Mmcp.market

Bray MCP server

by forgesworn.dev·dev.forgesworn/bray·v1.27.7·1 stars

Trust-aware Nostr for AI agents -- 235 tools covering social, DMs, zaps, trust, and identity

B82/100grade B
What users say
No reviews yet
Be the first
Safety scan
B82/100

full report

Adoption
Growing

1 stars693 downloads/wk

Reviews

Write one

Nobody has reviewed Bray yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Bray tools (100, 24 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • canary-beacon-check

    Check a CANARY beacon's status. Pass a beaconId to check a locally tracked beacon,

  • canary-beacon-createwrite action

    Create an encrypted liveness beacon for a CANARY group.

  • canary-group-createwrite action

    Create an encrypted CANARY verification group. All members share a secret seed

  • canary-group-current

    Get the current verification word for a CANARY group.

  • canary-group-join

    Join an existing CANARY group using a shared seed (received via NIP-17 DM).

  • canary-group-members

    List members and admins of a CANARY group.

  • canary-group-verify

    Verify a spoken word against a CANARY group.

  • canary-session-createwrite action

    Create a CANARY verification session for two-party spoken verification.

  • canary-session-current

    Get the current verification words for an active CANARY session.

  • canary-session-verify

    Verify a spoken word against an active CANARY session.

  • cast-spellwrite action

    Execute a NIP-A7 Spell (kind 777). Fetches the Spell event, resolves runtime variables ($me → your pubkey, $contacts → your follow list) and relative timestamps (e.g. "7d", "30d"), builds a REQ filter, and queries relays. Pass either an event ID or a Spell event object from a prior relay-query.

  • dispatch-ack

    Acknowledge receipt of a dispatch task. Tells the sender "got it, working on it" before you have a full result. Use when a task will take time to complete.

  • dispatch-cancelwrite action

    Cancel a dispatch task you previously sent or received. Notifies the other party that the task should be abandoned.

  • dispatch-capability-discover

    Discover dispatch-capable agents on Nostr. Searches for NIP-89 capability cards (kind 31990) tagged with the dispatch protocol. Optionally filter by task type. Returns agent names, descriptions, supported task types, repos, and availability.

  • dispatch-capability-publishwrite action

    Publish your agent's dispatch capabilities as a NIP-89 capability card (kind 31990). Lets other agents discover you on Nostr without needing a pre-shared identities file. The card advertises what task types you support, which repos you can work on, and your availability.

  • dispatch-capability-read

    Read a specific agent's dispatch capability card. Fetches their NIP-89 kind 31990 event to see what task types they support, which repos they work on, and their current availability.

  • dispatch-check

    Check for incoming collaboration tasks from trusted Nostr identities. Returns dispatch messages: think tasks, build tasks, results, acks, status updates. Only shows messages from identities in the dispatch trust list, validated for freshness. Defaults to messages received since this session started (prevents re-processing old tasks). Pass since=0 to see all available messages regardless of age.

  • dispatch-failure

    Report that a dispatch task failed after you attempted it. Use when you tried to complete the task but encountered errors. Optionally include partial results so work is not lost.

  • dispatch-propose

    Propose an alternative approach for a dispatch task. Use when you can't do exactly what was asked but have a better idea. The sender receives the proposal via dispatch-check.

  • dispatch-query

    Ask the task sender a clarifying question before delivering results. Use mid-task when you need more information to proceed. The sender receives the question via dispatch-check and can reply.

  • dispatch-refuse

    Refuse a dispatch task you cannot or should not complete. Tells the sender "I cannot do this" with a reason. Use when the task is outside your capabilities, scope, or permissions.

  • dispatch-replywrite action

    Send a result back for a completed dispatch task. Use after finishing a think or build task received via dispatch-check. Only replies to trusted identities. Do not use this for human conversations — only for responding to tasks from other AI agents.

  • dispatch-sendwrite action

    Send a collaboration task to a trusted Nostr identity. Think tasks request read-only code analysis. Build tasks request implementation with code changes. The recipient's AI agent receives the task via encrypted NIP-17 DM and processes it with dispatch-check. Uses the active identity as sender — switch identity first if needed.

  • dispatch-statuswrite action

    Send a status update to collaborators. Use to broadcast availability (e.g. "busy until 14:00"), queue depth, or progress on long-running tasks.

  • execute-actionwrite action

    Execute an action found via search-actions. Pass the exact action name and its parameters.

  • handler-discover

    Discover MCP-capable handlers on Nostr. Searches for kind 31990 events that include mcp transport tags. Optionally filter by supported event kind. Returns handler names, descriptions, supported kinds, and transport endpoints.

  • handler-publishwrite action

    Publish a NIP-XX Machine Application Handler card (kind 31990) advertising MCP transport endpoints. Lets other agents and tools discover MCP servers on Nostr by the event kinds they support. Provide at least one of stdio_command or http_url.

  • identity-accept-migration

    Accept a migration from an external signer (Amber, nsec.app, etc). Signs and publishes the acceptance event via the current signer. Optionally verifies the migration event from the old key. Requires a Heartwood-compatible signer or local key.

  • identity-backup

    Fetch profile, contacts, relay list, and attestations for a pubkey. Returns a portable JSON bundle (no private keys).

  • identity-backup-shamir

    Split the active identity's private key into Shamir shard files using threshold secret sharing. Any "threshold" shards can reconstruct the key. Files written with 0600 permissions via atomic rename. Returns file paths only — shard content never appears in the response.

  • identity-createwrite action

    Generate a fresh Nostr identity with a BIP-39 mnemonic seed. Returns { npub, mnemonic }. Store the mnemonic securely — it will not be shown again. Use this when the user needs a brand new identity unrelated to the current one.

  • identity-derive

    Derive a child Nostr identity from the master key by purpose and index. Deterministic — same inputs always produce the same npub. Returns { npub, purpose, index }. Use identity_switch after deriving to operate as the new identity.

  • identity-derive-persona

    Derive a named persona (e.g. "work", "personal", "anonymous"). Like identity_derive but uses a human-readable name. Returns { npub, personaName, index }. Follow with identity_switch to activate.

  • identity-list

    List all known identities (master + all derived). Returns array of { npub, purpose, index, personaName }. Never includes private keys. Use this to see what identities are available before switching.

  • identity-migrate

    Migrate from an old identity to the active one. Shows preview first — set confirm: true to execute. Publishes linkage proof and re-signs migratable events.

  • identity-provewrite action

    Create a cryptographic linkage proof between the master key and the active identity. "blind" (default) proves they share a master without revealing how the child was derived. "full" also reveals the purpose and index. Returns a LinkageProof object that can be verified by anyone with nsec-tree. Use trust_proof_publish to make it permanent on relays.

  • identity-restore

    Re-sign migratable events (profile, contacts, relay list) under the active identity. Skips attestations (trust chain protection).

  • identity-restore-shamir

    Reconstruct a secret from Shamir shard files. Returns the restored npub for verification.

  • identity-switch

    Switch the active Nostr identity. ALL subsequent tool calls will sign events and query relays as the new identity. Pass "master" to return to root. Returns { npub } of the now-active identity. This is the key tool for multi-persona workflows.

  • label-createwrite action

    Label an event, pubkey, or addressable event using NIP-32 (kind 1985).

  • label-read

    Query NIP-32 labels for a target event, pubkey, or address.

  • label-removewrite action

    Delete a label event via kind 5 deletion. Only works for labels you authored.

  • label-search

    Find all events/pubkeys that have been given a specific label in a namespace.

  • label-self

    Self-label your own content (kind 1985). Useful for content warnings, categories,

  • list-bookmark

    Manage bookmarks (NIP-51). Without a name, manages general bookmarks (kind 10003).

  • list-bookmark-read

    Read bookmarks. Without a name, reads general bookmarks (kind 10003).

  • list-check-muted

    Check if a pubkey, event ID, keyword, or hashtag is on your mute list.

  • list-followset-createwrite action

    Create a named follow set (NIP-51, kind 30000).

  • list-followset-manage

    Add or remove pubkeys from a named follow set (NIP-51, kind 30000).

  • list-followset-read

    Read a named follow set by name (NIP-51, kind 30000).

  • list-mute

    Manage your mute list (NIP-51, kind 10000). Add or remove pubkeys, event IDs, keywords, or hashtags.

  • list-mute-read

    Read your current mute list (NIP-51, kind 10000). Returns all muted pubkeys, events, keywords, and hashtags.

  • list-pin

    Manage pinned events (NIP-51, kind 10001). Add or remove event IDs from your pin list.

  • list-pin-read

    Read your pinned events list (NIP-51, kind 10001).

  • listing-close

    Mark a classified listing as sold or closed (NIP-99, kind 30402).

  • listing-createwrite action

    Create a classified listing (NIP-99, kind 30402). Publishes a replaceable event with title,

  • listing-read

    Read classified listing(s) (NIP-99, kind 30402) by author and optional slug.

  • listing-search

    Search classified listings (NIP-99, kind 30402) by hashtag or geohash location.

  • marketplace-announcewrite action

    Publish a kind 31402 service announcement on Nostr.

  • marketplace-call

    Make an authenticated API call using L402 credentials obtained from marketplace-pay.

  • marketplace-compare

    Compare two or more L402 services side by side — pricing, capabilities, and shared features.

  • marketplace-credentials-clear

    Clear all stored L402 credentials from memory. Use when switching identity or cleaning up.

  • marketplace-discover

    Discover L402/x402 paid API services announced on Nostr (kind 31402).

  • marketplace-inspect

    Get full details of a specific L402 service by event ID, or by provider pubkey + identifier.

  • marketplace-paywrite action

    Pay an L402 invoice via NWC and store credentials for authenticated API calls.

  • marketplace-probewrite action

    Send an HTTP request to an endpoint and inspect the response.

  • marketplace-reputation

    Check a service provider's reputation — number of active services, announcement history, and topics covered.

  • marketplace-retire

    Retire (delete) a service announcement by publishing a kind 5 deletion event. The service will no longer appear in discovery results.

  • marketplace-search

    Full-text search across L402 service names, descriptions, topics, and capabilities.

  • marketplace-updatewrite action

    Update an existing kind 31402 service announcement. Same pubkey + identifier replaces the previous version (NIP-33 replaceable).

  • moderation-filter

    Filter a set of events against the active identity's mute list.

  • nip05-lookup

    Resolve a NIP-05 identifier (user@domain) to a Nostr pubkey. Also returns relay hints if the server provides them. Use this to find someone's pubkey from their human-readable address.

  • nip05-relays

    Fetch relay hints from a NIP-05 identifier. The NIP-05 server can suggest preferred relays for each pubkey. Returns a map of pubkey to relay URLs. Useful for relay discovery before messaging someone.

  • nip05-verify

    Verify that a NIP-05 identifier (user@domain) resolves to the expected pubkey. Returns { verified: true/false }. Use this to confirm someone's claimed NIP-05 identity.

  • privacy-commitwrite action

    Create a Pedersen commitment to a secret value. Returns a public commitment point (safe to share) and a blinding factor (keep secret). The commitment cryptographically binds you to the value without revealing it.

  • privacy-open

    Verify a Pedersen commitment opening. Given the original value and blinding factor, check they match the public commitment. Returns true if the commitment is valid.

  • privacy-prove-age

    Prove age is within a range without revealing the exact age. Supports formats like "18+" (adult), "13-17" (teen), "8-12" (child). Optionally bind to a subject pubkey to prevent transplanting.

  • privacy-prove-range

    Prove a secret value is within [min, max] without revealing the value. Returns a cryptographic range proof that anyone can verify against the commitment. Optional binding context prevents proof transplanting between credentials.

  • privacy-prove-threshold

    Prove a value exceeds a threshold without revealing the exact value. Useful for income verification, balance checks, credit scoring. The proof shows value >= threshold.

  • privacy-publish-proofwrite action

    Publish a range proof as a kind 30078 (NIP-78) Nostr event. Includes the commitment, proof, range description, and optional subject pubkey. The proof can then be discovered and verified by anyone.

  • privacy-read-proof

    Fetch and verify range proof events from relays. Returns a list of proofs with their verification status, labels, ranges, and subject pubkeys.

  • privacy-verify-age

    Verify an age range proof. Checks that the subject is within the expected age range without learning their exact age.

  • privacy-verify-range

    Verify a range proof. Checks that the committed value is within [min, max] without learning the value. Supply the same binding context used during proof creation.

  • privacy-verify-threshold

    Verify a threshold proof. Checks that the committed value is >= threshold without learning the value.

  • relay-add

    Add a single relay to the active identity's relay set (in-memory only — does not publish kind 10002).

  • relay-auth

    Authenticate to a relay that requires NIP-42 AUTH. Connects to the relay, waits for an AUTH challenge, signs a kind 22242 event, and sends it back. Returns { authenticated: true/false }. Use this when a relay-query fails due to AUTH requirements, then retry the query.

  • relay-compare

    Compare 2 or more relays side-by-side. For each relay: NIP-11 metadata, response time,

  • relay-count

    Count events matching a filter without fetching them (NIP-45). Sends a COUNT request to each relay. Falls back to fetch-and-count (capped at 1000) if the relay does not support NIP-45. Results show per-relay counts with fallback/estimated flags. Filter fields may be supplied either as top-level arguments or wrapped in a single "filter" object (both shapes are accepted).

  • relay-discover

    Discover relays used by your contacts. Fetches kind 10002 (NIP-65) relay lists from your follow list,

  • relay-diversity

    Analyse your relay set for centralisation risk. Checks unique operators, software diversity,

  • relay-info

    Fetch the NIP-11 relay information document for a relay URL.

  • relay-list

    List the relay set (read/write) for the active identity. Optionally check for shared relays with another identity.

  • relay-nip-search

    Find relays that support specific NIPs. Queries NIP-11 info documents and filters to relays

  • relay-query

    Query events from Nostr relays by kind, author, ids, tags, or time range. Useful for discovering events, scanning for specific kinds, or investigating unknown event schemas. Uses explicit relays if provided, otherwise the active identity's read relays. Filter fields may be supplied either as top-level arguments or wrapped in a single "filter" object (both shapes are accepted).

  • relay-recommend

    Recommend relays for your use case. Uses contact relay discovery, NIP-11 metadata, and health checks

  • relay-setwrite action

    Publish a kind 10002 relay list for the active identity. Warns if a relay list already exists.

  • safety-activate

    Switch to an alternative identity configuration.

  • safety-configure

    Configure an alternative identity persona and pre-warm relay connections.

  • search-actions

    Search … additional actions by describing what you want to do.

  • whoami

    Returns the active identity's npub. The simplest way to check which identity is currently in use.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan187 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 3 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10
Overall 82/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Bray in Claude Code, Cursor or VS Code

Runs npx -y nostr-bray on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add bray -- npx -y nostr-bray
Add to Cursor

What the publisher says

From the Bray repository's README, as published. We do not edit it. Read it on GitHub

nostr-bray

Trust-aware Nostr MCP for AI and humans. 261 tools across 29 groups. Model-agnostic. Works with Claude, ChatGPT, Gemini, Cursor, Windsurf, or any MCP client.

Quick Start

Install globally or run via npx:

npm install -g nostr-bray

New to Nostr? Mint a key first -- this works before anything is configured and prints your npub plus a 24-word mnemonic (write it down; it is the key):

npx nostr-bray create

Add to your MCP client config:

{
  "mcpServers": {
    "nostr": {
      "command": "npx",
      "args": ["nostr-bray"],
      "env": {
        "NOSTR_SECRET_KEY": "nsec1...",
        "NOSTR_RELAYS": "wss://relay.damus.io,wss://nos.lol"
      }
    }
  }
}

Then ask your AI to call whoami to verify it works.

For production use, prefer Heartwood or any NIP-46 bunker (your key never leaves your signing device):

{
  "mcpServers": {
    "nostr": {
      "command": "npx",
      "args": ["nostr-bray"],
      "env": {
        "BUNKER_URI": "bunker://...",
        "NOSTR_RELAYS": "wss://relay.damus.io,wss://nos.lol"
      }
    }
  }
}

Auth tiers (best to worst)

Tool Groups

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Bray: common questions

Is Bray MCP server safe?
Mostly: it is graded B (82/100). Read the Bray safety report
How do I install Bray?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Bray need an API key?
Yes. The registry entry asks for NOSTR_SECRET_KEY, NWC_URI.
Is Bray maintained?
The last commit was 3 days ago (2026-09-24). The latest release is v1.27.7.

More from forgesworn.dev →