Yichus / Reference / API MCP tools
api_frontend
If api_verify is proven, generate a self-contained HTML frontend from a Yichus/Frontend::FrontendSpec in the sources. Refuses unknown routes, unrepresentable handler extras, and unproven APIs. Transport (in-process or http) and auth (dev, clerk, auth0, api-key, bearer) are tool args.
Kind: Frontend. Origin: Yichus/Mcp::catalog.
CLI: yichus api frontend — the same verified frontend generation.
Parameters
sources(required, array) — JSON array of {fileName, source} Bosatsu files including the API module and the FrontendSpec.instances(optional, string) — Deployment topology: 1 for a single engine instance, many for multiple instances sharing one DB. Left out, the sources are verified as many but an in-process engine still takes requests one at a time; pass many to run its requests side by side. With transport: http no engine is embedded: the sources are still verified under this topology, and the remote engine's own api_deploy decides how it takes requests.transport(optional, string) — in-process (default; embed the engine) or http (fetch to api_base_url).api_base_url(optional, string) — Required when transport is http: origin the generated app will POST to.auth(optional, string) — dev (default; user-id field), clerk (a session token for a YICHUS_AUTH=jwt engine with Clerk's JWKS; a clerk-api-key engine answers it 401), auth0, api-key (http only, for a YICHUS_AUTH=clerk-api-key engine: the person pastes an API key the page sends as its Bearer credential and holds in memory only; the page never creates keys, Clerk issues them; a key carries no roles, so the API must declare no role_route), or bearer (in-process only: the app hands the engine a Bearer token it verifies itself against jwks; the page's test issuer or any RS256 issuer). Provider modes obtain a Bearer token only.clerk_publishable_key(optional, string) — Clerk publishable key. Required when auth is clerk.auth0_domain(optional, string) — Auth0 domain. Required when auth is auth0.auth0_client_id(optional, string) — Auth0 SPA client id. Required when auth is auth0.jwks(optional, string) — JWKS JSON (a {keys:[...]} object, as a string) the in-process engine verifies RS256 Bearer tokens against. Required when auth is bearer.issuer(optional, string) — Optional expected iss claim for bearer auth.audience(optional, string) — Optional expected aud claim for bearer auth.roles_claim(optional, string) — Optional exact JWT payload key containing an array of role strings. Required to exercise role_route through in-process bearer auth.store(optional, string) — Storage the embedded engine attaches at boot: memory (default; forgets on reload) or local:<name> (one localStorage key per table; survives reloads and a crash).
Read the result according to this tool’s scope: static checks, bounded execution checks, and descriptive diagrams answer different questions. A successful call is not a general approval of the program. The safety and permissions guide compares the checks and provides editable ownership, guard, and role examples.