Is Operator MCP my customer-facing MCP?
No. Operator MCP belongs only to KE. The customer-facing paid product is KE Connector.
The paid customer product is KE Connector: buy Credits and run released KE tools. The internal one is KE Operator MCP: KE uses it, customers never do. The other two are a public menu and a server the customer already owns.
You do not need to understand the protocol to choose correctly. Match what you want to do with one of these four cards.
The public menu
Your own connection
The paid KE product
KE internal only
KE Connector is like ordering from a protected workshop. The customer chooses an approved job, prepays with Credits, and receives the result plus a receipt. KE keeps the provider account, private methods, prompts, source, routing, and internal Brain behind the wall.
The customer chooses from a fixed list. They cannot supply an arbitrary provider, model, URL, file path, or hidden prompt.
The spend key, customer account, wallet, and available Credits must all belong to the same person.
KE calculates the safe ceiling before work starts. If price or funding cannot be proven, the request stops.
KE runs the provider privately, charges only verified actual use, releases the unused reserve, and returns a bounded result.
No. Operator MCP belongs only to KE. The customer-facing paid product is KE Connector.
They never receive the account or key. If a released KE capability uses Replicate behind the scenes, KE makes that call privately and returns only the customer's result and receipt.
No. API-only KE Connector customers need funded Credits, not a Platform subscription. Private Platform apps use membership, which includes 50 Credits per verified paid period.
No. Payment buys permission to use a released capability and receive its result. It never transfers KE Brain, prompts, skills, source, routing, evaluations, provider credentials, or another customer's data.
The same four answers stay visible in every chapter: Discovery is the menu. Customer-direct is yours. Connector is the paid KE product. Operator is private to KE. Use arrow keys, the chapter controls, or swipe.
If the plain answer was enough, you can stop there. Developers and security reviewers can open the exact request path below—from the client through payment, private execution, result checks, and receipt.
The host runs the agent experience. It does not inherit tool authority merely because it can speak MCP.
The public menu. Anyone can see which KE tools exist, but this route cannot run them or charge anyone.
A server you or another provider owns. You connect to it directly; KE does not relay it, control it, or bill for it.
The paid KE product. Customers buy Credits to run released KE capabilities and receive results. No Platform subscription is required.
KE's private internal control connection. William and KE-controlled systems may use it; customers cannot connect to it or buy it.
Every missing proof closes the path before the next costly step.
Exact path, host, Origin, content type, size, protocol, and query rules are checked before JSON-RPC dispatch.
The bearer spend key resolves to one stable account. Possession alone is insufficient; wallet, key, and authenticated owner must be the same user.
The exact fixed capability, Connector scope, economics, and runtime release must be provable. Missing release or schema proof fails closed.
DLP, canary, composite decoding, and abuse admission reject extraction probes before a wallet hold or provider call.
A server-owned current quote reserves the maximum KE Credit debit, proves processor-net prepaid economic coverage, and admits the renewable provider-cost window before dispatch.
The fixed capability and provider-attempt identity are journaled before at-most-once external work can begin.
Generated, built, stored, and replayed results are scanned. Unsafe material is withheld, never returned as a paid result.
Actual usage settles exactly. Exact retries replay; ambiguous provider work is reconciled without blind retry or automatic refund.
Customer-bound · entitlement-filtered · hash-bound · size-bounded
Portable notes, preferences, artifacts, and project context are bound to the exact customer before projection.
Doctrine, prompts, skills, routing, evaluations, incident knowledge, and economics may influence a result but never enter a customer pack.
Each KE product retains its records, capabilities, releases, APIs, and failure boundary instead of becoming one universal database.
“MCP” describes how a host and server exchange typed tool messages. It does not tell you who owns the endpoint, credentials, bill, context, provider relationship, output, or authority. This table does.
| Boundary | 01 · Discovery | 02 · Customer-direct | 03 · KE Connector | 04 · Operator |
|---|---|---|---|---|
| What it is | Public metadata record | Another owner's MCP server | KE customer MCP server | KE private operator server |
| Who can connect | Anyone | The owner's allowed clients | Authenticated funded customer | KE-controlled local workloads |
| Transport | HTTPS GET | Owner-defined | Streamable HTTP MCP | Local stdio only |
| Credential | None | Customer/provider credential | Scoped KE spend key | KE process identity |
| Who pays | Nobody | Customer pays that owner | Exact funded KE Credits | KE internal operating cost |
| What executes | Nothing | Owner's tools | Fixed released KE tools | Fixed private read-only boundary tools |
| Context | Public cards only | Customer/provider contract | Customer-bound projection + server-only KE logic | Private KE context |
| Authority | None | Defined by that product | Invocation only; consequential authority remains separate | Observe-only; no customer authority |
| What leaves | Public metadata | Owner-defined result | Bounded result + billing receipt | Private bounded receipt |
| KE implementation | Never | Not in KE's path | Never transferred by payment | Never publicly discoverable |
A paid Connector account licenses bounded invocation and delivery of the customer's result. It does not sell an upstream provider account, the private Operator MCP, the KE Brain Kernel, or the machinery that produced the result.
Direct extraction attempts are refused before provider work or charge. Output is checked again before response, persistence, and replay. Privacy-safe abuse receipts support velocity limits, temporary suspension, review, and key revocation without storing raw probes.
These IDs are public contracts, not a generic proxy. Availability is still controlled by fixed scope, funded Credits, economics, provider, and release gates.
No arbitrary URL · provider · model · system prompt · file · filesystem path · private resource · generic tool name
These adjacent systems do the jobs people often—and incorrectly—assign to MCP itself. Keeping them separate is what makes the connector portable without making it unsafe.
Answers who the actor is. A model, runtime, session, and Agent identity are not interchangeable.
Separates private Platform membership from the API-only Connector and proves which fixed capability is actually released.
Answers whether processor-net funded value can reserve and settle variable work without exposing KE to uncovered provider cost.
Answers which knowledge can be projected, which can influence only a derived result, and which must remain server-only.
Define fixed schemas, artifacts, limits, side effects, release state, idempotency, and evidence for each tool.
Answers whether a consequential side effect has explicit authority and budget. MCP connection is never approval.
Records whether external work may have started so retries, reversals, and reconciliation remain economically safe.
Turns bounded receipts into human-visible operating evidence without exposing prompts, credentials, or private topology.
Public metadata remains easy to inspect. Executable routes fail closed with explicit status and error classes before tool dispatch or spend whenever identity, entitlement, security, or lifecycle proof is absent.
https://kestudios.dev/api/v1/mcpGET returns discovery. POST returns 410 before JSON-RPC parsing.
https://kestudios.dev/api/v1/ke/mcpBearer spend key, same-user ownership, Connector scope, verified funded Credits, prepaid economic coverage, and capability release all remain required. No Platform subscription is required.
No shared KE URLCustomer-direct endpoints belong to their owner. Operator MCP has no public listener or paid bridge.
POST to the discovery route never reaches JSON-RPC dispatch.
Missing, malformed, suspended, or unscoped spend authority.
Origin, Connector scope, capability release, or same-user proof does not pass.
An unrecognized or inconsistent request host is rejected.
Privacy-safe abuse velocity or a canary signal pauses the user/key with Retry-After.
Wallet, funding evidence, lifecycle, current economics, or abuse-journal truth cannot be established.
Do not replay or auto-refund work that may have crossed the provider boundary; reconcile it.
KE Connector is the portable customer product. KE Brain provides bounded context. KE Desktop is an optional first-party client. The private Operator MCP remains inside KE.