# ai.duvera/gateway

> Governed AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.

- name: ai.duvera/gateway
- version: 1.0.0
- connection class: R0 (autonomous)
- trust: 76/100 flags: no-repository
- quality: 79/100 (good)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/ai.duvera%2Fgateway
- tools: https://api.protogrid.dev/v1/servers/ai.duvera%2Fgateway/tools

**An agent can connect right now, no human step.** Remote endpoint, no authentication, reachable on the last probe.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "gateway": {
      "type": "http",
      "url": "https://app.duvera.ai/mcp",
      "headers": {
        "Authorization": "Bearer ${duvera_agent_key}"
      }
    }
  }
}
```

Placeholders to fill: `${duvera_agent_key}`.

## Trust

- hygiene: 80
- liveness: 100
- freshness: 65
- provenance: 55
- drivers: +dns-namespace +website +reachable +uptime-100% ~updated-120d-ago -no-repository
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 79/100 (good)

### protocol: 75 (weight 25)

- warn `protocol.modern`: newest supported version is 2025-03-26; 2026-07-28 not supported, older versions are deprecated until 2027-07-28
- n/a `protocol.stateless`: only applies to 2026-07-28 servers
- pass `protocol.transport`: streamable HTTP
- n/a `protocol.list_ttl`: only applies to 2026-07-28 servers

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 71 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- fail `tools.annotations`: no tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones
- fail `tools.directory_hints`: no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: maps__eta_share (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); duvera__finance_exchange_rates (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); microsoft365__calendar_list (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …
- pass `tools.token_cost`: about 4,441 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 100 (weight 15)

- pass `stability.changes`: no tool changes in 30 days
- pass `stability.rug_pull`: no tool changed its meaning under the same name

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 52, about 4,441 tokens to load them all
- tool set hash: e799ead977ae4430319e0df8f93c7e7d
- badge: [![protogrid quality](https://protogrid.dev/badge/ai.duvera/gateway.svg)](https://protogrid.dev/servers/ai.duvera/gateway)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Remotes

- https://app.duvera.ai/mcp (streamable-http, auth none, reachable true, uptime30d 1)

## Packages

_none_

## Tools (52)

- `amazon__package_track`: [amazon · risk:low] Look up the delivery status of an Amazon order (read-only)
- `applehealth__heart_rate_read`: [applehealth · risk:medium] Read heart-rate data from Apple Health
- `applehealth__sleep_read`: [applehealth · risk:medium] Read sleep-analysis data from Apple Health
- `applehealth__steps_read`: [applehealth · risk:medium] Read step-count data from Apple Health
- `bluesky__trending_get`: [bluesky · risk:low] Fetch the current trending topics on Bluesky. Returns topic names, display labels, and links to the topic feed. No account or API key required.

- `chase__balance_check`: [chase · risk:low] Read the current balance of a Chase account (read-only)
- `datadog__logs_view`: [datadog · risk:low] Search and read logs from Datadog over a time range
- `delta__boardingpass_show`: [delta · risk:low] Pull up the boarding pass for a Delta flight
- `duvera__dev_npm_package`: [duvera · risk:low] Look up the latest version, description, license, and dependencies of an npm package. Works for scoped packages too (e.g. "@types/node"). No account required.
- `duvera__dev_pypi_package`: [duvera · risk:low] Look up the current version, summary, license, and homepage of a Python package on PyPI. No account required.
- `duvera__dev_stackoverflow_search`: [duvera · risk:low] Search Stack Overflow questions by keyword. Returns top 5 by relevance with title, link, score, and answer status. No account required.
- `duvera__finance_crypto_price`: [duvera · risk:low] Current spot price for one or more cryptocurrencies (CoinGecko ids like "bitcoin,ethereum,solana") in a fiat currency (default USD). Read-only market data. No account required.
- `duvera__finance_exchange_rates`: [duvera · risk:low] Live USD exchange rates against major currencies. Read-only, no account required.
- `duvera__food_recipe_search`: [duvera · risk:low] Search recipes by dish name (e.g. "arrabiata", "pad thai"). Returns ingredients, instructions, category, and cuisine. No account required.
- `duvera__food_restaurant_search`: [duvera · risk:low] Search for restaurants and food places by name or location using OpenStreetMap. Read-only, no account required.
- `duvera__geo_geocode`: [duvera · risk:low] Convert a city or place name (e.g. "Berlin", "San Francisco") to latitude/longitude, country, timezone, and population. Use this before weather.current or weather.air-quality when you only have a place name. No account required.
- `duvera__github_latest_release`: [duvera · risk:low] Get the latest published release (tag, name, notes, date) of a public GitHub repository. Returns 404 for repos that publish no releases. No auth required.
- `duvera__github_read_file`: [duvera · risk:low] Read a file from a public GitHub repository. Read-only.
- `duvera__github_search_repos`: [duvera · risk:low] Search public GitHub repositories by keyword. Returns top 5 results by stars. No auth required.
- `duvera__news_search`: [duvera · risk:low] Search Hacker News stories by keyword, ranked by relevance. Returns title, URL, points, author, and comment count. No account required.
- `duvera__news_top_stories`: [duvera · risk:low] Top stories from Hacker News. Read-only, no account required.
- `duvera__reference_dictionary`: [duvera · risk:low] Definitions, phonetics, part of speech, and examples for an English word. No account required.
- `duvera__reference_public_holidays`: [duvera · risk:low] Public holidays for a given year and ISO country code (e.g. 2026 + "US"). Includes national and regional holidays with dates and names. No account required.
- `duvera__time_now`: [duvera · risk:low] Current date and time in an IANA timezone (e.g. "America/New_York", "Asia/Tokyo"). Includes day of week and DST status. No account required.
- `duvera__travel_flight_search`: [duvera · risk:low] List aircraft currently airborne within a radius of a point (adsb.lol ADS-B data). Use geo.geocode to get a city's coordinates first. Returns callsign, altitude, speed, and position. No account required.
- `duvera__weather_air_quality`: [duvera · risk:low] Current air quality (US AQI, PM2.5, PM10, ozone) for a latitude/longitude. Use geo.geocode first if you only have a place name. No account required.
- `duvera__weather_current`: [duvera · risk:low] Current temperature, conditions, wind, and humidity for a latitude/longitude (Open-Meteo). Use geo.geocode first if you only have a city or place name. No account required.
- `duvera__wiki_search`: [duvera · risk:low] Search Wikipedia articles by keyword. Returns matching page titles, keys, and excerpts. Pass a result's key to wiki.summary for the article summary. No account required.
- `duvera__wiki_summary`: [duvera · risk:low] Get the lead summary of a Wikipedia article by title (e.g. "Zero_trust_architecture"). Use wiki.search first to find the exact page key. No account required.
- `gmail__mail_read`: [gmail · risk:low] Read recent emails from the Gmail inbox
- `googlecalendar__availability_find`: [googlecalendar · risk:low] Find open time slots within a date range in Google Calendar
- `google_workspace__mail_search`: [google-workspace · risk:low] Search Mail via Gmail, governed by Duvera.
- `grubhub__order_track`: [grubhub · risk:low] Check the live status and ETA of a Grubhub order
- `hackernews__stories_top`: [hackernews · risk:low] Fetch the current list of top-story ids on Hacker News. Returns an array of item ids (resolve details via the item endpoint). No account or API key required; the hacker-news.firebaseio.com endpoint is open and unmetered.

- `instacart__menu_search`: [instacart · risk:low] Search for grocery items and stores in the Instacart app
- `maps__eta_share`: [maps · risk:low] Share your estimated time of arrival with a contact from Apple Maps
- `microsoft365__calendar_list`: [microsoft365 · risk:low] List Calendar via Outlook Calendar, governed by Duvera.
- `microsoft365__mail_search`: [microsoft365 · risk:low] Search Mail via Outlook / Exchange, governed by Duvera.
- `notion__notes_search`: [notion · risk:low] Search pages and notes in Notion by query
- `obsidian__notes_search`: [obsidian · risk:low] Search notes in an Obsidian vault by query
- `open_meteo__weather_forecast`: [open-meteo · risk:low] Current temperature, conditions, humidity, and wind for a latitude/longitude, from Open-Meteo.
- `opensky__flights_live`: [opensky · risk:low] List aircraft currently airborne within a latitude/longitude box, from OpenSky's live ADS-B feed.
- `postgres__sql_read`: [postgres · risk:low] Execute a read-only SQL query against a Postgres database
- `shazam__audio_identify`: [shazam · risk:low] Identify the song currently playing using Shazam
- `slack__message_search`: [slack · risk:low] Search recent messages across Slack channels
- `southwest__flight_status`: [southwest · risk:low] Check the status of a Southwest flight
- `telegram__message_read`: [telegram · risk:low] Read recent messages from a Telegram chat
- `twitter__tweets_search`: [twitter · risk:low] Search for recent tweets matching a keyword, hashtag, or phrase using the Twitter v2 API. Pass your Twitter Bearer Token via X-Duvera-Service-Token header — Duvera never stores it. Get a free Bearer Token at developer.twitter.com.

- `uber__fare_estimate`: [uber · risk:low] Estimate the fare for a trip in the Uber app
- `united__flight_status`: [united · risk:low] Check the status of a United flight
- `venmo__payment_request`: [venmo · risk:low] Request a payment from a contact via Venmo (no money leaves your account)
- `wallet__boardingpass_show`: [wallet · risk:low] Pull up a boarding pass stored in Apple Wallet
