For judges — Unsay in thirty seconds

An MCP server whose resources can be revised mid-sentence — so an assistant can stop, retract what it just said, and name what changed, who changed it, and how long ago.

No account, no clone, no key. Everything on this page is live at api.unsay.edycu.dev/judge and answers without a token.


The thirty-second path

Rather watch first? The 2:49 demo video films this path, then the protocol under it.

  1. Open the landing page, api.unsay.edycu.dev/. It mints its own demo tokens; you do not need one.
  2. From it, open The Echo Show screen and The clinician write screen side by side.
  3. On the clinician screen, type a new weight-bearing instruction and publish it.
  4. Watch the Echo Show: the line it was speaking strikes through, the new one replaces it, and the provenance line names the physio and how long ago the change was made.
  5. Open api.unsay.edycu.dev/verify — the public receipt. Every resource's version chain, its hash, and whether it is intact, with no token.

Nothing there is a recording. The deployment is one in-memory process, so a revision you publish is real for everyone until the next restart resets it to the seed.

The receipts

WhatNumberWhere it was written
Retraction lands inside the speech window, over the public internet200/200, end-to-end p95 461 msdocs/proof/bench.remote.txt
Safety assertions that MUST fail, and do34/34 (15 in-process, 19 over HTTP)docs/proof/verify.json
Test suite345 passing, tsc --strict cleannpm test · npm run typecheck
Real protocol frames of the whole demoone JSONL line per framedocs/proof/live_run.jsonl
A correction survives the connection dropping under itresumed with Last-Event-IDdocs/proof/resume.json

The 3,400 ms speech window is an assumed speech rate, not a measurement of Alexa+ TTS, and the bench says so on every run.

Reproduce it

The real path, against the real server, with no flags:

git clone https://github.com/edycutjong/unsay.git && cd unsay
npm install
npm run verify     # the reads and writes that MUST fail, do
npm run e2e        # the whole demo, as code, over Streamable HTTP
npm run bench -- --n 200 --url https://api.unsay.edycu.dev

There is no offline mode to confuse with the product. npm test needs no credentials because nothing Unsay does needs one — the server it tests is the server that is deployed.

Where to look first

  1. packages/live-resources/src/store.ts read() — the enforcement point. The audience split is two URI schemes behind two OAuth scopes, enforced here, not trusted to the host.
  2. FRICTION.md F-002 — why annotations.audience alone could not be the control.
  3. DEMO.md — every command above, verbatim from an empty clone, and what each proves.

Honest limitations

Rendered from JUDGE.md in the repository. Source as text: /JUDGE.md.