Back to overview

AI Keyholder (MCP)

The AI keyholder is an AI assistant that reads the state of your chastity session via the Model Context Protocol (MCP) and issues directives within human-defined free-text rules. It serves two situations of equal standing: relieving a human keyholder who hands off the routine work — and acting as a virtual keyholder for a sub without a human keyholder, who connects the AI themselves and gives it their own rules. The function is opt-in, off by default, and intended above all for self-hosting.

Who this is for

The AI keyholder fits two situations that stand side by side as equals.

With a human keyholder: the keyholder stays responsible but hands the routine to the AI. It reads the state, keeps to the keyholder's free-text rules, and issues directives — even when the keyholder has no time right now.

Without a keyholder (solo sub): if you have no human keyholder, you can connect the AI as your keyholder yourself. You store your own rules, and the AI takes on the keyholder function — structure, directives, and consequences — according to the rules you set for yourself. This gives even you, without a partner, reliable control and commitment.

How it works

The flow is the same for every directive and stays traceable. The AI reads the current state via MCP — lock status, wear time, open inspections, training goals, offence record. It compares that state against the stored free-text rules and, within that frame, decides on a directive, such as a lock period, an inspection, or a verdict.

The rules always stay in human hands — either your keyholder's or the ones you set for yourself. The AI does not invent its own requirements. Every action is fully audited and lands in the action log, so you can trace afterwards why it happened. You can always log in and intervene yourself.

Activating

The AI keyholder is opt-in and off by default; it has to be enabled per instance.

When self-hosting, you set the activation yourself through your instance's environment variables (ENABLE_MCP=true plus the setting for which user is managed) and restart the container.

If your instance runs on the portal, you cannot set these variables yourself. Request activation by e-mail to info@trublue.ch, stating which instance or subdomain is affected and which user should be managed.

Set the rules first

Before the AI acts for the first time, set its rules. In the admin area, open the settings of the relevant user and fill in the "AI keyholder rules (MCP)" field in plain language — for example "at least 12 h between two openings", "no inspections at night", or "if a photo proof is late, extend by no more than 24 h".

The AI reads these rules fresh with every action and follows them. They are deliberately soft guidance, not a hard lock — you keep control and can always log in and intervene yourself. In solo operation they are your own rules; with a human keyholder they are theirs.

Connecting

To connect, add a custom connector under the settings of an MCP-capable AI client — for example Claude in the browser, as a desktop or mobile app. Enter your instance with the path /api/mcp as the server URL, i.e. https://<your-instance>/api/mcp.

Sign-in runs via OAuth: the login page of your own instance opens, and you don't need to copy a token or password. If you sign in with an admin account, the AI may write and act as a keyholder; with a normal account it can only read.

Responsibility stays human

The AI keyholder is intended above all for self-hosting, where you run your own container and control the configuration. It is opt-in and stays off until you deliberately enable it. Whether with a human keyholder or solo, the rules — and with them the responsibility — stay human; the AI only carries them out in a traceable way.