Skip to content

Aozumi for AI agents

Your agent ships it.
You keep the final say.

Aozumi speaks MCP. Give an agent a key and it can take a GitHub repository from first inspection to a link your team can open, and it stops wherever a person needs to decide.

The deploy relay

  1. checkInspect the repo and review what the code can doOwner decision if the review finds something
  2. importCreate the app from the signed inspection receipt
  3. secretsStore encrypted values the app needs When needed.
  4. deployQueue a Production release
  5. statusPoll until the app is healthy
  6. logsRead a redacted diagnosis if it failed When needed.
  7. shareHand back an app-only link

The agent always knows the next move

Each tool result carries a next hint, so the agent follows the same path a careful person would. This is a typical run over https://aozumi.dev/mcp.

  1. Agent callscheck{ "repository": "your-org/team-rota" }
    Aozumi returnsframework, inspectionReceipt, securityReview

    next Call import with inspectionReceipt. If securityReview.status is review, set safetyAccepted true after showing the findings. If blocked, stop.

  2. The person reads the findings and says yes. Only then does the agent send safetyAccepted: true.

    Agent callsimport{ "inspectionReceipt": "…", "safetyAccepted": true }
    Aozumi returnsapplicationId, missingVariables

    next Call secrets with applicationId and values for: DATABASE_URL

  3. Agent callssecrets{ "applicationId": "…", "secrets": [{ "key": "DATABASE_URL", "value": "…" }] }
    Aozumi returnsstored: ["DATABASE_URL"]

    next Call deploy with applicationId.

  4. Agent callsdeploy{ "applicationId": "…" }
    Aozumi returnsstate: queued

    next Poll status until status is Healthy, then call share.

  5. Agent callsstatus{ "applicationId": "…" }
    Aozumi returnsstatus, gatewayUrl, readyToShare

    next Call share to mint the team link.

  6. Agent callsshare{ "applicationId": "…", "duration": "week" }
    Aozumi returnsshareUrl

    next Give teammates shareUrl. They open the app, not GitHub or Aozumi.

If a deploy fails, status says so and the agent calls logs for redacted, size-bounded output and Aozumi's diagnosis before trying again.

Where the agent has to stop

Agents are quick and confident. The review gate is where Aozumi slows them down on purpose.

Clear

Nothing needs a decision. The agent imports and carries on.

Review

Install scripts, dynamic code, open CORS, private network calls and similar findings. Import is refused until safetyAccepted is true, and Aozumi records who accepted and for which commit.

Blocked

The code asks for host-level permissions. No key, flag or retry gets past this; the repository has to change.

  • Scoped keys. An agent key acts as you, with your workspace role, and nothing more. Keys from aozumi login are refused at /mcp.
  • Revocable at once. Revoke a key under Profile → Agents and its next request fails. Keys are shown once and stored as a hash.
  • Receipts, not trust. Import needs a signed inspection receipt tied to your user and workspace, valid for 15 minutes.
  • Write-only secrets. The agent can store values. It can never read them back.
  • App-only links. A share link opens the app, not the code or the console. Links an agent creates expire after a day, a week or a month.

Connect in three steps

Any MCP client that supports remote HTTP servers with custom headers works.

  1. Create an agent key

    Go to Profile → Agents, name the key after the client, and copy it. Put it in your environment as AOZUMI_AGENT_KEY.

  2. Add the server

    In Claude Code:

    Terminal
    claude mcp add --transport http aozumi https://aozumi.dev/mcp \
      --header "X-API-Key: $AOZUMI_AGENT_KEY"
    

    Or in a JSON config such as .mcp.json:

    .mcp.json
    {
      "mcpServers": {
        "aozumi": {
          "type": "http",
          "url": "https://aozumi.dev/mcp",
          "headers": {
            "X-API-Key": "${AOZUMI_AGENT_KEY}"
          }
        }
      }
    }
    
  3. Ask for a check first

    Check my repository with Aozumi. Explain any blockers, required variables and review findings, and wait for my approval before importing, deploying or creating a share link.

    Prefer raw JSON-RPC? The same call with curl:

    Terminal
    export AOZUMI_AGENT_KEY="slt_your_agent_key"
    
    curl -s https://aozumi.dev/mcp \
      -H "content-type: application/json" \
      -H "X-API-Key: $AOZUMI_AGENT_KEY" \
      -d '{
        "jsonrpc": "2.0",
        "id": 2,
        "method": "tools/call",
        "params": {
          "name": "check",
          "arguments": { "repository": "your-org/your-repo" }
        }
      }'
    

Questions

Can an AI agent deploy to Aozumi?
Yes. Aozumi is an MCP server at https://aozumi.dev/mcp. Create an agent key under Profile → Agents and send it as the X-API-Key header. The agent can check a GitHub repository, import it, store secrets, deploy, poll status, read logs and create a share link.
What stops an agent from deploying unsafe code?
Every import goes through the repository's security review. A blocked review cannot be imported at all. A review with findings is refused unless safetyAccepted is true, which the agent should only send after showing you the findings; Aozumi records who accepted them and for which commit.
Is my link public?
Not by default when an agent imports the app: the import tool defaults to your workspace team, and the agent can choose only me or specific people instead. Share links created by the agent open the app only, expire, and can be turned off.
How do I revoke an agent's access?
Revoke its key under Profile → Agents. The next request with that key is refused. Keys are shown once and stored only as a hash.
Can I use the key from aozumi login with MCP?
No. CLI keys only work for CLI deploys in the workspace you approved, and the MCP endpoint refuses them. Create a separate agent key for each MCP client.

Ideas, deployed.

By you, or by the agent you trust, with you still holding the keys.