# Nostr Bray MCP server

Agent View of the PolicyLayer registry record for Nostr Bray: identity, probed posture, risk grade, and all 240 tools classified. HTML page: https://policylayer.com/tools/dev-forgesworn-bray

## Facts

- Server id: `nostr-bray`
- Install: `npx -y nostr-bray`
- Homepage: https://github.com/forgesworn/bray
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 240
- Tool categories present: Destructive, Execute, Financial, Read, Write
- Tags: dev forgesworn bray, payments, admin, automation
- Record last modified: 2026-07-01T11:09:13.595Z

## Tools (240)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `blossom-delete` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/blossom-delete.md |
| `group-remove-user` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/group-remove-user.md |
| `label-remove` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/label-remove.md |
| `marketplace-credentials-clear` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-credentials-clear.md |
| `marketplace-retire` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-retire.md |
| `social-delete` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/social-delete.md |
| `tombstone` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/tombstone.md |
| `trust-revoke` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/trust-revoke.md |
| `vault-revoke` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/vault-revoke.md |
| `zap-wallet-clear` | Destructive | Critical | https://policylayer.com/tools/dev-forgesworn-bray/zap-wallet-clear.md |
| `cast-spell` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/cast-spell.md |
| `execute-action` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/execute-action.md |
| `identity-restore-shamir` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/identity-restore-shamir.md |
| `identity-switch` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/identity-switch.md |
| `marketplace-probe` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-probe.md |
| `nip44-encrypt` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/nip44-encrypt.md |
| `onboard-verified` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/onboard-verified.md |
| `relay-auth` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/relay-auth.md |
| `trust-attest-chain` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest-chain.md |
| `trust-ring-lsag-sign` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/trust-ring-lsag-sign.md |
| `trust-ring-prove` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/trust-ring-prove.md |
| `trust-spoken-verify` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/trust-spoken-verify.md |
| `vault-encrypt` | Execute | High | https://policylayer.com/tools/dev-forgesworn-bray/vault-encrypt.md |
| `marketplace-pay` | Financial | Critical | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-pay.md |
| `zap-make-invoice` | Financial | Critical | https://policylayer.com/tools/dev-forgesworn-bray/zap-make-invoice.md |
| `zap-send` | Financial | Critical | https://policylayer.com/tools/dev-forgesworn-bray/zap-send.md |
| `article-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/article-list.md |
| `article-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/article-read.md |
| `badge-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/badge-list.md |
| `blossom-check` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/blossom-check.md |
| `blossom-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/blossom-discover.md |
| `blossom-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/blossom-list.md |
| `blossom-usage` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/blossom-usage.md |
| `blossom-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/blossom-verify.md |
| `calendar-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/calendar-read.md |
| `canary-beacon-check` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-beacon-check.md |
| `canary-duress-detect` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-duress-detect.md |
| `canary-duress-signal` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-duress-signal.md |
| `canary-group-current` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-group-current.md |
| `canary-group-members` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-group-members.md |
| `canary-group-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-group-verify.md |
| `canary-session-current` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-session-current.md |
| `canary-session-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/canary-session-verify.md |
| `community-feed` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/community-feed.md |
| `community-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/community-list.md |
| `contacts-get` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/contacts-get.md |
| `contacts-search` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/contacts-search.md |
| `count` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/count.md |
| `decode` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/decode.md |
| `dispatch-capability-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-capability-discover.md |
| `dispatch-capability-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-capability-read.md |
| `dispatch-check` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-check.md |
| `dispatch-query` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-query.md |
| `dm-conversation` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dm-conversation.md |
| `dm-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/dm-read.md |
| `encode-naddr` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-naddr.md |
| `encode-nevent` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-nevent.md |
| `encode-note` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-note.md |
| `encode-nprofile` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-nprofile.md |
| `encode-npub` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-npub.md |
| `encode-nsec` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/encode-nsec.md |
| `feed-by-name` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/feed-by-name.md |
| `feed-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/feed-discover.md |
| `fetch` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/fetch.md |
| `filter` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/filter.md |
| `group-chat` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/group-chat.md |
| `group-info` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/group-info.md |
| `group-members` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/group-members.md |
| `handler-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/handler-discover.md |
| `hashtag-feed` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/hashtag-feed.md |
| `identity-accept-migration` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-accept-migration.md |
| `identity-backup` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-backup.md |
| `identity-backup-shamir` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-backup-shamir.md |
| `identity-derive` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-derive.md |
| `identity-derive-persona` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-derive-persona.md |
| `identity-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-list.md |
| `identity-recover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/identity-recover.md |
| `key-decrypt` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/key-decrypt.md |
| `key-encrypt` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/key-encrypt.md |
| `key-public` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/key-public.md |
| `label-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/label-read.md |
| `label-search` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/label-search.md |
| `list-bookmark` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-bookmark.md |
| `list-bookmark-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-bookmark-read.md |
| `list-check-muted` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-check-muted.md |
| `list-followset-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-followset-read.md |
| `list-mute-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-mute-read.md |
| `list-pin-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/list-pin-read.md |
| `listing-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/listing-read.md |
| `listing-search` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/listing-search.md |
| `marketplace-call` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-call.md |
| `marketplace-compare` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-compare.md |
| `marketplace-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-discover.md |
| `marketplace-inspect` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-inspect.md |
| `marketplace-reputation` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-reputation.md |
| `marketplace-search` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-search.md |
| `moderation-filter` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/moderation-filter.md |
| `nip-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip-list.md |
| `nip-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip-read.md |
| `nip-show` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip-show.md |
| `nip05-lookup` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip05-lookup.md |
| `nip05-relays` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip05-relays.md |
| `nip05-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip05-verify.md |
| `nip44-decrypt` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/nip44-decrypt.md |
| `post-queue-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/post-queue-list.md |
| `privacy-open` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-open.md |
| `privacy-prove-age` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-prove-age.md |
| `privacy-prove-range` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-prove-range.md |
| `privacy-prove-threshold` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-prove-threshold.md |
| `privacy-read-proof` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-read-proof.md |
| `privacy-verify-age` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-verify-age.md |
| `privacy-verify-range` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-verify-range.md |
| `privacy-verify-threshold` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/privacy-verify-threshold.md |
| `profile-by-name` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/profile-by-name.md |
| `relay-compare` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-compare.md |
| `relay-count` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-count.md |
| `relay-discover` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-discover.md |
| `relay-diversity` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-diversity.md |
| `relay-health` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-health.md |
| `relay-info` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-info.md |
| `relay-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-list.md |
| `relay-nip-search` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-nip-search.md |
| `relay-query` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-query.md |
| `relay-recommend` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/relay-recommend.md |
| `search-actions` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/search-actions.md |
| `search-notes` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/search-notes.md |
| `search-profiles` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/search-profiles.md |
| `signet-badge` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/signet-badge.md |
| `signet-credentials` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/signet-credentials.md |
| `signet-policy-check` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/signet-policy-check.md |
| `signet-verifiers` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/signet-verifiers.md |
| `social-feed` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/social-feed.md |
| `social-notifications` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/social-notifications.md |
| `social-profile-get` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/social-profile-get.md |
| `trust-attest` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest.md |
| `trust-attest-check-revoked` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest-check-revoked.md |
| `trust-attest-filter` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest-filter.md |
| `trust-attest-parse` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest-parse.md |
| `trust-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-read.md |
| `trust-request-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-request-list.md |
| `trust-ring-key-image` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-ring-key-image.md |
| `trust-ring-lsag-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-ring-lsag-verify.md |
| `trust-ring-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-ring-verify.md |
| `trust-score` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-score.md |
| `trust-spoken-challenge` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-spoken-challenge.md |
| `trust-spoken-directional` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-spoken-directional.md |
| `trust-spoken-encode` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-spoken-encode.md |
| `trust-verify` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/trust-verify.md |
| `vault-config` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-config.md |
| `vault-members` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-members.md |
| `vault-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-read.md |
| `vault-read-shared` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-read-shared.md |
| `vault-rotate` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-rotate.md |
| `vault-share` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/vault-share.md |
| `verify-event` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/verify-event.md |
| `verify-person` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/verify-person.md |
| `whoami` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/whoami.md |
| `wiki-list` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/wiki-list.md |
| `wiki-read` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/wiki-read.md |
| `zap-balance` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/zap-balance.md |
| `zap-decode` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/zap-decode.md |
| `zap-list-transactions` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/zap-list-transactions.md |
| `zap-lookup-invoice` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/zap-lookup-invoice.md |
| `zap-receipts` | Read | Low | https://policylayer.com/tools/dev-forgesworn-bray/zap-receipts.md |
| `article-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/article-publish.md |
| `badge-accept` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/badge-accept.md |
| `badge-award` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/badge-award.md |
| `badge-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/badge-create.md |
| `blossom-mirror` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/blossom-mirror.md |
| `blossom-repair` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/blossom-repair.md |
| `blossom-servers` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/blossom-servers.md |
| `blossom-upload` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/blossom-upload.md |
| `calendar-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/calendar-create.md |
| `calendar-rsvp` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/calendar-rsvp.md |
| `canary-beacon-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/canary-beacon-create.md |
| `canary-group-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/canary-group-create.md |
| `canary-group-join` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/canary-group-join.md |
| `canary-session-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/canary-session-create.md |
| `community-approve` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/community-approve.md |
| `community-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/community-create.md |
| `community-post` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/community-post.md |
| `contacts-follow` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/contacts-follow.md |
| `contacts-unfollow` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/contacts-unfollow.md |
| `dispatch-ack` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-ack.md |
| `dispatch-cancel` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-cancel.md |
| `dispatch-capability-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-capability-publish.md |
| `dispatch-failure` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-failure.md |
| `dispatch-propose` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-propose.md |
| `dispatch-refuse` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-refuse.md |
| `dispatch-reply` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-reply.md |
| `dispatch-send` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-send.md |
| `dispatch-status` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dispatch-status.md |
| `dm-by-name` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dm-by-name.md |
| `dm-send` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/dm-send.md |
| `group-add-user` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/group-add-user.md |
| `group-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/group-create.md |
| `group-send` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/group-send.md |
| `group-set-roles` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/group-set-roles.md |
| `group-update` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/group-update.md |
| `handler-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/handler-publish.md |
| `identity-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/identity-create.md |
| `identity-migrate` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/identity-migrate.md |
| `identity-prove` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/identity-prove.md |
| `identity-restore` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/identity-restore.md |
| `identity-setup` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/identity-setup.md |
| `label-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/label-create.md |
| `label-self` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/label-self.md |
| `list-followset-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/list-followset-create.md |
| `list-followset-manage` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/list-followset-manage.md |
| `list-mute` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/list-mute.md |
| `list-pin` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/list-pin.md |
| `listing-close` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/listing-close.md |
| `listing-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/listing-create.md |
| `marketplace-announce` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-announce.md |
| `marketplace-update` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/marketplace-update.md |
| `nip-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/nip-publish.md |
| `post-queue-cancel` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/post-queue-cancel.md |
| `post-schedule` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/post-schedule.md |
| `privacy-commit` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/privacy-commit.md |
| `privacy-publish-proof` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/privacy-publish-proof.md |
| `publish-event` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/publish-event.md |
| `relay-add` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/relay-add.md |
| `relay-set` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/relay-set.md |
| `safety-activate` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/safety-activate.md |
| `safety-configure` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/safety-configure.md |
| `signet-challenge` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/signet-challenge.md |
| `signet-policy-set` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/signet-policy-set.md |
| `signet-vouch` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/signet-vouch.md |
| `social-post` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/social-post.md |
| `social-profile-set` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/social-profile-set.md |
| `social-react` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/social-react.md |
| `social-reply` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/social-reply.md |
| `social-repost` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/social-repost.md |
| `trust-attest-temporal` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/trust-attest-temporal.md |
| `trust-claim` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/trust-claim.md |
| `trust-proof-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/trust-proof-publish.md |
| `trust-request` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/trust-request.md |
| `vault-create` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/vault-create.md |
| `wiki-publish` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/wiki-publish.md |
| `zap-wallet-set` | Write | Medium | https://policylayer.com/tools/dev-forgesworn-bray/zap-wallet-set.md |

## Tool descriptions

- `blossom-delete` — Delete a blob from a blossom media server by SHA-256 hash.
- `group-remove-user` — Remove a user from a NIP-29 group (kind 9001 admin event).
- `label-remove` — Delete a label event via kind 5 deletion. Only works for labels you authored.
- `marketplace-credentials-clear` — Clear all stored L402 credentials from memory. Use when switching identity or cleaning up.
- `marketplace-retire` — Retire (delete) a service announcement by publishing a kind 5 deletion event. The service will no longer appear in discovery results.
- `social-delete` — Request deletion of an event you published (kind 5). Relays may or may not honour the request.
- `tombstone` — Overwrite an addressable event (kind 30000-39999) with empty content, effectively deleting it from relays. Use this to clean up broken or stale replaceable events.
- `trust-revoke` — Revoke a previously issued attestation. Active identity must match the original attestor.
- `vault-revoke` — Revoke a pubkey from the vault config. Fetches the current config, adds the pubkey to the revoked list, signs, and republishes the updated config event. Returns the updated event and revoked npub.
- `zap-wallet-clear` — Remove the NWC wallet for the active identity. Falls back to the global NWC_URI if set.
- `cast-spell` — Execute a NIP-A7 Spell (kind 777). Fetches the Spell event, resolves runtime variables ($me → your pubkey, $contacts → your follow list) and relative timestamps (e.g.
- `execute-action` — Execute an action found via search-actions. Pass the exact action name and its parameters.
- `identity-restore-shamir` — Reconstruct a secret from Shamir shard files. Returns the restored npub for verification.
- `identity-switch` — Switch the active Nostr identity. ALL subsequent tool calls will sign events and query relays as the new identity. Pass
- `marketplace-probe` — Send an HTTP request to an endpoint and inspect the response.
- `nip44-encrypt` — Encrypt a plaintext string using NIP-44 for a recipient pubkey. Uses the active identity\
- `onboard-verified` — Guided workflow to build a verified trust profile. Shows your current Signet tier, what steps remain (self-declaration, vouches, professional verification, vault setup), and lists contacts who could vouch for you.
- `relay-auth` — Authenticate to a relay that requires NIP-42 AUTH. Connects to the relay, waits for an AUTH challenge, signs a kind 22242 event, and sends it back. Returns { authenticated: true/false }. Use this when a relay-query fails due to AUTH requ…
- `trust-attest-chain` — Follow endorsement references to build a transitive trust chain. Starting from a subject, queries attestations about that subject, then follows each attestor as a new subject up to maxDepth. Returns the full chain with validity status fo…
- `trust-ring-lsag-sign` — Create an LSAG (Linkable SAG) signature with a key image tied to an election ID. If the same signer signs twice in the same election, the duplicate key image reveals double-action without revealing identity. Use for anonymous voting, one…
- `trust-ring-prove` — Create a ring signature proving anonymous group membership. A verifier can confirm
- `trust-spoken-verify` — Verify a spoken token response against the shared secret.
- `vault-encrypt` — Encrypt content using a content key derived from the active identity for a given tier and epoch. No network access — purely local cryptography. Returns the ciphertext, tier, and epoch used.
- `marketplace-pay` — Pay an L402 invoice via NWC and store credentials for authenticated API calls.
- `zap-make-invoice` — Generate a Lightning invoice via NWC to receive payments.
- `zap-send` — Pay a Lightning invoice via Nostr Wallet Connect (NWC). SPENDS REAL SATS. Decodes the invoice and shows amount first — set confirm: true to execute payment.
- `article-list` — List long-form article metadata (NIP-23, kind 30023) by author — titles, slugs, summaries, and dates without full content. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `article-read` — Read long-form article(s) (NIP-23, kind 30023) by author. Optionally fetch a specific article by slug. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `badge-list` — List badges defined by an author or displayed on a profile (NIP-58). Mode
- `blossom-check` — Verify a blob exists and is intact on a blossom server. HEAD request to check existence, optionally downloads and verifies SHA-256 hash matches.
- `blossom-discover` — Discover blossom servers used by contacts. Fetches kind 10063 (NIP-B7 server list) events from the given pubkeys and aggregates unique server URLs. Use contacts-get first to get pubkeys.
- `blossom-list` — List blobs uploaded by a pubkey on a blossom server.
- `blossom-usage` — Check storage usage across blossom servers for a pubkey. Returns per-server blob count and total size, plus aggregate totals.
- `blossom-verify` — Verify all media URLs in a note are still accessible. Pass the note content and get back alive/broken status per URL. Optionally verifies SHA-256 hash integrity for blossom URLs.
- `calendar-read` — Fetch calendar events (NIP-52, kinds 31922 + 31923) by author and/or date range. Accepts any identifier for author: name, NIP-05, npub, or hex pubkey.
- `canary-beacon-check` — Check a CANARY beacon\
- `canary-duress-detect` — Check if a spoken verification word is a duress signal.
- `canary-duress-signal` — Generate a duress signal for a CANARY group. Returns the duress word (indistinguishable
- `canary-group-current` — Get the current verification word for a CANARY group.
- `canary-group-members` — List members and admins of a CANARY group.
- `canary-group-verify` — Verify a spoken word against a CANARY group.
- `canary-session-current` — Get the current verification words for an active CANARY session.
- `canary-session-verify` — Verify a spoken word against an active CANARY session.
- `community-feed` — Read approved posts in a community (NIP-72). Fetches kind 4550 approved posts and unwraps the original content.
- `community-list` — Discover communities on Nostr (NIP-72). Fetches kind 34550 community definitions.
- `contacts-get` — Fetch the contact list (kind 3 follows) for a Nostr identity. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `contacts-search` — Search your contacts by name, display name, or NIP-05. Resolves profiles in one batch — much faster than fetching each individually. Use this to find a contact when you know their name but not their pubkey.
- `count` — Count events matching a filter on the active identity\
- `decode` — Decode a nip19 entity (npub, nsec, note, nevent, nprofile, naddr) or nostr: URI to its components.
- `dispatch-capability-discover` — Discover dispatch-capable agents on Nostr. Searches for NIP-89 capability cards (kind 31990) tagged with the dispatch protocol. Optionally filter by task type. Returns agent names, descriptions, supported task types, repos, and availabil…
- `dispatch-capability-read` — Read a specific agent\
- `dispatch-check` — Check for incoming collaboration tasks from trusted Nostr identities. Returns dispatch messages: think tasks, build tasks, results, acks, status updates. Only shows messages from identities in the dispatch trust list, validated for fresh…
- `dispatch-query` — Ask the task sender a clarifying question before delivering results. Use mid-task when you need more information to proceed. The sender receives the question via dispatch-check and can reply.
- `dm-conversation` — Read DM conversation with a specific person. Accepts any identifier: name, NIP-05, npub, or hex pubkey. Shows messages in chronological order.
- `dm-read` — Read direct messages addressed to the active identity. Decrypts both NIP-17 (gift wrap) and NIP-04 (legacy). Each message includes { from, content, protocol, decrypted }. Gracefully handles decryption failures without crashing.
- `encode-naddr` — Encode an addressable event reference as a bech32 naddr.
- `encode-nevent` — Encode an event ID with relay hints and optional author as a bech32 nevent.
- `encode-note` — Encode a hex event ID as a bech32 note.
- `encode-nprofile` — Encode a hex pubkey with relay hints as a bech32 nprofile.
- `encode-npub` — Encode a hex public key as a bech32 npub.
- `encode-nsec` — Encode a hex private key as a bech32 nsec. WARNING: private key material flows through the MCP transport.
- `feed-by-name` — Fetch recent posts by a contact, searching by name instead of pubkey. Returns an error if zero or multiple contacts match.
- `feed-discover` — Discover new accounts worth following, ranked by trust score. Strategies: trust-adjacent (contacts-of-contacts), topic (hashtag search), active (recent posters in your network).
- `fetch` — Fetch events by nip19 code (note, nevent, nprofile, npub, naddr). Resolves the entity and queries relays.
- `filter` — Test if a Nostr event matches a given filter. Returns true or false.
- `group-chat` — Fetch recent chat messages from a NIP-29 group.
- `group-info` — Fetch group metadata (name, about, picture) for a NIP-29 group.
- `group-members` — List members of a NIP-29 group.
- `handler-discover` — Discover MCP-capable handlers on Nostr. Searches for kind 31990 events that include mcp transport tags. Optionally filter by supported event kind. Returns handler names, descriptions, supported kinds, and transport endpoints.
- `hashtag-feed` — Fetch notes (kind 1) with a specific hashtag. Uses standard tag filtering — works on all relays, no NIP-50 required.
- `identity-accept-migration` — Accept a migration from an external signer (Amber, nsec.app, etc). Signs and publishes the acceptance event via the current signer. Optionally verifies the migration event from the old key. Requires a Heartwood-compatible signer or local…
- `identity-backup` — Fetch profile, contacts, relay list, and attestations for a pubkey. Returns a portable JSON bundle (no private keys).
- `identity-backup-shamir` — Split the active identity\
- `identity-derive` — Derive a child Nostr identity from the master key by purpose and index. Deterministic — same inputs always produce the same npub. Returns { npub, purpose, index }. Use identity_switch after deriving to operate as the new identity.
- `identity-derive-persona` — Derive a named persona (e.g.
- `identity-list` — List all known identities (master + all derived). Returns array of { npub, purpose, index, personaName }. Never includes private keys. Use this to see what identities are available before switching.
- `identity-recover` — Recover a master identity from Shamir word-list shard files. Reconstructs the secret, derives the master npub, and optionally configures new relays. This operation is destructive — use only when the original identity is inaccessible.
- `key-decrypt` — Decrypt an ncryptsec (NIP-49) with a password. Returns the derived pubkey for verification — never the raw key.
- `key-encrypt` — Encrypt a secret key with a password (NIP-49 ncryptsec). Returns the ncryptsec string and the derived pubkey. WARNING: secret key is transmitted through the MCP transport.
- `key-public` — Derive a public key (hex + npub) from a secret key (nsec or hex). WARNING: the secret key is transmitted through the MCP transport — use only for local/trusted setups.
- `label-read` — Query NIP-32 labels for a target event, pubkey, or address.
- `label-search` — Find all events/pubkeys that have been given a specific label in a namespace.
- `list-bookmark` — Manage bookmarks (NIP-51). Without a name, manages general bookmarks (kind 10003).
- `list-bookmark-read` — Read bookmarks. Without a name, reads general bookmarks (kind 10003).
- `list-check-muted` — Check if a pubkey, event ID, keyword, or hashtag is on your mute list.
- `list-followset-read` — Read a named follow set by name (NIP-51, kind 30000).
- `list-mute-read` — Read your current mute list (NIP-51, kind 10000). Returns all muted pubkeys, events, keywords, and hashtags.
- `list-pin-read` — Read your pinned events list (NIP-51, kind 10001).
- `listing-read` — Read classified listing(s) (NIP-99, kind 30402) by author and optional slug.
- `listing-search` — Search classified listings (NIP-99, kind 30402) by hashtag or geohash location.
- `marketplace-call` — Make an authenticated API call using L402 credentials obtained from marketplace-pay.
- `marketplace-compare` — Compare two or more L402 services side by side — pricing, capabilities, and shared features.
- `marketplace-discover` — Discover L402/x402 paid API services announced on Nostr (kind 31402).
- `marketplace-inspect` — Get full details of a specific L402 service by event ID, or by provider pubkey + identifier.
- `marketplace-reputation` — Check a service provider\
- `marketplace-search` — Full-text search across L402 service names, descriptions, topics, and capabilities.
- `moderation-filter` — Filter a set of events against the active identity\
- `nip-list` — List all official Nostr NIPs from the protocol repository.
- `nip-read` — Fetch community NIPs (kind 30817) from relays. Filter by author, identifier, or defined kind.
- `nip-show` — Fetch and display the full content of an official NIP by number.
- `nip05-lookup` — Resolve a NIP-05 identifier (user@domain) to a Nostr pubkey. Also returns relay hints if the server provides them. Use this to find someone\
- `nip05-relays` — Fetch relay hints from a NIP-05 identifier. The NIP-05 server can suggest preferred relays for each pubkey. Returns a map of pubkey to relay URLs. Useful for relay discovery before messaging someone.
- `nip05-verify` — Verify that a NIP-05 identifier (user@domain) resolves to the expected pubkey. Returns { verified: true/false }. Use this to confirm someone\
- `nip44-decrypt` — Decrypt a NIP-44 ciphertext using the active identity\
- `post-queue-list` — List all scheduled posts waiting to be published.
- `privacy-open` — Verify a Pedersen commitment opening. Given the original value and blinding factor, check they match the public commitment. Returns true if the commitment is valid.
- `privacy-prove-age` — Prove age is within a range without revealing the exact age. Supports formats like
- `privacy-prove-range` — Prove a secret value is within [min, max] without revealing the value. Returns a cryptographic range proof that anyone can verify against the commitment. Optional binding context prevents proof transplanting between credentials.
- `privacy-prove-threshold` — Prove a value exceeds a threshold without revealing the exact value. Useful for income verification, balance checks, credit scoring. The proof shows value >= threshold.
- `privacy-read-proof` — Fetch and verify range proof events from relays. Returns a list of proofs with their verification status, labels, ranges, and subject pubkeys.
- `privacy-verify-age` — Verify an age range proof. Checks that the subject is within the expected age range without learning their exact age.
- `privacy-verify-range` — Verify a range proof. Checks that the committed value is within [min, max] without learning the value. Supply the same binding context used during proof creation.
- `privacy-verify-threshold` — Verify a threshold proof. Checks that the committed value is >= threshold without learning the value.
- `profile-by-name` — Look up a contact\
- `relay-compare` — Compare 2 or more relays side-by-side. For each relay: NIP-11 metadata, response time,
- `relay-count` — Count events matching a filter without fetching them (NIP-45). Sends a COUNT request to each relay. Falls back to fetch-and-count (capped at 1000) if the relay does not support NIP-45. Results show per-relay counts with fallback/estimate…
- `relay-discover` — Discover relays used by your contacts. Fetches kind 10002 (NIP-65) relay lists from your follow list,
- `relay-diversity` — Analyse your relay set for centralisation risk. Checks unique operators, software diversity,
- `relay-health` — Check health of the active identity\
- `relay-info` — Fetch the NIP-11 relay information document for a relay URL.
- `relay-list` — List the relay set (read/write) for the active identity. Optionally check for shared relays with another identity.
- `relay-nip-search` — Find relays that support specific NIPs. Queries NIP-11 info documents and filters to relays
- `relay-query` — Query events from Nostr relays by kind, author, ids, tags, or time range. Useful for discovering events, scanning for specific kinds, or investigating unknown event schemas. Uses explicit relays if provided, otherwise the active identity\
- `relay-recommend` — Recommend relays for your use case. Uses contact relay discovery, NIP-11 metadata, and health checks
- `search-actions` — Search ${catalog.size} additional actions by describing what you want to do.
- `search-notes` — Full-text search for notes (kind 1) using NIP-50. Requires relay support for NIP-50 — if results are empty, try relay-info to check NIP support. Optionally specify relays known to support NIP-50.
- `search-profiles` — Search for Nostr profiles (kind 0) by keyword using NIP-50. Requires relay support for NIP-50 — if results are empty, try relay-info to check NIP support.
- `signet-badge` — Get a quick trust summary for a pubkey — returns their Signet tier, trust score, composite level, and flags. Use this as a
- `signet-credentials` — List all kind 31000 Signet credentials held by a pubkey — includes tier, type, method, profession, jurisdiction, age range, and expiry. Use this to inspect a user\
- `signet-policy-check` — Check whether a pubkey satisfies a community\
- `signet-verifiers` — Search for Signet-registered professional verifiers. Filter by jurisdiction (e.g.
- `social-feed` — Fetch the kind 1 text note feed. Optionally filter by authors.
- `social-notifications` — Fetch notifications for the active identity — mentions, replies, reactions, and zap receipts.
- `social-profile-get` — Fetch the kind 0 profile for a Nostr identity. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `trust-attest` — Verify someone else\
- `trust-attest-check-revoked` — Check if a specific attestation has been revoked. Queries relays for the latest version of the attestation and checks its revocation status. Provide either (type + identifier) for typed attestations or (assertionId | assertionAddress) fo…
- `trust-attest-filter` — Build a Nostr relay filter for attestation queries. Returns a filter object suitable for relay subscriptions. Supports filtering by type, subject, attestor, schema, and time range.
- `trust-attest-parse` — Parse a kind 31000 attestation event into a fully typed object with all metadata fields: type, subject, assertion references, temporal fields (occurredAt, validFrom, validTo), expiration, schema, revocation status, and content.
- `trust-read` — Read kind 31000 attestations from relays. Filter by subject, type, or attestor. Works with both assertion-first (trust-attest) and direct claims (trust-claim).
- `trust-request-list` — Scan received NIP-17 DMs for attestation request payloads.
- `trust-ring-key-image` — Compute the key image for the active identity in a specific election context. Use this to pre-check whether the active identity has already signed in an election without creating a full signature. The key image is deterministic: same key…
- `trust-ring-lsag-verify` — Verify an LSAG signature and check the key image against a list of known images to detect double-signing. Returns validity, key image, and duplicate status.
- `trust-ring-verify` — Verify a ring signature proof.
- `trust-score` — Compute a trust score for a Nostr identity using the web-of-trust graph and kind 31000 attestations. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `trust-spoken-challenge` — Generate a spoken verification token for in-person identity confirmation.
- `trust-spoken-directional` — Generate a directional token pair where each role gets a different token. Prevents the
- `trust-spoken-encode` — Generate a spoken token in an alternative encoding: PIN digits for phone keypads, hex for technical contexts, or multi-word for higher entropy. Same HMAC derivation as trust-spoken-challenge but with configurable output format.
- `trust-verify` — Validate the structural correctness of a kind 31000 attestation event.
- `vault-config` — Fetch a vault config and return a summary of tier names, member counts, revoked count, grant count, and current epoch. Optionally inspect another author\
- `vault-members` — Fetch a vault config and list all members annotated with trust levels. Optionally query another author\
- `vault-read` — Decrypt ciphertext using the content key derived from the active identity for a given tier and epoch. No network access — purely local cryptography. Returns the plaintext, tier, and epoch.
- `vault-read-shared` — Decrypt ciphertext using a vault key that was shared with you by another identity. Fetches the encrypted share event from relays, decrypts the content key via NIP-44, then decrypts the ciphertext. Use this when you are a recipient of vau…
- `vault-rotate` — Show the current epoch ID and explain how epoch-based key rotation works. Purely informational — to rotate access, revoke recipients and re-share keys for the next epoch.
- `vault-share` — Derive the content key for a tier and epoch, then distribute encrypted vault shares to recipients via gift-wrapped events. Returns counts of published and failed shares.
- `verify-event` — Verify a Nostr event\
- `verify-person` — Verify a Nostr identity: checks NIP-05, trust score, kind 31000 attestations, linkage proofs, and (in full mode) ring endorsements and a spoken challenge token. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `whoami` — Returns the active identity\
- `wiki-list` — List wiki topics (NIP-54, kind 30818). Returns unique topics with latest title, summary, and author. Optionally filter by author. Accepts any identifier: name, NIP-05, npub, or hex pubkey.
- `wiki-read` — Read wiki article(s) by topic (NIP-54, kind 30818). Without an author, returns versions from multiple authors sorted by recency — readers pick the version from the author they trust most. Accepts any identifier for author: name, NIP-05, …
- `zap-balance` — Request wallet balance via NWC. Sends a get_balance request to the wallet service.
- `zap-decode` — Decode basic fields from a bolt11 Lightning invoice string.
- `zap-list-transactions` — List recent Lightning transactions via NWC.
- `zap-lookup-invoice` — Look up a Lightning invoice status via NWC.
- `zap-receipts` — Fetch zap receipts (kind 9735) for the active identity. Returns sender, amount in msats, and message.
- `article-publish` — Publish a long-form article (NIP-23, kind 30023). Creates a replaceable event with title, markdown content, and optional metadata. The slug (d-tag) defaults to a slugified version of the title.
- `badge-accept` — Accept a badge and add it to your profile badges (NIP-58, kind 30008). Updates your profile badge list preserving existing badges.
- `badge-award` — Award a badge to one or more recipients (NIP-58, kind 8). The badge must be defined first via badge-create.
- `badge-create` — Define a new badge (NIP-58, kind 30009). Creates a replaceable badge definition with name, description, and optional image.
- `blossom-mirror` — Upload a file to multiple blossom servers for redundancy. Provide a source URL (existing blob), file path, or data. Uploads to each server in parallel and returns per-server results with verified SHA-256 hash.
- `blossom-repair` — Find a broken blob on other blossom servers by SHA-256 hash and optionally re-upload to a target server. Searches each server, verifies hash integrity, and re-uploads if found.
- `blossom-servers` — Read or update your preferred blossom server list (kind 10063). Without servers parameter, reads the current list. With servers parameter, publishes a new list.
- `blossom-upload` — Upload a file to a blossom media server. Returns the blob URL and SHA-256 hash.
- `calendar-create` — Create a calendar event (NIP-52). Auto-detects date-based (kind 31922, YYYY-MM-DD) vs time-based (kind 31923, ISO datetime). Returns the signed event and publish result.
- `calendar-rsvp` — RSVP to a calendar event (NIP-52, kind 31925). Pass the event coordinate (kind:pubkey:d-tag format) and your status.
- `canary-beacon-create` — Create an encrypted liveness beacon for a CANARY group.
- `canary-group-create` — Create an encrypted CANARY verification group. All members share a secret seed
- `canary-group-join` — Join an existing CANARY group using a shared seed (received via NIP-17 DM).
- `canary-session-create` — Create a CANARY verification session for two-party spoken verification.
- `community-approve` — Approve a post in a community you moderate (NIP-72, kind 4550). Wraps the original event for inclusion in the community feed.
- `community-create` — Create a moderated community (NIP-72, kind 34550). Communities are open and approval-based, different from NIP-29 closed groups.
- `community-post` — Post to a community (NIP-72). Creates a kind 1 note with an a-tag pointing to the community. A moderator must approve it before it appears in the feed.
- `contacts-follow` — Follow a Nostr pubkey. Fetches current contact list, adds the pubkey, publishes updated kind 3. If the list would shrink by >20%, returns a guarded warning — pass confirm: true to proceed.
- `contacts-unfollow` — Unfollow a Nostr pubkey. Fetches current contact list, removes the pubkey, publishes updated kind 3. If the list would shrink by >20%, returns a guarded warning — pass confirm: true to proceed.
- `dispatch-ack` — Acknowledge receipt of a dispatch task. Tells the sender
- `dispatch-cancel` — Cancel a dispatch task you previously sent or received. Notifies the other party that the task should be abandoned.
- `dispatch-capability-publish` — Publish your agent\
- `dispatch-failure` — Report that a dispatch task failed after you attempted it. Use when you tried to complete the task but encountered errors. Optionally include partial results so work is not lost.
- `dispatch-propose` — Propose an alternative approach for a dispatch task. Use when you can\
- `dispatch-refuse` — Refuse a dispatch task you cannot or should not complete. Tells the sender
- `dispatch-reply` — Send a result back for a completed dispatch task. Use after finishing a think or build task received via dispatch-check. Only replies to trusted identities. Do not use this for human conversations — only for responding to tasks from othe…
- `dispatch-send` — Send a collaboration task to a trusted Nostr identity. Think tasks request read-only code analysis. Build tasks request implementation with code changes. The recipient\
- `dispatch-status` — Send a status update to collaborators. Use to broadcast availability (e.g.
- `dm-by-name` — Send an encrypted DM to a contact by name — no pubkey needed. Searches your contacts, finds the match, and sends the message. Returns an error if zero or multiple matches are found (use contacts-search to disambiguate).
- `dm-send` — Send an encrypted direct message. Accepts any identifier: name, NIP-05, npub, or hex pubkey. Default: NIP-17 gift wrap (most private). Set nip04: true for legacy NIP-04 (only if NIP04_ENABLED=1). Use dm-by-name to search your contacts if…
- `group-add-user` — Add or update a user\
- `group-create` — Create a NIP-29 group (kind 9004 admin event). The relay assigns membership state from the event. Optionally supply a group ID; the relay may derive its own from the event ID.
- `group-send` — Send a message to a NIP-29 group.
- `group-set-roles` — Define role names and their permissions in a NIP-29 group (kind 9007 admin event). Each role entry is { name, permissions? }.
- `group-update` — Update NIP-29 group metadata (kind 9002 admin event). Supply only the fields you want to change.
- `handler-publish` — Publish a NIP-XX Machine Application Handler card (kind 31990) advertising MCP transport endpoints. Lets other agents and tools discover MCP servers on Nostr by the event kinds they support. Provide at least one of stdio_command or http_…
- `identity-create` — Generate a fresh Nostr identity with a BIP-39 mnemonic seed. Returns { npub, mnemonic }. Store the mnemonic securely — it will not be shown again. Use this when the user needs a brand new identity unrelated to the current one.
- `identity-migrate` — Migrate from an old identity to the active one. Shows preview first — set confirm: true to execute. Publishes linkage proof and re-signs migratable events.
- `identity-prove` — Create a cryptographic linkage proof between the master key and the active identity.
- `identity-restore` — Re-sign migratable events (profile, contacts, relay list) under the active identity. Skips attestations (trust chain protection).
- `identity-setup` — Set up a multi-persona identity from the current master secret. Derives named persona sub-identities, optionally creates a Shamir backup and configures relays. Preview mode (confirm: false) shows what would be created without any side ef…
- `label-create` — Label an event, pubkey, or addressable event using NIP-32 (kind 1985).
- `label-self` — Self-label your own content (kind 1985). Useful for content warnings, categories,
- `list-followset-create` — Create a named follow set (NIP-51, kind 30000).
- `list-followset-manage` — Add or remove pubkeys from a named follow set (NIP-51, kind 30000).
- `list-mute` — Manage your mute list (NIP-51, kind 10000). Add or remove pubkeys, event IDs, keywords, or hashtags.
- `list-pin` — Manage pinned events (NIP-51, kind 10001). Add or remove event IDs from your pin list.
- `listing-close` — Mark a classified listing as sold or closed (NIP-99, kind 30402).
- `listing-create` — Create a classified listing (NIP-99, kind 30402). Publishes a replaceable event with title,
- `marketplace-announce` — Publish a kind 31402 service announcement on Nostr.
- `marketplace-update` — Update an existing kind 31402 service announcement. Same pubkey + identifier replaces the previous version (NIP-33 replaceable).
- `nip-publish` — Publish a community NIP (kind 30817) — a custom protocol specification on Nostr.
- `post-queue-cancel` — Cancel a scheduled post by event ID. Removes it from the queue.
- `post-schedule` — Schedule a Nostr event for future publication. Signs the event now and queues it on disk. Use nostr-bray publish-scheduled (via cron) to publish when due.
- `privacy-commit` — Create a Pedersen commitment to a secret value. Returns a public commitment point (safe to share) and a blinding factor (keep secret). The commitment cryptographically binds you to the value without revealing it.
- `privacy-publish-proof` — Publish a range proof as a kind 30078 (NIP-78) Nostr event. Includes the commitment, proof, range description, and optional subject pubkey. The proof can then be discovered and verified by anyone.
- `publish-event` — Sign and publish a Nostr event with any kind, content, and tags. Use for custom or experimental event kinds not covered by dedicated tools.
- `relay-add` — Add a single relay to the active identity\
- `relay-set` — Publish a kind 10002 relay list for the active identity. Warns if a relay list already exists.
- `safety-activate` — Switch to an alternative identity configuration.
- `safety-configure` — Configure an alternative identity persona and pre-warm relay connections.
- `signet-challenge` — Publish a kind 31000 challenge event against a verifier suspected of misconduct. Provide a reason code and optional supporting evidence text. Use
- `signet-policy-set` — Publish a kind 30078 Signet community policy signed by the active identity. Sets minimum verification tiers for adult and child access, optional minimum trust score, and enforcement mode. Use
- `signet-vouch` — Vouch for another user by publishing a kind 31000 attestation signed by the active identity. Use
- `social-post` — Post a text note (kind 1) signed by the active identity and publish to relays. Returns { id, pubkey, publish: { success, allAccepted, accepted, rejected } } where success is the majority-quorum signal (true when at least one relay accept…
- `social-profile-set` — Set the kind 0 profile for the active identity. Warns if profile already exists — set confirm: true to overwrite. Profile fields may be supplied either as top-level arguments or wrapped in a single
- `social-react` — React to a Nostr event (kind 7). Pass
- `social-reply` — Reply to a Nostr event (kind 1) with correct threading tags. You need the event ID and the author\
- `social-repost` — Repost/boost a Nostr event (kind 6) as the active identity.
- `trust-attest-temporal` — Create and publish an attestation with occurredAt field — records when the attested event actually happened, which may differ from the publication time. Also supports validFrom/validTo for deferred activation and validity windows.
- `trust-claim` — Make a direct statement about another identity — an endorsement, review, vouch, or any attestor-originated claim. You define the type and subject. Use trust-attest instead if the subject has published their own assertion event.
- `trust-proof-publish` — Publish a cryptographic linkage proof as a kind 30078 event. Requires confirmation — this is irreversible.
- `trust-request` — Send an attestation request to another Nostr identity via NIP-17 encrypted DM.
- `vault-create` — Create a Dominion vault config with named access tiers. Signs and publishes the config as a kind 30078 event. Returns the created event, publish result, and tier names.
- `wiki-publish` — Publish or update a wiki article (NIP-54, kind 30818). Creates a replaceable event keyed by topic (d-tag). Content convention is Asciidoc but Markdown is widely accepted. Articles are collaborative — anyone can publish a revision for the…
- `zap-wallet-set` — Set the NWC wallet URI for the active identity. Each persona can have its own Lightning wallet.

## Related servers

- Yaver (812 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- GoHighLevel MCP Server (566 tools) — https://policylayer.com/tools/busybee3333-go-high-level-mcp-2026-complete.md
- Ruflo (486 tools) — https://policylayer.com/tools/ruflo.md
- Claude Flow (454 tools) — https://policylayer.com/tools/io-github-ruvnet-claude-flow.md
- ServiceTitan MCP Server (454 tools) — https://policylayer.com/tools/jordandalton-servicetitanmcpserver.md
- CloudStack MCP Server (442 tools) — https://policylayer.com/tools/mozg31337-cloudstack-mcp-server.md
- Serac (432 tools) — https://policylayer.com/tools/serac.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-forgesworn-bray · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/dev-forgesworn-bray
