🤫husshhussh
🤫husshhusshOnePuppy

On this page

  • MCP & agents
  • OpenClaw/Hermes
  • Runtime modes
  • Consent flow
  • Scopes
  • MCP tools

MCP & AGENTS

Connect OpenClaw, Hermes, and any agent with hussh MCP.

Bring OpenClaw, Hermes Agent, or any external MCP agent to a user's One Personal Data. Discover available scopes, request explicit consent, then retrieve only the approved encrypted export. Trusted-device writes use a separate owner-authorized native path.

Install ClawHub pluginOpen @hushh/mcp
Loading developer workspace…

Three authentication paths

Use a self-serve developer token, OAuth authorization code with S256 PKCE, or an operations-provisioned partner service credential.

Encrypted exports

Ciphertext and wrapped-key metadata only; OpenClaw, Hermes, or your external connector decrypts client-side.

Dynamic scopes

Scopes are discovered per user from PKM metadata instead of hardcoded globally.

Zero-knowledge

The server stores encrypted personal data and enforces consent before access.

OPENCLAW / HERMES

One connection path for every external agent

OpenClaw and Hermes are first-class ways to connect outside agent infrastructure to One, but the protocol is not locked to either name. Any external MCP agent can follow the same steps: discover Personal Data scopes, ask for consent, wait for the user, then retrieve the approved encrypted export. Consent MCP does not grant write authority.

OpenClaw connector

Point OpenClaw at the remote MCP URL or REST API so it can discover a user's live One PKM scopes before any data moves.

Hermes Agent

Use Hermes as the consent messenger: every external tool call becomes a clear request inside One with purpose, scope, expiry, and receipt.

Any external agent

If you are not using OpenClaw or Hermes, follow the same contract directly from your agent host: discover, request, wait, then retrieve the encrypted scoped export.

NOW ON CLAWHUB

Install the Hushh One MCP plugin for OpenClaw.

The ClawHub package @hushh/one-mcp bundles the MCP config and OpenClaw skill guidance for Hussh One consent flows. It still requires a developer token and user-approved scopes before PKM data moves.

OpenClaw install

openclaw plugins install clawhub:@hushh/one-mcpView plugin listing

Direct setup steps

01

Mint a developer token and connect OpenClaw, Hermes Agent, or your own agent host through Remote MCP, REST, or the npm bridge.

02

Call search-user-scopes so the agent sees the user's current PKM scopes instead of guessing from a static menu.

03

Call request-consent with one discovered scope, a clear purpose, expiry, timeout, and connector key-wrapping metadata.

04

After approval, use the returned grant reference to retrieve the encrypted scoped export in your trusted connector process.

RUNTIME MODES

Three ways to integrate

Pick the host shape first. Remote MCP is the cleanest path for agent hosts, REST is the direct application contract, and the npm bridge keeps stdio-only clients on the same protocol.

Remote MCP

Authorization: Bearer <developer-token>

Use a bare HTTPS MCP URL and keep the developer token machine-local in the host secret store.

REST API

/api/v1

Use versioned endpoints for scope discovery, consent requests, status checks, and encrypted scoped exports.

npm bridge

npx -y @hushh/mcp

Use the public launcher when an external agent still expects a local stdio process instead of remote MCP.

CONSENT FLOW

Discover, request, approve, export

01

Search available scopes

Call search-user-scopes with the person's identifier. Scopes are dynamic and come from their indexed PKM.

02

Request a specific scope

Ask for one discovered scope with a transparent purpose, expiry, timeout, and connector key-wrapping metadata.

03

Wait for approval

The user approves or denies inside the hussh surface. Poll only with the returned request_ref and interval.

04

Retrieve the approved export

Use grant_ref and expected_scope to retrieve the encrypted scoped export in a trusted connector process. There is no plaintext fallback.

SCOPE MODEL

Scopes are runtime facts, not a static menu

Always discover first. A broader active grant can satisfy a narrower request, but a narrower grant never silently upgrades to a broader parent scope.

attr.{domain_slug}.{scope_slug}.*

A dynamic semantic branch returned by per-user discovery. Do not hardcode a domain key.

cap.one.invoke

A reserved One task capability. It grants no user-data read or mutation authority by itself.

MCP TOOLS

The public consent tool surface

The integration snippets and tool names below are read from the live consent API. Authentication identifies your app; every user-data request still requires an explicit, time-limited consent grant.

Loading the live MCP contract…

Products

  • Agent One
  • The 🤫 One app
  • Puppy One
  • Which Puppy is right for you?
  • The Puppy 100
  • Tag One
  • The 🤫 Store
  • The 🤫 One Card
  • Pricing
  • Claim your One
  • The product roadmap

🤫 Yellow Pages

  • The 🤫 Yellow Pages
  • Discover in the feed
  • Find a local expert
  • Coverage & markets
  • Connect - in Agent One
  • Ping an expert

Business & Enterprise

  • 🤫 for Business
  • Small & medium business
  • 🤫 Concierge (VVIP)
  • 🤫 for the Enterprise
  • Industry solutions
  • Federal government & agencies
  • 🇺🇸 Defense & national security
  • For advisors (RIAs)
  • Partner Portal
  • One for Sellers
  • Developers

Watch, read & learn

  • The media library
  • The 🤫 Feed
  • See it in a minute
  • Listen - the podcasts
  • Blogs
  • The field guide - the book
  • Research & papers
  • Guides - by topic
  • Academy
  • Events & public assets
  • Wiki

Company & open

  • About
  • Team
  • Investors
  • Fund A
  • Building in the open
  • News & investor relations
  • Release notes
  • Careers
  • Contact
  • Explore - the whole site, mapped
  • Sitemap

Trust, rights & gratitude

  • The Hussh Protocol (PCHP)
  • Day 0 Trusted Circle
  • The case - a right, made enforceable
  • Data-rights landscape
  • Accessibility
  • 🤫 Champions of the Community
  • 🤫 Faculty - the professors
  • Gratitude - people we admire
  • The 1024 - humans of the world
  • Search every page
  • Browse (developer view)

🤫 Private Agent One is free for every American citizen. We do not sell your data, your attention, or your contacts.

Company and product names are used to describe interoperability only and do not imply affiliation or endorsement. Certifications described as “in pursuit” are not held today.

Copyright © 2026 Hushh Technologies Corporation. All rights reserved.

Privacy PolicyTerms of UseYour data rightsAccessibilitySite Map

🇺🇸United States

🤫husshhusshKirkland, WashingtonMore ways to reach us: talk to a human or find an agent near you.