Yichus / Reference / API MCP tools
api_deploy
If api_verify is proven under the declared topology, generate the Yichus API engine JavaScript (handlers + Principal injection + DB IO). Refuses when any property is violated or blocked, and when a property named in require is not proven. The emitted HTTP server refuses to listen unless YICHUS_AUTH is jwt (JWKS), clerk-api-key (API keys checked with Clerk via CLERK_SECRET_KEY), proxy-header (X-User-Id plus YICHUS_TRUST_PROXY_AUTH=1), or dev (YICHUS_DEV_AUTH=1). The engine also serves its routes as MCP tools at /mcp, so an agent can call the deployed API.
Kind: Deploy. Origin: Yichus/Mcp::catalog.
CLI: yichus api deploy — the same engine generation; the CLI writes the file, the tool returns it.
Parameters
sources(required, array) — JSON array of {fileName, source} Bosatsu files for the API module.port(optional, integer) — Optional listen port for the generated engine (default 8080).instances(optional, string) — Deployment topology: 1 for a single engine instance, many for multiple instances sharing one DB. Left out, the sources are verified as many but the engine still takes requests one at a time; pass many to run them side by side.require(optional, array) — Optional JSON array of api_verify property ids (for example ["stored-field-disclosure"]) that must each be proven, not only free of violations: a warning or blocked status, or an id the verdict does not have, refuses the deploy.
Read the result according to this tool’s scope: static checks, bounded execution checks, and descriptive diagrams answer different questions. A successful call is not a general approval of the program. The safety and permissions guide compares the checks and provides editable ownership, guard, and role examples.