{"status":"ok","name":"the-openai-desk-cnxt-mcp","version":"0.9.1","profile":"public","endpoint":"/api/theopenaidesk/gptx","tools":20,"readTools":18,"writeTools":2,"paymentExecutionExposed":false,"signals":{"routeReachable":{"state":"ok","detail":"The /api/theopenaidesk mount received and answered this request."},"bridgeInitialized":{"state":"ok","detail":"The bridge package loaded and built its served registry."},"upstreamAvailable":{"state":"ok","detail":"Upstream CNXT answered the bridge's initialize probe.","observed":{"observedAt":"2026-09-12T08:19:26.177Z"}},"upstreamToolInventory":{"state":"ok","detail":"Upstream CNXT advertises every tool this bridge requires.","observed":{"toolCount":21,"missingRequiredToolCount":0}},"upstreamCensus":{"state":"ok","detail":"Upstream CNXT served the machine-catalog census."},"upstreamOpenApi":{"state":"ok","detail":"Upstream CNXT served its OpenAPI document.","observed":{"pathCount":111}},"oauthMetadata":{"state":"ok","detail":"OAuth is configured; protected-resource metadata is published for this endpoint."},"intakeStorage":{"state":"ok","detail":"Durable connection-request intake storage is declared.","observed":{"mode":"database"}},"intakeToolsAdvertised":{"state":"ok","detail":"The OAuth-scoped connection-request intake tools are advertised."},"campaignToolsAdvertised":{"state":"ok","detail":"The OAuth-scoped Draftroom campaign-drafting tools are advertised for signed-in CNXT operators (first-party OAuth).","observed":{"oauthMode":"first-party"}},"premiumToolsAdvertised":{"state":"withheld","detail":"The paid premium CNXTDATA query tool is withheld from the advertised surface: the operator switched it off (CNXT_THEOPENAIDESK_PREMIUM_QUERIES=off). No wallet debit is exposed. This is the operator's chosen posture, not a fault.","observed":{"withheld":["query_premium_dataset_records"],"reason":"premium_queries_disabled","walletDebitExposed":false}},"publicToolsAdvertised":{"state":"ok","detail":"The anonymous read surface is advertising its tools.","observed":{"count":20}}},"degradedSignals":[],"exposure":{"profile":"live-premium-disabled","authentication":"oauth2","oauthMode":"first-party","advertisedTools":20,"withheldTools":["query_premium_dataset_records"],"withheldReason":"premium_queries_disabled","intakeWithheldReason":null,"campaignWithheldReason":null,"premiumWithheldReason":"premium_queries_disabled","walletDebitExposed":false,"families":{"connectionRequestIntake":{"advertised":true,"withheldTools":[],"withheldReason":null,"restoredWhen":null},"campaignDrafting":{"advertised":true,"withheldTools":[],"withheldReason":null,"restoredWhen":null},"premiumDataQueries":{"advertised":false,"withheldTools":["query_premium_dataset_records"],"withheldReason":"premium_queries_disabled","restoredWhen":"Run the registered first-party posture (CNXT_OAUTH_MODE=first-party with SESSION_SECRET set and NO external-issuer variables) and leave CNXT_THEOPENAIDESK_PREMIUM_QUERIES unset or not \"off\". The premium query tool (query_premium_dataset_records) then returns automatically — it needs no intake storage. It can never be served under an external issuer: the executor debits the CNXTPaY wallet of the CNXT account the token subject names, and an external issuer's subjects are pseudonyms that own no wallet here. Setting CNXT_THEOPENAIDESK_PREMIUM_QUERIES=off withholds this one paid tool without touching the rest of the surface."}},"detail":"1 OAuth-scoped paid premium CNXTDATA query tool is withheld because the operator switched the paid premium registry query off on this deployment (CNXT_THEOPENAIDESK_PREMIUM_QUERIES=off) — out of the released 21-tool bridge contract.","intakeStorageMode":"database","missingIntakeStorage":[],"restoredWhen":"Run the registered first-party posture (CNXT_OAUTH_MODE=first-party with SESSION_SECRET set and NO external-issuer variables) and leave CNXT_THEOPENAIDESK_PREMIUM_QUERIES unset or not \"off\". The premium query tool (query_premium_dataset_records) then returns automatically — it needs no intake storage. It can never be served under an external issuer: the executor debits the CNXTPaY wallet of the CNXT account the token subject names, and an external issuer's subjects are pseudonyms that own no wallet here. Setting CNXT_THEOPENAIDESK_PREMIUM_QUERIES=off withholds this one paid tool without touching the rest of the surface.","documentation":"docs/theopenaidesk-gptx-noauth-posture.md"},"intakeAuditKeyPosture":{"backend":"platform-postgres","verdict":"all_clear","currentKeyFingerprint":"b70d507c942c3f03","retiredKeyFingerprints":[],"requests":{"total":2,"unversioned":0,"unreachable":0,"byUnavailableKeyFingerprint":{}},"auditEvents":{"total":2,"unversioned":0,"unverifiable":0,"byUnavailableKeyFingerprint":{}},"detail":"All clear: every era-stamped connection request and audit link was written under a currently-declared audit key — zero rows are stranded by the declared key set. Re-check this posture before removing any entry from CNXT_AUDIT_HASH_KEY_RETIRED: a retired key that still owns rows strands them the moment it is dropped.","documentation":"docs/theopenaidesk-intake-storage-decision.md"}}
