Server data from the Official MCP Registry
Durable temporal event intelligence: composite triggers, derived events, and runtime wakeups.
About
Durable temporal event intelligence: composite triggers, derived events, and runtime wakeups.
Security Report
Valid MCP server (2 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.
6 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: DATA_DIR
Environment variable: MCP_WRITE_ENABLED
Environment variable: RUNTIME_WAKE_TARGETS_JSON
Environment variable: TYPESAFE_API_KEY
Environment variable: TYPESAFE_MODEL
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-sarooo17-event-intelligence": {
"env": {
"DATA_DIR": "your-data-dir-here",
"TYPESAFE_MODEL": "your-typesafe-model-here",
"TYPESAFE_API_KEY": "your-typesafe-api-key-here",
"MCP_WRITE_ENABLED": "your-mcp-write-enabled-here",
"RUNTIME_WAKE_TARGETS_JSON": "your-runtime-wake-targets-json-here"
},
"args": [
"-y",
"mcp-event-intelligence"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
MCP Event Intelligence
Durable temporal event intelligence for sleeping agents.
MCP Event Intelligence is an experimental event runtime for agents that need to react to future conditions over multiple event sources without keeping an LLM or agent loop alive.
The primary integration model is embedded and host-owned: the agent host keeps its existing MCP clients, transports, OAuth sessions and provider credentials. Event Intelligence receives a reference to the host's MCP registry, discovers the already-connected clients automatically, and uses only the Events-capable ones.
An agent can express an intent such as:
When this PR is merged, the production deploy succeeds, and no error is observed for 10 minutes, wake this task and review the release.
Event Intelligence persists that continuation independently of the model, waits for the world to satisfy it, and wakes the host only when necessary.
Embed it in an existing agent host
Install from npm:
npm install mcp-event-intelligence
Published package: npm · Official MCP Registry
Pass the harness-level MCP registry once — not every MCP one by one:
import {
createEventIntelligenceHost,
createMcpRegistryAdapter,
} from 'mcp-event-intelligence/host';
const ei = await createEventIntelligenceHost({
dataDir: './data',
mcpRegistry: createMcpRegistryAdapter({
listConnections: () => host.mcp.listConnections(),
subscribe: (refresh) => host.mcp.onConnectionsChanged(refresh),
}),
wake: async (packet, activation) => {
const receipt = await host.resume(packet.target, {
packet,
activation,
});
return { runtimeReceiptId: receipt.id };
},
});
Event Intelligence enumerates the host registry automatically. GitHub, Gmail, private/company MCPs and future connections do not need to be configured again inside EI. Tools-only MCPs remain available to the agent and are ignored by the Events layer; Events-capable MCPs are attached automatically.
Agent-first trigger flow
Agents no longer need to construct the low-level trigger DSL directly for common cases. Ask EI to compile an agent-friendly plan against the event sources that are actually available:
const plan = await ei.planTrigger({
events: [{
id: 'invoice',
event: 'erpnext.sales_invoice.submitted',
where: [
{ path: 'grand_total', op: 'gt', value: 10000 },
],
}],
match: 'all',
withinMs: 60 * 60 * 1000,
target: {
runtime: 'agent',
kind: 'conversation',
id: 'chat-42',
},
continuation: {
instruction:
'Check the submitted invoice for anomalies and report back in this conversation.',
},
});
await ei.triggerControl.createTrigger({
definition: plan.definition,
connectionIds: plan.connectionIds,
actor,
owner,
});
planTrigger() is deterministic. It does not call a model. It resolves event names to live source/server IDs, validates predicate paths against advertised payload schemas, compiles all / any / sequence / count, and returns the canonical trigger definition plus the required connection IDs.
The persisted continuation answers a separate question from the trigger condition: what should the agent do after the future condition becomes true?
The wire wake remains deliberately small and reference-only. Embedded hosts also receive an Activation Envelope as the second wake argument. The same envelope can be reconstructed later:
const activation = ei.hydrateWake(wakeId);
The envelope contains the configured continuation, trigger/match state, and matched evidence. Event payloads are labeled as untrusted external signals and are included only according to the trigger's continuation.contextPolicy.
Shared hosts, tenant isolation and storage
One EI host can serve many tenants/workspaces without sharing trigger state. Give each host-owned MCP connection a scopeId and give tenant-facing code only the corresponding scoped view:
const tenant = await ei.scope('tenant-acme');
await tenant.triggerControl.createTrigger({
definition,
connectionIds: ['acme-erp'],
actor,
owner,
});
const acmeConnections = tenant.mcpStatus();
The default reference store physically namespaces non-default scopes under separate persistent store partitions. Trigger IDs, match IDs, cursors, event sources, deadlines, derived events and wake delivery state are therefore resolved inside a scope rather than filtered out of a global result after the fact. The root host object is the trusted operator/control-plane capability; tenant code should receive a scoped view.
Storage is injectable:
const ei = await createEventIntelligenceHost({
store: myEventIntelligenceStore,
mcpRegistry,
wake,
});
PersistentEventStore remains the zero-dependency default. A custom backend can implement forScope(scopeId) to return an isolated tenant view. For horizontally scaled workers, its wake-delivery claim/lease operations must be atomic across processes; the bundled JSONL store provides serialized atomicity inside one process and is a reference backend, not a distributed database.
Add Events to an MCP provider
Providers can expose the experimental Events boundary without reimplementing the generic JSON-RPC glue:
import { createMcpEventsProvider } from 'mcp-event-intelligence/provider';
const events = createMcpEventsProvider({
events: [
{
descriptor: {
name: 'erpnext.sales_invoice.submitted',
description: 'A submitted Sales Invoice was observed.',
delivery: ['poll'],
inputSchema: { type: 'object' },
payloadSchema: {
type: 'object',
required: ['name', 'company', 'grand_total'],
properties: {
name: { type: 'string' },
company: { type: 'string' },
grand_total: { type: 'number' },
},
},
},
poll: async ({ cursor, maxEvents, context }) => {
return providerRuntime.pollInvoices({ cursor, maxEvents, context });
},
},
],
});
The package owns capability advertisement, server/discover, events/list, events/poll, common validation and response shapes. The provider owns domain event definitions, authentication, data queries, occurrence IDs and opaque cursor semantics.
This adapter remains experimental compatibility work around MCP Events; it is not a claim of finalized MCP Events conformance.
An ERPNext-shaped provider factory is also exported:
import {
createErpNextEventsProvider,
} from 'mcp-event-intelligence/provider/erpnext';
const events = createErpNextEventsProvider({
pollSalesInvoices: ({ cursor, maxEvents }) =>
erp.pollSubmittedInvoices({ cursor, maxEvents }),
pollSalesOrders: ({ cursor, maxEvents }) =>
erp.pollCreatedSalesOrders({ cursor, maxEvents }),
});
This helper owns the MCP Events descriptors, schemas and response validation for
erpnext.sales_invoice.submitted and erpnext.sales_order.created. It is
not a credential-owning ERPNext connector: the host/provider must supply the
actual data-access functions. That separation is intentional so Event
Intelligence never duplicates provider authentication.
The production proof that the abstraction works against a real ERP data layer
lives in sarooo17/world-capability-mcp: its ERP Events implementation uses
createMcpEventsProvider with authenticated ERPNext/Frappe record queries,
tenant/company filters, opaque replay-safe cursors, pagination/hasMore,
timezone normalization and deterministic occurrence IDs. The local factory in
this package should therefore be read as a typed convenience API, not as the
production ERP connector itself.
What v0.3 implements
Host-owned event sources
- automatic discovery from the host's existing MCP registry;
- reuse of already-connected MCP clients without duplicate credentials;
- experimental MCP Events capability discovery;
events/listandevents/poll;- persistent opaque cursors;
- per-scope source/cursor isolation for shared hosts;
- single-flight polling per connection plus bounded
hasMorebatch draining; - automatic event-source registration;
- dynamic attach/detach of host MCP clients;
- provider-native compatibility adapters such as GitHub webhooks.
Composite and temporal triggers
allOf,anyOf,sequence,count;- deterministic same-value correlation;
- optional semantic correlation;
absence,not,unless,after,until;debounce,threshold,rate,distinct;- calendar-aware conditions with IANA timezones;
- durable deadlines that continue even when no new provider event arrives.
Agent-authored continuations
- event-source discovery;
- agent-friendly deterministic trigger planning/compilation;
eq,neq,contains,in,exists,gt,gte,lt,ltepredicates;- persisted continuation contracts separated from trigger conditions;
- Activation Envelope hydration with matched event evidence;
- embedded wake callbacks receive
(packet, activation); - deterministic validation against real source schemas and advertised fields;
- approval-gated persistent mutations;
- one-shot, cooldown, max-firings, expiry, leases, update and delete.
Derived events and composition
Triggers can emit immutable higher-level events instead of waking an agent:
pr.merged + deploy.succeeded
↓
release.ready@1
+
manager.approved
↓
rollout.allowed@1
↓
runtime wake
Derived events preserve refs-only lineage to their direct parents and flattened root evidence.
Versioned contracts
Derived event names are versioned contracts such as release.ready@1.
- first producer establishes the canonical schema;
- compatible producers may join the same contract version;
- incompatible schemas fail before trigger persistence;
- multiple versions may coexist;
- ambiguous unversioned consumers fail closed;
- every occurrence carries a schema fingerprint.
Host or callback wake
An embedded harness can provide one in-process wake dispatcher that routes by target.runtime, target.kind and target.id; runtime-specific handlers remain available as a lower-level option. A standalone deployment can instead use signed HMAC callbacks. Both paths return a stable runtimeReceiptId.
Runtime delivery is durable: a stable wake ID gets a persisted delivery record, a worker claims it with a lease, transient failures are retried with bounded exponential backoff, expired claims can be recovered after restart, and only an exhausted retry budget enters dead-letter. This prevents two workers sharing an atomic store from intentionally owning the same delivery at the same time. The runtime should still treat the stable wake ID as an idempotency key because no system can make an arbitrary external side effect transactionally exactly-once without cooperation from the receiver.
Why this exists
MCP Events is concerned with the event transport/subscription boundary. Event Intelligence explores the layer above transport:
- how an agent declares a future condition;
- how multi-event state survives while the agent sleeps;
- how absence/time becomes an event;
- how higher-level facts are derived without invoking a model;
- how those facts can be safely composed;
- how a host resumes an agent effectively once in the validated scenarios.
This project does not propose a replacement for MCP Events and does not claim to be an official MCP extension.
AI and API keys
Event Intelligence has one optional AI boundary: semantic correlation.
TYPESAFE_API_KEYenables the bundled TypeSafe Jev evaluator when a trigger explicitly requests semantic correlation.- embedded hosts may inject a compatible
semanticEvaluatorinstead. - there is no bundled OpenAI planner and no OpenAI API dependency.
The agent/harness is already responsible for natural-language reasoning. It can use trigger_plan / planTrigger() to compile common requests deterministically against discovered source schemas, or submit a canonical trigger definition directly for advanced cases. Deterministic correlation, temporal logic, persistence, derived events and wake delivery require no model API.
Full-system acceptance
The v0.3 acceptance suite verifies:
- host-owned MCP client → event discovery/poll → composite match → in-process wake;
- provider-neutral events → composite match → derived event → derived composition → signed runtime wake;
- contract schema evolution and ambiguity rejection;
- refs-only root provenance;
- replay without duplicate derived events or wakes;
- process shutdown while a temporal deadline is pending;
- restart on the same datastore after the deadline;
- wake recovery without a new provider event;
- retry-state recovery after process restart and lease-based concurrent-worker exclusion;
- shared-host tenant isolation with identical trigger IDs in different scopes;
- bounded/single-flight provider polling;
- provider-generalization coverage with ERPNext-shaped invoice/order events;
- hash-linked audit verification.
A separate live regression also verified real GitHub webhook ingress into the MCP EventOccurrence / composite fan-in path.
Standalone reference service
Requirements
- Node.js 22+
- no external database for the reference setup
git clone https://github.com/sarooo17/event-intelligence.git
cd event-intelligence
npm ci
npm run check
export SERVICE_AUTH_TOKEN="$(openssl rand -hex 32)"
npm start
Then:
curl http://127.0.0.1:3000/readyz
The standalone service supports manual/provider-native event ingress. It does not own arbitrary MCP connections; host-owned MCP reuse belongs to the package integration above.
Docker
docker build -t mcp-event-intelligence:0.3.1 .
docker run --rm \
-p 3000:3000 \
-v mcp-event-intelligence-data:/data \
-e SERVICE_AUTH_TOKEN="$(openssl rand -hex 32)" \
mcp-event-intelligence:0.3.1
Optional MCP control plane
The package also exposes a standard MCP stdio control plane through the official TypeScript SDK v2:
npx mcp-event-intelligence mcp
Read/non-mutating tools are exposed by default, including event_sources_list, trigger_plan, inspection, simulation, wake_hydrate, contracts and runtime status. trigger_create accepts either a raw canonical definition or the same agent-friendly plan shape; EI compiles the latter before applying the normal mutation controls.
Persistent trigger mutations are only registered when the operator explicitly enables MCP_WRITE_ENABLED=true, and each mutation still requires a confirmationId. The MCP server is a control-plane adapter; it is not a gateway through which the host's other MCP servers must be reconnected.
See docs/QUICKSTART.md and docs/MCP-REGISTRY.md.
Configuration
Standalone/core environment variables:
| Variable | Required | Purpose |
|---|---|---|
SERVICE_AUTH_TOKEN | yes for protected HTTP APIs | bearer token for control-plane endpoints |
DATA_DIR | no | persistent JSONL directory, default ./data |
PORT | no | HTTP port, default 3000 |
ENVIRONMENT_ID | no | environment boundary |
RUNTIME_WAKE_TARGETS_JSON | no | signed standalone runtime callbacks |
GITHUB_WEBHOOK_SECRET | no | verify GitHub webhook ingress |
TYPESAFE_API_KEY | no | bundled TypeSafe Jev semantic evaluator |
WAKE_DELIVERY_MAX_ATTEMPTS | no | maximum wake delivery attempts, default 5 |
WAKE_DELIVERY_LEASE_MS | no | claim lease duration, default 30000 |
WAKE_RETRY_BASE_DELAY_MS | no | first retry delay, default 1000 |
WAKE_RETRY_MAX_DELAY_MS | no | retry backoff cap, default 60000 |
WAKE_RETRY_TICK_MS | no | retry scheduler tick, default 1000 |
Embedded hosts pass one MCP registry adapter. Event Intelligence discovers already-connected clients from that registry; provider MCP connection settings are not duplicated inside EI.
Architecture
The detailed execution model, clocks, lifecycle, persistence and trust boundaries are documented in docs/ARCHITECTURE.md.
Important semantics
Event-time vs processing-time
Normal event windows use event occurredAt.
Absence/deadline progression uses Event Intelligence processing time. This separation is explicit and tested.
Effectively-once runtime activation
The implementation does not claim theoretical distributed exactly-once delivery.
It uses stable wake IDs, persisted delivery state, atomic claim leases, bounded retries, runtime receipts and replay handling to provide effectively-once runtime activation in the validated reference scenarios.
Derived event vs current state
A derived event says what became true at a point in history.
v0.3 intentionally does not implement a mutable current-state/facts database.
Security
Read SECURITY.md and docs/SECURITY-MODEL.md.
In embedded mode, the host retains MCP authorization and credentials; Event Intelligence discovers only the client objects exposed through the host-provided MCP registry. Tenant-facing callers should receive only host.scope(scopeId). The reference JSONL store is scope-partitioned and single-process; distributed custom stores must preserve scope isolation and atomic wake claims.
MCP compatibility status
There are two separate MCP boundaries:
- event ingress: host-owned, already-connected MCP clients exposing experimental Events, plus provider-native adapters;
- control plane: optional standard MCP stdio server built on the official TypeScript SDK v2 and targeting protocol revision 2026-07-28.
Registry identity:
io.github.sarooo17/event-intelligence
server.json is validated with the official mcp-publisher validate command in CI. MCP Events itself remains experimental and may change as the Triggers & Events work evolves.
Project status
v0.3.x reference implementation / experimental.
The architecture is implemented and exercised end-to-end. Storage is now injectable and scoped, while the bundled JSONL backend remains a single-process reference implementation. Remaining work is primarily production database adapters/HA validation, scale benchmarks and upstream feedback.
Example
See the release-gate example for a composed future-condition flow using durable time, derived events and targeted wake.
Contributing
See CONTRIBUTING.md.
Contributions are especially useful around host adapters, MCP Events compatibility, temporal semantics, production persistence, security review and reproducible provider integrations.
License
Apache License 2.0. See LICENSE.
Disclaimer
This is an independent open-source project. It is not an official Model Context Protocol specification and is not affiliated with or endorsed by the MCP maintainers.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
