Chp

io.github.capabilityhostprotocolv0.8.0更新於 Oct 8, 2026

Learn and adopt the Capability Host Protocol — the agentic web's open evidence layer.

已驗證Streamable HTTP可網頁執行Developer ToolsAI & MLSecurity & Monitoring

概覽

AI 產生的概覽

一個遠端 MCP 端點,用於 Capability Host Protocol,將代理與工具的實際行為記錄並治理為可簽章、可重放的證據。

功能
提供 Capability Host Protocol(CHP),一個面向代理與工具執行的開放證據層。它定義了能力描述元、主機描述元、呼叫封套、關聯脈絡、結構化執行證據、結果/錯誤/拒絕語意以及重放查詢。README 也描述了一個本機 Python 套件(chp-core),可掛接編碼代理,把每次工具呼叫記錄為本機 SQLite 存放區中帶雜湊鏈的型別化事件,並支援列出工作階段、依關聯 ID 重放,以及測試某項政策原本會拒絕哪些呼叫。
適用情境
如果你想要代理與工具行為的受治理、防竄改紀錄(包括附原因碼的拒絕),並能重放或稽核一次執行,就值得考慮。它鎖定的是需要在執行邊界取得證據與治理的團隊,而不是另一個代理框架。
執行需求
資訊清單宣告了一個不需驗證、沒有環境變數或標頭的遠端 streamable HTTP 端點。README 中的本機流程需要 Python 與 pip 來安裝 chp-core,並把證據寫入使用者家目錄下的本機 SQLite 檔案。
安裝前請注意
README 描述了會攔截代理工具呼叫並在本機記錄的掛接,啟用前應確認會蒐集哪些內容。它也提到可選的 ed25519 簽章擴充以及一個失敗即報錯的驗證開關(CHP_HOST_REQUIRE_AUTH=1),因此金鑰處理與驗證設定需要留意。資訊清單宣告該遠端端點不需驗證。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Chp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "chp": {
      "type": "http",
      "url": "https://capabilityhostprotocol.com/api/mcp"
    }
  }
}

README

Capability Host Protocol

[PyPI] [Python] [npm] [License] [Docs]

CHP is the open protocol for declaring, governing, and proving what agents, tools, and systems do — the single signed plane where a human approval, an agent's action, and a system call become the same governed, tamper-evident, replayable event.

The hook is simple:

See what your agents and tools actually did — and what governed it.

Try it in two minutes

Your coding agent reads files, runs commands, calls tools. This puts a governed boundary at the point of action — no application code changes:

bash
pip install chp-corechp hooks install                        # hooks Claude Codechp hooks install --all-harnesses        # ...or Claude Code + Codex + Gemini CLI

Use your agent normally, then look at what it did:

bash
chp session listchp session tree <session_id>

Every tool call is a typed evidence event, hash-chained and stored locally in ~/.chp/evidence.sqlite. A denial is a first-class event with a reason code — not a swallowed exception — and the chain is tamper-evident, so someone who did not run the agent can still tell whether the record is intact.

Prefer to drive the protocol directly? chp serve-demo starts a governed host and prints a copy-pasteable first invocation.

Full guide: docs/quickstart.md · why it exists: docs/why-chp.md · docs site: docs.capabilityhostprotocol.com

What you get back

Replay is by correlation ID, and the record answers more than "what happened" — from examples/agent-operations-demo/:

json
[  {"sequence": 1,  "event_type": "execution_started",   "capability_id": "trace_execution", "outcome": null},  {"sequence": 3,  "event_type": "execution_completed", "capability_id": "trace_execution", "outcome": "success"},  {"sequence": 7,  "event_type": "execution_started",   "capability_id": "tool.add",        "outcome": null},  {"sequence": 12, "event_type": "execution_started",   "capability_id": "tool.multiply",   "outcome": null},  {"sequence": 13, "event_type": "execution_completed", "capability_id": "tool.multiply",   "outcome": "success"}]

You can also ask what a policy would have done to a run that already happened:

json
{  "invariant": {"id": "deny_multiply_tool", "kind": "capability_id_matches"},  "would_have_denied": true,  "violating_events": [{"capability_id": "tool.multiply", "event_type": "execution_started"}]}

Why a protocol, not a library

CHP is not another agent framework, tool protocol, or workflow engine. It is the governed evidence plane at the capability boundary: what ran and what governed it (policy, risk tier, safety checks, human approval, autonomy budgets, denial) emit onto one signed, correlated record. Observability tools split execution across separate, optional, unsigned signals and carry no governance; CHP unifies both and proves them.

Status: CHP is a pre-1.0 release candidate (v0.9.3) — a frozen, additive wire surface backed by two independent implementations (Python + TypeScript) that pass conformance. chp-core ships on PyPI.

What CHP Defines

  • Capability descriptors
  • Host descriptors
  • Invocation envelopes
  • Correlation context
  • Structured execution evidence
  • Outcome, error, and denial semantics
  • Replay queries and results
  • Replay by correlation ID
  • Minimal conformance requirements

Install

bash
pip install chp-core                 # zero runtime dependenciespip install 'chp-core[schema]'       # enforce declared input_schemapip install 'chp-core[signing]'      # ed25519 — signed hosts, bundles, mandatesnpm install @capabilityhostprotocol/sdk   # TypeScript client + verifier (alpha)

chp host verify smoke-tests the install in under a second and reports whether input-schema validation is enforced.

From this checkout: python -m pip install -e packages/python.

Minimal Capability

python
from chp_core import LocalCapabilityHost, capability
host = LocalCapabilityHost("example-host")
@capability(    id="math.add",    version="1.0.0",    description="Add two numbers.",)def add(a: int, b: int):    return {"sum": a + b}
host.register(add)
result = host.invoke(    "math.add",    {"a": 2, "b": 3},    correlation_id="demo-correlation",)
print(result.outcome)       # "success"print(result.data)          # {"sum": 5}
for event in host.replay("demo-correlation"):    print(event.event_type)  # execution_started, execution_completed

The host emits execution_started and execution_completed evidence for the invocation. If execution fails, it emits execution_failed. If the host denies invocation, it emits execution_denied.

Repository Map

  • spec/README.md: the specification index — core (v0.1), governance vocabulary, invocation pipeline, HTTP binding, evidence integrity + anchors (v0.2), reserved names, test vectors, changelog, proposal process
  • schemas/: JSON Schemas for protocol objects
  • packages/python/chp_core/: reference host (Python)
  • packages/chp-sdk/ + packages/chp-host-ts/: the second implementation (TypeScript)
  • examples/capability-host-endpoint-demo/: HTTP-served host demo
  • examples/agent-operations-demo/: agent/tool observability demo
  • examples/codex-self-observation-demo/: Codex dogfooding demo
  • examples/mcp-bridge-demo/: experimental MCP-style bridge prototype
  • conformance/: conformance runner
  • docs/quickstart.md: install, first run, serving, mesh
  • docs/why-chp.md: the problem and the thesis
  • docs/adapter-authoring.md: writing your own capability adapter
  • docs/production-runbook.md: operations, backup/restore, key compromise
  • docs/comparisons/chp-vs-mcp.md: precise MCP comparison
  • docs/comparisons/chp-and-opentelemetry.md: OpenTelemetry alignment note
  • docs/comparisons/landscape.md: adjacent framework comparison
  • docs/security/threat-model-v0.1.md: v0.1 threat model

Production Posture

The reference implementation is hardened for production operation: WAL multi-writer safety with hot backup (chp store backup --verify), SIGTERM drain (in-flight work completes before exit), a fail-loud auth flag (CHP_HOST_REQUIRE_AUTH=1), scheduled retention, and operator metrics (store size, witness-loop liveness, revocation counts, internal errors). Operations, backup/restore, rolling upgrades, and the key-compromise runbook: docs/production-runbook.md. Vulnerability reporting: SECURITY.md.

CHP vs MCP

MCP exposes tools and context to AI applications. CHP governs and evidences execution of capabilities.

They fit together. MCP can be a source of capability invocation, and CHP adds correlation, replay, evidence, denial semantics, and governance at the execution boundary.

Read more: docs/comparisons/chp-vs-mcp.md.

Contributing

Read CONTRIBUTING.md first. One thing to know before you open a pull request: this repository is a generated mirror of a private development repository. CI rejects pull requests that touch packages/, docs/, spec/, schemas/, or examples/ from a branch that is not sync/*, so a code PR against those paths will fail by construction no matter how good it is.

That is not a brush-off — it is the publishing model, and we would rather say so up front than let you find out from a red check. Issues, spec proposals, comparisons, and discussion are the highest-bandwidth way in today; open an issue and we will route the change through the internal flow with attribution.

Open Source Boundary

Open source should include local visibility:

  • spec and schemas
  • local host
  • SDK primitives
  • conformance
  • local replay
  • agent observability wrapper
  • experimental MCP bridge prototype

Commercial value can remain around production trust:

  • hosted capability graph
  • multi-host trace stitching
  • retention
  • team workspaces
  • advanced explanation
  • invariant libraries
  • assurance derivation
  • compliance exports
  • enterprise identity and RBAC

Guiding rule:

Local visibility should be free. Production trust should be paid.

License

CHP is dual-licensed by asset:

  • Code (packages/, conformance/, examples/, scripts/): Apache License 2.0 — see LICENSE.
  • Specification, schemas & docs (spec/, schemas/, docs/): Creative Commons Attribution 4.0 (CC BY 4.0) — see LICENSE-DOCS. Implementing the specification is additionally covered by a royalty-free patent grant — see PATENTS.
  • Trademarks: "CHP" and "CHP-Certified" — see TRADEMARK.md.

Contributions are accepted under the Contributor License Agreement; see CONTRIBUTING.md.

Copyright © 2026 Project Auxo, Inc. See NOTICE.

來源:README.md,提交 6ffb84a

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.8.0最新Sep 16, 2026