@humanagencyp/deploy-mcp
OfficialThe @humanagencyp/deploy-mcp server lets you securely manage and trigger deployments for GitHub-hosted repositories, gating real user releases behind a signed receipt. It never builds code—only activates existing workflow runs. You can:
List deployments (
list_deployments): Retrieve recent workflow runs available for release, with their URLs and states.Get deployment details (
get_deployment): Fetch a specific workflow run's details by ID.Resolve references (
resolve_ref): Convert a branch, tag, or partial commit SHA into a full commit SHA, ensuring deploys target an exact commit.List environments (
list_environments): Enumerate repository environments (e.g., production, staging) using the host's naming.Deploy (
deploy): Dispatch a GitHub Actions workflow to deploy a specific commit to a target environment, optionally on a custom branch. Requires areceipt_id(injected by the gateway) that the pipeline verifies before promoting the build.
Provides tools for resolving branch/tag references to commit SHAs, listing environments, and dispatching deployment workflows on GitHub repositories.
Allows dispatching GitHub Actions workflow runs for deployment, listing recent workflow runs, and retrieving deployment status.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@humanagencyp/deploy-mcpwhat's the latest commit on main?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@humanagencyp/deploy-mcp
Deploy MCP server — make already-built software live, under bounded human authority.
Implements the executor side of the Human Agency Protocol
deploy@0.7 profile. Backend: GitHub Actions.
What it does
Exposes releasing as gated tools so an agent can put software in front of real users only with a signed receipt behind it. It does not decide whether a release is allowed — that is the Gatekeeper's job, and then the pipeline's.
The gated action is a release, not a build. Building harms nobody: a preview at a URL nobody visits has no consequence. Serving it does. So this server never builds — it activates a build that already exists, which means a human can open it and look before approving, and no rebuild can diverge from what was approved.
Tool | Kind | |
| read | builds that can be released, with their URLs |
| read | one build, with URL and state |
| read | branch/tag → commit SHA |
| read | the repo's real environments |
| consequential | make an existing build live |
Related MCP server: agentic-sdlc-mcp
Setup
GITHUB_TOKEN=<fine-grained token>Fine-grained, scoped to one repository:
Permission | Why |
Actions: read & write | dispatch the workflow |
Environments: read | list environments for the authorization wizard |
Contents: read | resolve a branch to a commit |
Not Contents: write. This server releases builds that already exist; it
never authors or builds anything.
Two properties that are easy to lose
1. release declares receipt_id. That declaration is what makes a Suveren
gateway inject the receipt it just minted. Remove it and the pipeline has
nothing to verify — the chain quietly degrades to an unproven release. The tool
refuses to dispatch when the field is missing, so the failure is loud.
2. A build URL is required, not a commit or branch. release rejects
anything that is not a URL. The receipt binds that exact build — the same bytes
a human inspected. Call list_deployments first.
Deployment URLs come from GitHub's Deployments API, which hosts with a GitHub
integration (Vercel, Netlify, Render) populate with environment_url. So this
server never needs the host's credentials — GitHub already knows the address,
and that one value identifies the artifact, shows the human what they are
approving, and is what the host's promote command accepts.
The pipeline must verify
Dispatching is not the control point — anyone with repository write access can dispatch a workflow. The workflow itself must check the receipt before serving anything:
on:
workflow_dispatch:
inputs:
deployment_url: { required: true }
receipt_id: { required: true }
environment: { required: true }
jobs:
verify: # signature, action is a release, freshness,
# and that the receipt BINDS THIS BUILD
...
release:
needs: verify
steps:
- run: vercel promote "${{ inputs.deployment_url }}" --token "$VERCEL_TOKEN"Nothing is built here. promote re-points production at bytes that already
exist, so what goes live is exactly what was inspected.
on:
workflow_dispatch:
inputs:
sha: { required: true }
receipt_id: { required: true }
environment: { required: true }
jobs:
verify: # signature, scope, commit binding, freshness
...
deploy:
needs: verify
steps:
- uses: actions/checkout@v6
with:
ref: ${{ inputs.sha }} # the APPROVED commit, not the branch headBuilding the branch head instead of inputs.sha means a receipt for one commit
can ship another — and the receipt still verifies, certifying something false.
That is worse than having no receipt at all.
Limits, stated plainly
This server dispatches; it does not hold the deploy credentials the pipeline uses. The boundary is the receipt requirement, not the whole path.
GitHub returns no run id from a dispatch, so the run is matched by workflow and creation time. Best-effort: it reports no run rather than guessing wrong.
Licence
MIT
Available Tools
5 toolsdeployA
Deploy a specific commit by running a deployment pipeline. Requires a receipt: the pipeline verifies it before anything is released.
| Name | Required | Description | Default |
|---|---|---|---|
| sha | Yes | Exact commit to deploy — resolve it with resolve_ref first | |
| repo | Yes | Repository as owner/name | |
| branch | No | Branch the workflow is dispatched on (default "main"). The commit that gets BUILT is `sha`, not this. | |
| workflow | Yes | Workflow file to run, e.g. deploy.yml | |
| receipt_id | No | Injected by the gateway after the receipt is issued | |
| environment | Yes | Target environment, e.g. production |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must carry the full burden of behavioral disclosure. It reveals a critical behavior: the pipeline verifies the receipt before releasing anything, which is a gating mechanism. However, it does not disclose other important traits such as whether the deployment is asynchronous, what side effects occur, or what happens on failure. The single behavioral detail is useful but incomplete.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise: two sentences that front-load the primary action and follow up with the critical receipt requirement. Every word earns its place, and there is no redundant or vague language.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is a deployment operation with six parameters and no output schema, yet the description does not explain what the tool returns or how the receipt is obtained. While the schema documents all parameters well, the missing information about return values and the receipt issuance workflow leaves gaps. For a complex operation like deployment, a score of 3 reflects the incomplete context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema provides 100% coverage with detailed descriptions for all parameters, including the note that the built commit is `sha` not `branch`, and that `receipt_id` is injected by the gateway. The description itself adds no additional parameter semantics beyond the schema. With full schema coverage, a baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: deploying a specific commit through a deployment pipeline. It uses a specific verb and resource, and the mention of the receipt requirement adds distinguishing detail. It is unambiguously different from the sibling tools, which are about resolving refs, listing deployments, getting deployments, and listing environments.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states a key prerequisite: a receipt is required and verified before any release. This gives clear usage context. However, it does not explicitly mention when not to use this tool or name alternatives, such as using list_deployments to check status instead, so it falls short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_deploymentB
Get one workflow run by id.
| Name | Required | Description | Default |
|---|---|---|---|
| repo | Yes | Repository as owner/name | |
| run_id | Yes | Workflow run id |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It only states 'Get one workflow run by id' without mentioning error handling, return format, auth requirements, or any other behavioral traits. This is insufficient for a tool with no structured safety hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with zero extraneous words. It efficiently states the action and identifier, making it easy to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of annotations, lack of output schema, and a potential naming mismatch, the description is too sparse to be fully self-contained. It does not explain what the returned object looks like, error cases, or how this tool fits into the broader workflow deployment context, leaving the agent with limited guidance.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already fully describes both parameters (repo and run_id) with 100% coverage, so the description adds no additional meaning. Per guidelines, baseline for high schema coverage is 3, and the description merely says 'by id' without elaborating on parameter formats or relationships.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action ('Get one workflow run by id'), clearly distinguishing from listing siblings by focusing on a single item. However, there is a slight naming mismatch between the tool name ('get_deployment') and the described resource ('workflow run'), which could cause confusion but doesn't obscure the core purpose.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage when you need a single workflow run by ID, but it does not explicitly contrast with alternatives like list_deployments or resolve_ref, nor provide context on when not to use this tool. The guidance is minimal and relies on inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_deploymentsB
List recent workflow runs for a repository.
| Name | Required | Description | Default |
|---|---|---|---|
| repo | Yes | Repository as owner/name | |
| limit | No | How many runs to return (default 10) | |
| workflow | No | Workflow file name, e.g. deploy.yml |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It only says 'list recent workflow runs' without stating that it is safe/read-only, whether it affects state, or any other side-effect or access requirements. This is minimal transparency beyond the core action.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that is direct and to the point. No filler or redundant detail, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple list tool, the description is adequate but lacks detail about return format, pagination, or the time window implied by 'recent'. The name mismatch with 'deployments' also creates ambiguity. Given the absence of an output schema and annotations, slightly more context would be needed for full completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with all three parameters (repo, limit, workflow) described. The tool description adds no extra param semantics beyond implying recency ('recent') and workflow filtering, but the schema already covers these. Thus baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a clear action ('List') and resource ('recent workflow runs') with context ('for a repository'). However, the tool name 'list_deployments' clashes with the description's 'workflow runs', which could confuse agents expecting deployment objects. It is specific enough to be understood, but the naming inconsistency prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is given on when to use this tool over siblings like get_deployment or deploy. The description simply states what it does without specifying scenarios, prerequisites, or exclusions, leaving the agent to infer usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_environmentsA
List the deployment environments a repository defines. Names are the host's own vocabulary, not a fixed set.
| Name | Required | Description | Default |
|---|---|---|---|
| repo | Yes | Repository as owner/name |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses a behavioral trait: environment names follow the host's own vocabulary, not a fixed set. As a listing operation, read-only is implied, but no annotations are available to confirm safety or other behaviors.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences: the first states the primary action and target, the second adds an important qualifier. No redundant details.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a straightforward single-parameter list operation, the description covers the core purpose and a key caveat. However, with no output schema, it doesn't explicitly describe the return shape, though this is reasonably inferable from 'list environments'.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema fully documents the single required parameter 'repo' with type and description. The description adds no additional parameter semantics beyond the schema, so baseline applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the action ('List') and the resource ('deployment environments a repository defines'), distinguishing it from siblings like list_deployments by focusing on environments defined by the repo. The added nuance about host-specific vocabulary further clarifies the scope.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides context that environment names are host-specific, implying the user should not assume fixed values. However, it does not explicitly state when to prefer this over list_deployments or get_deployment, though the 'environments' vs 'deployments' distinction offers implicit guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
resolve_refA
Resolve a branch, tag or commit to a concrete commit SHA. Call this BEFORE deploying: a deploy is authorised for one specific commit, not for whatever a branch points at later.
| Name | Required | Description | Default |
|---|---|---|---|
| ref | Yes | Branch, tag or commit SHA (e.g. "main") | |
| repo | Yes | Repository as owner/name |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of disclosing tool behavior. It adds useful context about deploy authorization but does not explicitly mention read-only nature, failure modes, or permissions, leaving gaps in transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, with the purpose front-loaded and a critical usage directive appended. Every word earns its place; no redundancy or fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 2-parameter tool with no output schema, the description conveys purpose, usage context, and the result type (concrete commit SHA). It lacks error behavior details or explicit read-only confirmation, but those are reasonable omissions for such a simple tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already describes both parameters with 100% coverage. The description does not add new semantic details about parameters beyond the schema, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Resolve') with a clear resource ('a branch, tag or commit to a concrete commit SHA'). This directly conveys the tool's function and distinguishes it from sibling tools like list_deployments or deploy.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly instructs 'Call this BEFORE deploying' and explains the reasoning (deploy is authorised for one specific commit). This provides a clear when-to-use directive, even though no alternative tools are named.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
5 tool updates
v0.1.0- First observed
deploy - First observed
get_deployment - First observed
list_deployments - First observed
list_environments - First observed
resolve_ref
TDQS
Each tool has a clearly distinct purpose: resolving a ref, listing deployments, getting a specific deployment, listing environments, and triggering a deploy. There is no overlap or ambiguity between the tools.
Most tools follow a verb_noun pattern (resolve_ref, list_deployments, get_deployment, list_environments). 'deploy' is a single verb, which is a minor deviation but still understandable and consistent in style.
The five tools are well-scoped for a deployment-focused server. Each tool covers a necessary part of the deployment workflow without being overly granular or redundant.
The core deployment lifecycle is covered: resolving a commit, deploying, listing, and getting deployments. Missing features like cancellation or rollback are minor gaps that do not critically hinder the main workflow.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
AI agent infrastructure for discovery, authorization, execution, identity, and signed receipts.
Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Plan Salesforce deploys, open pull requests and trigger pipelines from your AI client.
Related MCP Servers
- AlicenseAqualityNot gradedmaintenanceConnects AI assistants to GitHub Actions workflows to monitor CI/CD pipelines, view run logs, diagnose failures, and optionally trigger or manage workflows with granular permission controls.101-
- AlicenseAqualityAmaintenanceEnables AI coding agents to orchestrate the full software development lifecycle on GitHub, including planning, issue creation, code review, security triage, and release readiness checks.131151MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to securely perform privileged actions like creating GitHub issues by minting short-lived, single-purpose tokens on demand, with policy enforcement and audit logging.MIT
- FlicenseNot gradedqualityBmaintenanceEnables AI assistants to interact with GitHub issues, pull requests, and Actions workflows through MCP tools.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/humanagencyprotocol/hap-deploy-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server