# yaver_openrouter_integrate

Deterministically add a secure, cost-bounded OpenRouter chat seam to an Expo + Convex app. Detects either the Yaver starter-session boundary or standard Convex auth, refuses an unauthenticated paid proxy, keeps OPENROUTER_API_KEY server-only, restricts browser CORS to APP_URL, passes SSE through without one database write per token, and optionally writes a React Native stream client. Idempotent; returns exact changed files, env keys, security contract, and next prompts for domain-aware chat or image diagnosis.

Agent View of the PolicyLayer registry record for `yaver_openrouter_integrate`. HTML page: https://policylayer.com/tools/io-github-kivanccakmak-yaver/yaver-openrouter-integrate

## Facts

- Tool: `yaver_openrouter_integrate`
- Server: Yaver (`yaver-cli`) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Install: `npx -y yaver-cli`
- Homepage: https://github.com/kivanccakmak/yaver.io
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 5 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `auth_mode` | string | no | Default auto. An explicit mode is still validated against actual auth wiring. |
| `directory` | string | yes | Explicit project or monorepo root. Auto-detects backend/convex or convex and an Expo root at ., apps/mobile, or mobile. |
| `convex_directory` | string | no | Optional path relative to directory when Convex layout is nonstandard or detection is ambiguous. |
| `mobile_directory` | string | no | Optional Expo root relative to directory when layout is nonstandard or detection is ambiguous. |
| `include_mobile_client` | boolean | no | Default true. Write yaver/openRouterChat.ts beneath the detected Expo root for native/RN-web SSE consumption. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "yaver_openrouter_integrate",
    "arguments": {
      "directory": "<directory>"
    }
  }
}
```

## Why yaver_openrouter_integrate is rated Medium

Creates/modifies app configuration, environment variables, and source code files reversibly with security guardrails intact.

From the tool's own definition: "add secure cost-bounded OpenRouter chat seam, writes React Native stream client, returns changed files env keys"

Risk signals: Accepts file system path (directory)

## Use case

AI agents use yaver_openrouter_integrate to create or update resources in Yaver, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Yaver environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Yaver:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "yaver_openrouter_integrate": {
      "limits": [
        {
          "counter": "yaver_openrouter_integrate_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Yaver (677)

- `acl_remove_peer` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/acl-remove-peer.md
- `cancel_schedule` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/cancel-schedule.md
- `cloud_destroy` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/cloud-destroy.md
- `companion_down` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/companion-down.md
- `data_delete` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/data-delete.md
- `db_push` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/db-push.md
- `db_reset` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/db-reset.md
- `db_restore` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/db-restore.md
- `disk_manage` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/disk-manage.md
- `dns_flush` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/dns-flush.md
- `dns_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/dns-remove.md
- `docker_prune` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/docker-prune.md
- `docker_rm` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/docker-rm.md
- `docker_rmi` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/docker-rmi.md
- `dogfood_installation_action` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/dogfood-installation-action.md
- `feedback_delete` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/feedback-delete.md
- `forgot_password` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/forgot-password.md
- `git_member_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/git-member-remove.md
- `git_stash` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/git-stash.md
- `jobs_cancel` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/jobs-cancel.md
- `machine_onboarding_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/machine-onboarding-remove.md
- `machine_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/machine-remove.md
- `microservice_down` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/microservice-down.md
- `migrate_rollback` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/migrate-rollback.md
- `models_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/models-remove.md
- `monitor_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/monitor-remove.md
- `phone_project_delete` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/phone-project-delete.md
- `proxy_remove` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/proxy-remove.md
- `relay_clear_password` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/relay-clear-password.md
- `release_rollback` — Destructive — https://policylayer.com/tools/io-github-kivanccakmak-yaver/release-rollback.md
- …and 647 more: https://policylayer.com/tools/io-github-kivanccakmak-yaver.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-kivanccakmak-yaver · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-kivanccakmak-yaver
