. Upload is a presigned PUT straight to object storage; delivery is a signed GET from the CDN edge. A leaked URL exposes one object for minutes — not an identity. Every asset sits on one of three tiers:

Public
CDN-cached, plain URLs. Deliberate, reversible, and an opt-in scope for delegated sessions.
Authenticated
The default. Short-TTL signed URLs minted per request, ownership and shares enforced.
Link
An unguessable one-time secret link — access without an account, revocable at any time.