Chapter03Nebbos MCP

The tool substrate. Attested.

Every tool your Nebbos platform runs passes through one substrate. The binary lives on your Nebbos USB. Physical presence gates the elevated tiers. Attestation is server-verified, not client-claimed.

Get the highlights

Five commitments. One tool surface.

  • Transport

    JSON-RPC over HTTPS

    Every call authenticated, versioned, and auditable.

  • Attestation

    Server-verified

    The MCP verifies factors before executing. Client claims mean nothing.

  • Isolation

    Shell-scoped

    Cross-Shell reads require enclave-signed approval. No accidental crossing.

  • Binary

    Ships on the USB

    Config, credentials, and code live on your Nebbos USB. Unplug removes them.

  • Quota

    Cost-follow overage

    Tool-call quotas per Shell. Overage billed at cost-follow with quarterly reconciliation.

Take a closer look

How the substrate holds.

  • One substrate, every tool call

    Every action that touches Shell state — reads, writes, mutations, cross-boundary joins — passes through the Nebbos MCP. There are no side channels, no direct database access, no host-shell backdoors.

  • Tier-gate decorator

    Every tool declares its required tier (L1 · L2 · L3). The MCP verifies factors before executing. Missing biometric? Refused. Missing USB physical presence for L2? Refused. Missing enclave-signed approval for L3? Refused.

  • Binary lives on the USB

    The MCP binary, the config, the attestation credentials, and the Shell state that seeds a session all ship on the encrypted Nebbos USB volume. When the device is mounted, the host reads and executes. Unplug, and the mount is gone; elevated calls cannot produce valid attestations.

  • Audit chain on every call

    Every call writes an audit event with a hash-chained parent reference. Hash-chain verifiable end-to-end. Replay-proof, tamper-evident, discovery-ready.

The core

One code tree. Two surfaces.

The Nebbos MCP and the Nebbos USB are one code tree. The binary ships on the encrypted USB volume; physical presence of the device is the hardware factor that gates elevated tiers.

Without the USB plugged in, elevated permissions are not available. There is no cloud-only version of the MCP with the same authority. The device is the contract.

About the Nebbos USB →

Built for

Operators who need their tools to prove what they did.

  • Enterprise operators

    Every tool call authenticated, versioned, and auditable.

  • Regulated verticals

    Finance, healthcare, energy, defense contractors, government agencies.

  • Platform builders

    Nebbos.ai and your own domain-specific tools, one substrate.

Values

Three commitments. No exceptions.

  • Attestation

    The MCP verifies. You don't claim.

    Every elevated call requires factors the server verifies against enrolled credentials. Signature counter, origin, attestation chain, tier gate — all checked before the tool runs.

  • Shell isolation

    Cross-Shell reads are a ceremony.

    The MCP refuses cross-Shell operations without an enclave-signed approval token. Accidental crossing is impossible; deliberate crossing is audited and reviewable.

  • Cost-follow

    Overage matches provider cost.

    Tool-call quotas per Shell. When you exceed, overage rates follow underlying provider costs with quarterly reconciliation. No markup surprises, no lock-in.

Choose your tier

One MCP. Three tiers.

Each tier unlocks a different scope of the tool surface. L2 and L3 require the Nebbos USB physically plugged in; L3 additionally requires an enclave-signed approval token per admin call.

  • L1 · Basic

    MCP tool substrate for a Shell — read tools and low-risk operations.

    Factors · Device-native biometric (Touch ID · Face ID · Windows Hello · Android BiometricPrompt)

    Ops · Dashboard view, personal-scope reads, low-risk tool calls.

    Contact sales →

  • L2 · Privileged

    MCP substrate with USB-attested elevated tool surface for a Shell.

    Factors · Biometric + Nebbos USB physical presence

    Ops · Shell writes, memory registers, admin operations within the Shell.

    Contact sales →

  • L3 · Admin

    MCP substrate for substrate-mutation and cross-boundary admin ops.

    Factors · Biometric + Nebbos USB + enclave-signed approval token

    Ops · Shell creation and destruction, substrate mutation, cross-Shell, quorum-required actions.

    Contact sales →

The other three products

One matrix. Four products.

  • Software

    Nebbos.ai platform

    The AI operations platform for institutional scale.

    Explore →

  • Software

    Nebbos app

    Local native for macOS and Windows.

    Explore →

  • Hardware

    Nebbos USB

    Hardware-attested security devices.

    Explore →

Every tool call, attested.

Enterprise procurement and regulated deployments: reach out and we’ll walk you through provisioning, tier gates, and audit chain setup.