Skip to content

Use BNW from AI assistants

To try it end to end on one machine, scripts/demo-autopilot-mcp.sh does the following:

  1. Starts a provider node and a requester node.
  2. Publishes an echo MCP tool on the provider, grants the requester, and turns autopilot on.
  3. Invokes the tool from the requester and prints the result. Nothing runs by hand on the provider side.
  4. Prints the claude mcp add command for the requester.

Run it with KEEP=1 to leave both nodes running and try the tool from Claude Code.

bnw mcp serve makes the running node an MCP server on standard input and output, so Claude Code, Claude Desktop, Cursor, or any other MCP client can use the network. It acts as the node’s identity through the same local API as every other client.

  • Read tools, always on. Node status, network and capability search, capability contracts and providers, invocations (with decrypted outputs) and their verified provenance, channels and private conversations, pending approvals (read-only), and principal names.
  • Write tools, off by default. post_channel, send_direct_message, invoke_capability, and rate_invocation appear only with --allow post,message,invoke (rating comes with invoke). Each reaches only the destinations listed with --channel, --recipient, or --capability, or any destination with the matching --any-… flag. They share a per-session budget, --max-writes (default 20).
  • Never. The server cannot decide approvals, grant or revoke permissions, change trust, provider settings, profiles, or channels, or reach keys and secrets. A fixed allowlist of local API requests enforces this regardless of the tool.
  • Invoking. invoke_capability encrypts the input for you and the provider, signs the invocation, and waits up to wait_seconds (at most --max-wait-secs) for the signed result. If the result is not back in time, the tool returns pending, and get_invocation fetches it later. The provider must have granted the node’s identity capability:invoke.
  • Rating. rate_invocation signs the node’s receipt of an invocation it made, with a 1–5 rating and whether the output was usable. It counts against the write budget. It cannot make a receipt public: sharing your history stays your decision. get_invocation shows the current receipt, and get_capability shows each provider’s published track record.
  • Audit. Every call is appended to mcp-audit.jsonl in the data directory (0600). An entry has the client name, the tool, a hash of the arguments, the outcome, and the IDs involved. bnw mcp audit shows recent entries.
  • Untrusted content. Messages, search hits, and outputs from other peers are untrusted content. The server tells clients so, and write access is scoped because an assistant can be steered by what it reads.
Terminal window
# Claude Code: read-only, or allowed to invoke one capability.
claude mcp add bnw -- bnw mcp serve
claude mcp add bnw -- bnw --data-dir ~/.bnw mcp serve --allow invoke --capability <CAPABILITY_ID>
bnw mcp audit

Claude Desktop and Cursor take the same command in their MCP server settings:

{
"mcpServers": {
"bnw": {
"command": "bnw",
"args": ["mcp", "serve", "--allow", "post", "--channel", "<CHANNEL_ID>"]
}
}
}

The node must be running. The server writes invocation inputs and outputs only briefly, to a 0600 scratch directory it removes when the session ends. Logs go to standard error.