mend.rest

BETA trust & repair
Status  Development instance. The official benchmark held-out execution is BLOCKED pending independent steward isolation. Nothing on this site is a production claim or an assurance claim, and a deployed instance is still an unclaimed dev instance.

Get an API key, connect your harness, and start appraising work.

mend.rest is a standalone service. Sign up, open the link it emails you, copy one line into Claude Code or any MCP client, and the mend.* methods are available to your orchestrator. No sales call, no onboarding, no second credential.

Get your API key Read the integration doc No password. One key, shown once. Free while this is a dev instance.
1 Sign up, then open the link An email address and, if this instance is invite-only, a code. The platform mails that address a confirmation link; opening it is what issues the account's one API key, displayed exactly once — mend_live_… — and that key is your account. Sign up →
2 Copy the config The page that link opens hands you a ready-to-paste line with your key already in it, plus generic MCP JSON and a raw curl. One credential covers all three. See the blocks →
3 Connect your harness Run the line. Your client discovers the tools, and every call carries your key as a bearer. Read the receipts back on this site, or verify them offline without it. Read receipts →

Contact

Who builds this, and how to reach him.

Who builds thismend.rest is built by not.rest.
Emaildo@not.rest — bug reports, a verdict that looks wrong, and questions about what this service does or does not claim all go to the same place. There is no support desk, no ticket system and no queue position — mail reaches the person who runs the instance, and he answers it himself when he gets to it.

What this is

mend.rest is a declared, hosted trust-and-repair agent system. An orchestrator delegates a unit of work; mend.rest appraises what came back, hands the orchestrator bounded repair when the work falls short, and emits a reproducible report of what it observed — including, explicitly, what it could not observe.

"Declared" is the load-bearing word. Every surface states its own agency, its allowed effects, its budgets, and its non-capabilities up front, and is then held to them. The product is not the verdict. The product is the evidence behind the verdict, in a form you can re-check without trusting this website.

The loop

Four moves, each leaving a receipt. The system's authority to act ends where its evidence ends.

AppraiseA submitted claim of done-ness is graded against the commission's scope, budgets, and prohibited effects. The disposition is one of PASS UNKNOWN REPAIR_REQUIRED BLOCKED.
RepairA shortfall produces a bounded repair node the orchestrator fetches and acknowledges. Attempts are counted against the commission's budget. mend.rest does not perform the work; it names what is missing.
ReportA deterministic projection of report-safe facts — timeline, coverage, named gaps, claims and their evidence, scope and budget, roots and witnesses — reduced to one fact_digest.
GovernExport and deletion are first-class methods with their own receipts. A deletion receipt names its own limitations rather than claiming completeness it cannot deliver.

The honesty colouring

The same three-colour law runs through every surface here. It is the brand, and it is not decorative.

greenReceipt-backed and verified. Used only where a receipt exists and its pin is a real proof pin — never for a PASS that rests on a simulation pin.
amberAttention, unverified, unknown, or absent. Absence is never red — a missing receipt means unobserved, not didn't-happen. An error of observation (a refused credential, a timeout) is also amber: it means we could not learn.
redRefuted, failed, tampered, or BLOCKED. Only ever a verdict about the work — never a verdict about our ability to look at it.
Inherited from the ledger surface in assets/surfaces-ledger/, which renders no verdict it cannot support. This portal keeps that rule and adds one: the distinction between "we looked and it failed" and "we could not look" is never collapsed.

Where to go

Sign upEmail, optional invite code, one API key shown exactly once. No password and no confirmation mail — the key is the account.
ConnectThe integration document: the Claude Code line, generic MCP JSON, raw JSON-RPC, where mcp_server.py comes from, and all 14 mend.* methods.
DashboardPaste your key to see the account it belongs to, list keys, issue another, revoke one. The key is the session; nothing is stored on this site.
ReportsThe receipts river. Read your own task reports and verdict receipts in the browser with the same key. Nothing is stored on this site.
VerifyHow to check a report offline, against the open verifier, without trusting this site or its API.
APIPOST https://api.mend.rest/rpc — JSON-RPC 2.0, Authorization: Bearer, 14 mend.* methods. Health at GET /healthz. Accounts and keys at /v1/*.
What this instance does not claim

Donate

Contributions expand the compute nodes this development instance runs on. That is the whole of what the money does.

What it pays forCompute for the nodes serving this instance. A contribution is not a purchase: it buys no support relationship, no priority, no influence over what gets built, and no commitment about what this service will do next.
What this is notThis is not a nonprofit or a foundation, contributions are not tax-deductible, and there is no refund process. If any of that matters to you, the right answer is not to donate.
Where you landStripe’s own hosted checkout page, on Stripe’s domain, in a new tab. Card details are entered there and never on this site, which collects no payment information of any kind.