{
  "independent_protocols": [
    {
      "audience": null,
      "id": "oauth.authorization",
      "path": "/oauth/authorize",
      "protocol": "oauth_2_1_pkce",
      "reason": "OAuth authorization, discovery, token exchange, refresh, and revocation establish credentials; they are protocol infrastructure rather than user business tools.",
      "scopes": []
    },
    {
      "audience": "attention-mcp",
      "id": "mcp.transport",
      "path": "/mcp",
      "protocol": "mcp_streamable_http",
      "reason": "The Streamable HTTP endpoint transports the MCP tools declared below and performs audience, scope, entitlement, and request validation.",
      "scopes": [
        "profile:read",
        "collection:read",
        "collection:write",
        "digest:read",
        "digest:write",
        "moderation:write",
        "moderation:court:read",
        "moderation:court:vote",
        "public:read",
        "public:full",
        "ai:search",
        "subscription:read"
      ]
    },
    {
      "audience": "attention-sync",
      "id": "collection.sync",
      "path": "/api/sync",
      "protocol": "sync_http",
      "reason": "Local-first collection synchronization has conflict, tombstone, and batch semantics that are intentionally separate from conversational MCP tool calls.",
      "scopes": [
        "sync:read",
        "sync:write"
      ]
    },
    {
      "audience": "attention-channel-runtime",
      "id": "local-agent.runtime-reporting",
      "path": "/api/runtime",
      "protocol": "runtime_reporting_http",
      "reason": "A local Agent may report installation health and host-managed channel pairing outcomes without uploading local channel credentials; this is not a hosted Channel UI.",
      "scopes": [
        "runtime:register",
        "runtime:heartbeat",
        "channel:bind:report",
        "channel:disconnect:report",
        "channel:notifications:read"
      ]
    }
  ],
  "mcp": {
    "audience": "attention-mcp",
    "contract_version": "1.7.0",
    "scopes": [
      "profile:read",
      "collection:read",
      "collection:write",
      "digest:read",
      "digest:write",
      "moderation:write",
      "moderation:court:read",
      "moderation:court:vote",
      "public:read",
      "public:full",
      "ai:search",
      "subscription:read"
    ],
    "tools": [
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "member_or_filter"
        },
        "id": "collection.source.read",
        "oauth": {
          "any_of_scopes": [
            "collection:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Read temporary article evidence from an eligible public source owned through the current account's collection.",
        "tool_name": "attention_read_collection_source",
        "web_surface": {
          "kind": "api",
          "path": "/api/collections/:collectionId/source-read",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "account.read",
        "oauth": {
          "any_of_scopes": [
            "profile:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Read the signed-in account's public identity and current Member and Filter capabilities.",
        "tool_name": "attention_get_my_account",
        "web_surface": {
          "kind": "page",
          "path": "/account",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "membership.read",
        "oauth": {
          "any_of_scopes": [
            "subscription:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Read live Member and Filter capability and the current billing subscription record without changing billing.",
        "tool_name": "attention_get_membership_status",
        "web_surface": {
          "kind": "page",
          "path": "/membership",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "collection.list",
        "oauth": {
          "any_of_scopes": [
            "collection:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "List and search the authenticated account's private and public collections with pagination.",
        "tool_name": "attention_list_collections",
        "web_surface": {
          "kind": "page",
          "path": "/account",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": "filter_for_public_visibility",
          "required": "authenticated_account"
        },
        "id": "collection.create",
        "oauth": {
          "any_of_scopes": [
            "collection:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Collect a URL or platform share text privately, or publicly when the account has live Filter status.",
        "tool_name": "attention_collect_content",
        "web_surface": {
          "kind": "page",
          "path": "/collect",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "content.enrichment.submit",
        "oauth": {
          "any_of_scopes": [
            "collection:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Submit the first grounded title, final public URL, summary, and normalized tags for Content owned through an active collection without overwriting an existing shared result.",
        "tool_name": "attention_submit_content_enrichment",
        "web_surface": {
          "kind": "page",
          "path": "/collect",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": "filter_for_public_visibility",
          "required": "authenticated_account"
        },
        "id": "collection.candidate.select",
        "oauth": {
          "any_of_scopes": [
            "collection:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Resolve one ambiguous collection attempt by selecting a candidate using its one-time selection token.",
        "tool_name": "attention_select_collection_candidate",
        "web_surface": {
          "kind": "page",
          "path": "/collect",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "collection.status.read",
        "oauth": {
          "any_of_scopes": [
            "collection:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Read processing, collection, and content status for an owned collection attempt or collection.",
        "tool_name": "attention_get_collection_status",
        "web_surface": {
          "kind": "page",
          "path": "/collect",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": "filter_for_public_visibility",
          "required": "authenticated_account"
        },
        "id": "collection.visibility.update",
        "oauth": {
          "any_of_scopes": [
            "collection:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Change an owned collection between private and public while enforcing live Filter status for public visibility.",
        "tool_name": "attention_update_collection",
        "web_surface": {
          "kind": "page",
          "path": "/account",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": "member_for_full_public_feed",
          "required": "authenticated_account"
        },
        "id": "public-content.list",
        "oauth": {
          "any_of_scopes": [
            "public:read",
            "public:full"
          ],
          "audience": "attention-mcp"
        },
        "summary": "List the chronological public feed with the same preview wall and full-feed Member policy as the website.",
        "tool_name": "attention_list_public_content",
        "web_surface": {
          "kind": "page",
          "path": "/ai",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "member"
        },
        "id": "content.search",
        "oauth": {
          "any_of_scopes": [
            "ai:search"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Search owned collections and the complete public network and return citations to original-link routes.",
        "tool_name": "attention_search_content",
        "web_surface": {
          "kind": "api",
          "path": "/api/agent/query",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "moderation.report.create",
        "oauth": {
          "any_of_scopes": [
            "moderation:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Report public content after explicit user confirmation, with duplicate reports handled idempotently.",
        "tool_name": "attention_report_content",
        "web_surface": {
          "kind": "api",
          "path": "/api/moderation/reports",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "filter"
        },
        "id": "moderation.court.list",
        "oauth": {
          "any_of_scopes": [
            "moderation:court:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "List current moderation-court cases, vote counts, prior vote, and original-link routes for an active Filter.",
        "tool_name": "attention_list_moderation_cases",
        "web_surface": {
          "kind": "page",
          "path": "/account/court",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "filter"
        },
        "id": "moderation.court.vote",
        "oauth": {
          "any_of_scopes": [
            "moderation:court:vote"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Cast an active Filter's irreversible moderation vote only after explicit confirmation of the exact case and decision.",
        "tool_name": "attention_cast_moderation_vote",
        "web_surface": {
          "kind": "page",
          "path": "/account/court",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "authenticated_account"
        },
        "id": "digest.settings.read",
        "oauth": {
          "any_of_scopes": [
            "digest:read"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Read digest schedule, domains, delivery settings, and current eligibility without modifying delivery.",
        "tool_name": "attention_get_digest_settings",
        "web_surface": {
          "kind": "page",
          "path": "/account/digests",
          "shared_policy": true
        }
      },
      {
        "contract_version": "1.7.0",
        "entitlement": {
          "conditional": null,
          "required": "member_or_filter"
        },
        "id": "digest.settings.update",
        "oauth": {
          "any_of_scopes": [
            "digest:write"
          ],
          "audience": "attention-mcp"
        },
        "summary": "Enable, disable, or reschedule digest delivery with the same domain and live entitlement checks as the website.",
        "tool_name": "attention_update_digest_settings",
        "web_surface": {
          "kind": "page",
          "path": "/account/digests",
          "shared_policy": true
        }
      }
    ]
  },
  "release_stage": "infrastructure_only",
  "schema_version": "1.0.0",
  "web_only": [
    {
      "id": "account.authentication",
      "reason": "Email verification, password login, and browser-session bootstrap cannot be delegated to a bearer credential that does not exist until authentication succeeds.",
      "reason_code": "credential_bootstrap_boundary",
      "summary": "Register, sign in, verify email ownership, and establish the browser session used to approve later Agent access.",
      "web_surface": {
        "kind": "page",
        "path": "/login"
      }
    },
    {
      "id": "account.security",
      "reason": "Password changes and session logout stay behind a fresh interactive browser session so a compromised MCP credential cannot replace account credentials or terminate sessions.",
      "reason_code": "credential_lifecycle_boundary",
      "summary": "Set or change the account password and manage the current authenticated browser session.",
      "web_surface": {
        "kind": "page",
        "path": "/account/security"
      }
    },
    {
      "id": "account.public-identity",
      "reason": "Display name, Attention ID, and avatar changes affect public attribution and therefore require an explicit human-controlled profile interaction rather than an Agent content workflow.",
      "reason_code": "human_identity_boundary",
      "summary": "Edit public identity fields and avatar while preserving the Attention ID rename policy.",
      "web_surface": {
        "kind": "page",
        "path": "/account/settings"
      }
    },
    {
      "id": "agent.credential-management",
      "reason": "OAuth consent, client revocation, and API Key creation or revocation must not be exposed through the same credential whose authority they could expand, replace, or conceal.",
      "reason_code": "credential_lifecycle_boundary",
      "summary": "Approve Agent access and create, inspect, or revoke OAuth connections and API Keys.",
      "web_surface": {
        "kind": "page",
        "path": "/account/connections"
      }
    },
    {
      "id": "membership.checkout",
      "reason": "Starting a paid subscription requires interactive price disclosure, payment-provider checkout, and user confirmation; MCP only exposes read-only membership status.",
      "reason_code": "interactive_payment_boundary",
      "summary": "Review membership terms and start or manage an interactive paid subscription checkout.",
      "web_surface": {
        "kind": "page",
        "path": "/membership"
      }
    },
    {
      "id": "growth.rewards",
      "reason": "Invitation rewards, Filter redemption codes, and annual gifts remain in a rate-limited human flow because automating issuance or redemption would weaken abuse controls.",
      "reason_code": "anti_abuse_boundary",
      "summary": "Create and redeem invitation or Filter reward codes and inspect the account's reward state.",
      "web_surface": {
        "kind": "page",
        "path": "/account/rewards"
      }
    }
  ]
}
