tilaCAUTION
Durable state and artifact storage for multi-machine agentic work. Content-addressed artifacts, schema-validated records, first-writer-wins coordination. Cloudflare-native or local.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Durable state and artifact storage for multi-machine agentic work.
Content-addressed artifacts outside your git repo. Schema-validated records. Coordination primitives that prevent races.
Deploy to your own Cloudflare account, or run locally with zero infrastructure.
Status: v0.3.0 — see the latest published release. APIs may change before v1.0. Upgrading from v0.2.x requires coordinated client/Worker updates; read the upgrade notes before deploying.
Direction: tila is evolving into one development-management product around this coordination core: an orchestrator with workers across Mac/Linux hosts, then native Mac/iPhone clients. Cloudflare will be the shared backend and project keys the supported auth path. These are planned changes; the current release still includes local persistence and GitHub auth. See the roadmap for the first milestone and runtime evaluation.
For: framework authors, AI autopilot builders, and small teams (3 to 6 engineers) whose agents need shared state across multiple machines.
Contents
- Why tila exists
- What it looks like
- Self-hosted
- When you need tila
- Quick start
- For AI coding agents
- Monorepo packages
- Related projects
- Contributing
- FAQ
🪨 Why tila exists
Agent-produced artifacts (plans, designs, analysis reports, build outputs) pile up fast. Commit them to your repo and they rot in context: coding agents waste tokens parsing stale intermediate files, and your git history fills with noise no human reviews. Gitignore them and they vanish on clone, can't be shared across machines, and agents lose access on context switch. A separate repo jus
a3fcaa80f023OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tila-mcp-server -- npx -y tila-mcp-server@None
Exposed tools (107)
82 read · 19 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ack | read | Acknowledge this participant |
add | write | Add a relationship between artifacts |
add-entry | write | Add an entry to an index |
admin | read | Manage project admin roster |
apply | write | Apply schema changes |
archive | read | Archive a record |
artifact | read | Manage artifacts |
artifact-ref | read | Manage entity-artifact references |
artifacts | write | Artifact upload (no claim; sizes round-robin), metadata read-back, and a periodic kind-filtered list. The embedded tier writes text blobs via writeText. |
auth | read | Manage tila authentication (instances, tokens, status) |
cancel | read | Cancel a pending gate |
cat | read | Read artifact text to stdout |
claim | read | Claim a task |
claims-contended | read | Participants contend for one or more hot resources: acquire, hold, release. Reports conflicts, takeovers and fence monotonicity. |
claims-uncontended | read | Per-participant resource: acquire (exclusive), renew x3, release. No contention; pure claim-path cost. |
close | read | Close a task |
cold-start | write | POST /admin/restart to evict the DO, then time the first summary read (cold) and three more (warm after restart). |
complete | read | Generate bash, zsh, fish or powershell completion scripts |
config | read | View project configuration |
configure | read | Configure a custom domain for the tila Worker |
create | write | Create a gate on a resource |
delete | destructive | Delete a signal group (admin) |
deploy | write | Deploy Worker and UI to Cloudflare via wrangler. Exit codes: 0 success, 1 deploy failed. |
destroy | destructive | Destroy a tila project and its resources |
diff | read | Preview schema changes without applying |
disconnect | destructive | Remove local credentials (keep project config) |
doctor | read | Check project health |
entity | read | Deprecated alias for |
export | write | Create a complete checksummed project backup |
fenced-writes | read | Fenced task updates (owner-mode claims) with a thief forcing stale-fence retries, or CAS record writes between paired participants. |
forget | read | Alias for |
gate | read | Manage coordination gates |
get | read | Download an artifact |
grant | read | Grant admin access to a GitHub user |
grep | read | Search artifact content by exact substring or bounded regex. Prints key:line: text per matching line. col is a character offset (ASCII-accurate); not a raw-byte offset. |
group | read | Groups |
heartbeat | write | Send a participant heartbeat |
history | read | List artifact revisions |
import | write | Restore a complete project backup |
inbox | read | Show this participant |
index | read | Manage index artifacts |
infra | read | Manage account-level tila infrastructure |
init | read | Join an existing tila project |
inspect | read | Show effective identity, role, capabilities, and restrictions |
instances | read | Manage registered tila instances |
instantiate | write | Instantiate a template to create entities |
issue | read | Issue a new API token |
journal | read | Query the project journal |
journal-replay | read | Writers append journal rows via claim cycles while readers page the journal with replay cursors and acknowledge progress. |
latest | read | Get the latest artifact of a given kind for a resource |
lifecycle | read | Configure and inspect coding-session lifecycle integration |
link | read | Register and trust a tila instance, storing a credential in the keychain |
list | read | List active project admins |
list-entries | read | List entries in an index |
mcp | read | MCP server configuration |
migrate | read | Eagerly promote legacy .tila/.env / .tila/.session credentials into the ~/.tila store |
new | write | Create a new task |
open | read | Open the tila dashboard in your browser |
patch | write | Patch a record (JSON Merge Patch) |
presence | read | Manage agent presence |
presence-signals | read | Presence heartbeat, then a participant-targeted signal to a random peer, then inbox read and acknowledgement of every pending bench signal. |
project | read | Manage tila projects |
provision | read | Provision account-level infrastructure (D1, R2, Worker, GitHub App) |
put | write | Upload an artifact |
ready | read | List tasks with no open blockers |
record | read | Manage typed records |
recover | read | Regenerate the DPoP keypair and re-bind to a fresh session (use after a lost or corrupted private key) |
register | read | Register the configured GitHub repo in the project allowlist |
reindex | write | Trigger a batched FTS reindex for artifacts, entities, or both |
rel | read | Manage artifact relationships |
relationship | read | Manage task relationships (alias: rel) |
release | read | Release a task claim |
remove | destructive | Remove a registered instance (removes registry entry and keychain secrets) |
renew | read | Renew a task claim |
repos | read | Manage the GitHub repo allowlist |
reset | destructive | Reset all project data |
resolve | read | Resolve a pending gate |
restore | read | Append a revision from an existing artifact |
review | read | Record an explicit artifact review (a hash does not establish trust) |
reviews | read | Read artifact review history |
revoke | destructive | Revoke admin access from a GitHub user |
rotate | read | Rotate a scoped credential without changing its principal |
schema | read | Manage project schema |
search | read | Full-text search across indexed artifacts |
send | write | Send a signal to typed recipients |
service-account | read | Manage project service identities and workload bindings |
set | write | Set a config value (writes to .tila/config.toml) |
shell | read | Spawn a sub-shell pinned to an instance (per-shell isolation; use |
show | read | Show current schema |
signal | read | Signal parity trial |
sprint | read | A task with one subtask |
state | read | Show claim state |
status | read | Show all registered instances, trust, expiry, and which resolves here |
summary | read | Show project summary |
switch | read | Switch the active tila instance (process-global; use |
tail | read | Show recent journal events |
task | read | Manage tasks |
teardown | read | Tear down account-level tila infrastructure |
template | read | Manage entity templates |
test | read | test |
token | read | Emit the resolved bearer token to stdout (credential-helper mode) |
tree | read | Show task tree view |
types | read | List record types |
unarchive | read | Unarchive a record |
update | write | Update a task field |
work-unit | read | Deprecated alias for |
write | write | Write text content as an artifact |
Trust audit
CAUTIONgrade F · trust 45/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
token: "ghu_test_access_token",
token: "auto-discovery-leg-tok",
const token = "runtime-artifact-token";
TOKEN="tila_dev_token_localonly"
TOKEN="tila_dev_token_localonly"
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
pem: "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----",
pem: "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----",
delete, destroy, disconnect, remove, reset, revoke
.gitleaks.toml
.gitleaksignore
.graphifyignore
.mcp.json.example
.mergify.yml
exec(statement: string, ...bindings: unknown[]) {exec(statement: string, ..._bindings: unknown[]): SqlExecResult {exec(statement: string, ...bindings: unknown[]): SqlExecResult {exec(statement: string, ..._bindings: unknown[]): SqlExecResult {exec(statement: string, ...bindings: unknown[]) {} from "../../packages/cli/src/commands/signal";
} from "../../packages/cli/src/lib/output";
} from "../../packages/cli/src/commands/signal";
} from "../../packages/cli/src/commands/signal";
Gates applied: no_behavioural_pass.
a3fcaa80f023full audit observations/trust-audit/mcp-server/davebream__tila.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a3fcaa80f023 | CAUTION | F | 45 | first audit |
Questions
What is the tila MCP server?
Durable state and artifact storage for multi-machine agentic work. Content-addressed artifacts, schema-validated records, first-writer-wins coordination. Cloudflare-native or local.
What tools does tila expose?
107 in total: 82 read-only, 19 that write, and 6 that can delete or overwrite (delete, destroy, disconnect, remove, reset). Every one is listed on this page with its risk.
Is tila safe to connect to an agent?
With care. The audit graded it F (45/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does tila need?
It reads ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, CLOUDFLARE_API_TOKEN, GH_TOKEN, GITHUB_TOKEN, INFRA_ADMIN_TOKEN, TILA_API_TOKEN, TILA_LIFECYCLE_KEY, TILA_READ_TOKEN and TILA_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does tila run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tila/worker at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (a3fcaa80f023), read on 2026-10-08. The repository is watched and re-audited when it changes.