ALPHA ARCHITECTURE
Artifact MCP and Live MCP
Artifact interprets a session that has already ended. Live exercises authority over a run. Keeping them separate keeps shared evidence away from control of a Mac.
In preparation
This architecture is approved, but Artifact MCP is not yet available to connect. Today, the published remote connector remains the Live door, and the MCPB extension remains the local door.
Two authorities, three paths
| surface | used for | cannot reach |
|---|---|---|
| Artifact MCP — in preparation | Read a sealed source allowed by your original audience or shared with you by name, explore its observed flow, and create authorized derivatives. | Jobs, rooms, live frames, input, Nodes, Simulator, or the local bridge. |
| Remote Live MCP | Create runs, enter rooms, and read sealed results for runs whose original audience includes you, using your identity, role, and lease. | It never uses a ProjectShare to expand that audience or grant live control. |
| Local MCPB extension | Connect an agent to Kelvin.app on the same Mac through the macOS user's private socket. | It receives no Artifact token and grants no access to projects shared in the Cloud. |
Sharing a project is not sharing a credential
The creator grants access to a named Kelvin person or organization. The HTML and identifiers only locate the project; every read uses the viewer's own account and rechecks the share.
Access may have no end date, but it remains revocable. When the creator revokes it, the next read fails, even if a read had been authorized moments earlier.
The original remains the original
Observed reuses screens and transitions present in the sealed evidence. Pixels come from the original capture and the derivative points to the source hash.
Modelled is a separate, visibly marked hypothesis. It never enters the seal or appears as a screen the session proved.
When the requested screen was not observed
- Artifact stops at not observed and offers to prepare a new capture.
- A separate dashboard page requires a recent login and shows exactly what will run.
- Kelvin.app shows the same request on the selected Mac and requires local approval.
- Only after both approvals does Live create a new run. The previous seal is never changed.
The boundary that matters
A token, catalog, or permission from one surface is invalid on the other. Artifact never calls local MCP, and knowing an ID or sharing the HTML never grants authority.