Self-hosted permission-aware context layer. Search returns only what the caller may read.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Your index. Your access rules. Your perimeter.
Agents see exactly what they're allowed to see.
nacre.work Β· Docs Β· Quickstart Β· Discussions
Nacre is a self-hosted knowledge index with fine-grained access control. Agents reach it over MCP, applications over a REST API. No chat interface, no company assistant β just the context layer underneath them.
Vector search is a solved problem. What isn't solved: making sure an agent querying a company index sees exactly the documents the requesting user is cleared for β and being able to prove it to an auditor.
read/write/admin
inherited top-down. write does not imply read; admin implies both.
Document-level grants and deny rules are commercial β this build refuses them
and says so, rather than accepting a rule it cannot propagate.top_k returns k permitted results
rather than k minus whatever got stripped out.SQLSTATE 23505, an invoice
number or a variable name needs the literal match, and a dense-only index
does not reliably return it.npx @nacre.work/cli signs in, creates a layer,
walks a directory into it and searches β the four curl invocations the
quickstart spells out, for when you want the result rather than the contract.
A document that fails to index is a non-zero exit, so a nightly ingest cannot
report success having indexed nothing.Full walkthrough: docs/quickstart.md.
On an Apple Silicon Mac, read docs/apple-silicon.md first β the images are arm64 and the stack is native, but the embedder is the one piece you run on the host.
Early, and it runs. The loop works end to end and has been driven by hand
against a real PostgreSQL and a real Qdrant: create an organization, create a
layer, grant someone read, ingest a document, poll the job to indexed,
search and get the chunk back β and search as someone without the grant and get
nothing while the vectors are still sitting in the index. Both surfaces work,
REST and MCP over Streamable HTTP and STDIO alike. Revoking a grant removes the
document from results, and the recomputation that refreshes the index tags runs
in the worker with a metric on how far behind it is.
Search is rate limited per organization, unsafe methods take an
Idempotency-Key, collections page by cursor, and reranking runs on the search
path when a deployment configures a reranker. Tombstoned vectors are collected,
and the SDK and the admin UI are written.
Signing in works: email and password, with rotating refresh tokens that end the
session if one is replayed. init creates the first administrator and prints a
generated password once. SSO is a commercial module.
The access log is readable: GET /v1/audit, newest first, cursor-paged, as
JSON, JSONL or CSV. org_admin sees which documents were read β the question
an audit log exists to answer β and platform_admin sees administrative actions
and never that, which is rule 2 applied to the journal.
A layer can be moved onto a different embedding model. Qdrant will not add a named vector to a collection that exists, so the collection is replaced rather than altered: every point copied across with no embeddings computed, one statement to switch the pointer, then re-embedding one layer at a time. Search stays available and stays one query throughout. Before a layer switches, its reference query set is scored against the new model and a migration that lost recall stops instead of going live β that gate is off until you write a set, because it needs documents only you can pick.
A document can be uploaded as a form as well as sent as JSON, and a PDF is
extracted by the parser sidecar. Both signals have to agree β the part declares
application/pdf and the bytes begin with %PDF- β because a declared type the
bytes contradict is a disagreement, and sniffing alone would make the declared
type decoration. Any other binary format is still refused at the edge, and a
scanned PDF with no text layer is refused rather than indexed as nothing.
Tokens can be signed with an Ed25519 key instead of a shared secret, in which
case the public half is published at /.well-known/jwks.json and only the
process issuing tokens holds the private one.
docker compose --profile minimal up has been run from a clean clone, and
the whole loop driven through it.
What is not built is what a commercial licence covers, and docs/licensing.md
lists it: multi-tenancy, SSO, document-level permissions and deny rules,
ID-JAG, SIEM export, a global admin, quotas, and HA Helm charts.
docs/ is the specification, and it still runs ahead of the code in places β
start with docs/authz.md, which everything else depends on.
Six rules. Breaking any of them is a security incident, not a bug. Details in docs/authz.md.
write does not imply read.Apache 2.0 β all of it. Everything above is in this repository and stays there.
Multi-tenancy, SSO/SCIM, document-level deny rules, EMA, SIEM export, global admin and backup are commercial modules. They live in a separate private repository under a separate license and are not distributed with this one β see docs/licensing.md for the line between the two and the one question that decides it.
Where this build meets one of them it refuses in the open: a deny rule or a
document-scoped grant is answered 400 with the reason, rather than accepted
and silently not enforced.
The Nacre name and mark are trademarks; see TRADEMARK.md.
There is no hosted tier, no seat count and nothing metered here, so the open half earns nothing by being used β which is the point, and also why it is worth saying who pays for it. The commercial modules do, and they are for the organizations that need them; a developer running this on a laptop is never the person being asked.
If it saved you a week, the Sponsor button at the top of this repository is the other way to say so. Nothing in this repository is behind it, and nothing will be.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/nacre)<a href="https://allmcps.com/mcp/nacre"><img src="https://allmcps.com/api/badge/nacre?style=directory" alt="Nacre on AllMCPs" /></a>