Nacre

Nacre playground

A self-hosted knowledge index with fine-grained access control. Two ways in: sign into the demo company and see the permission model from the inside, or take an organization of your own for 24 hours.

The demo company

Three people, three different answers to one question. Sign in at https://playground.nacre.work with organization demo and search for “what is the contract number for Northwind”.

Sign in asPasswordCan read
engineer@demo.nacre.workquartz-shale-clover-marlin-cinder-ember-88handbook, engineering
contractor@demo.nacre.workbramble-aurora-bloom-fathom-opal-pillar-54handbook

Neither finds the contract number. Not a shorter list of results — nothing at all, because the permission filter runs inside the index traversal, so their search never reached the document. Both hold read and nothing else, which is why these credentials can be printed on a public page.

An organization of your own

Administrator access to a real organization: create layers, grant access, ingest documents, connect an MCP client. It is erased 24 hours later, along with everything in it.

No email address is asked for and none is stored. The password below is shown once and kept nowhere — if you lose it, take another organization.

Limits: 200 documents, 500 searches a day. No object storage on this stand, so PDF upload is refused — text and URLs work.

Connect an agent

MCP over Streamable HTTP, one endpoint:

https://playground.nacre.work/mcp

Point any MCP client at it. Authorization is OAuth and the client discovers the rest for itself: the first call comes back 401 naming the RFC 9728 document, and the client walks from there to registration, to a consent screen in your browser, to a token. With Claude Code that is one command:

claude mcp add --transport http nacre https://playground.nacre.work/mcp

Six tools: search, list_layers, get_document, ingest_status, ingest_document, delete_document. What they return is bounded by whoever approved the connection — and when you approve it you choose a ceiling: which layers, and whether the client may write at all. A search client that cannot delete a document is the default, not a setting you have to find.

Or watch one get refused, here in this browser — a real agent connected to this stand over MCP, with the tool calls and what came back. Your own key, or a small model that runs on your GPU.

Or call the API

Same permissions, same answers, at https://playground.nacre.work/v1. Sign in for a token, then search:

TOKEN=$(curl -s https://playground.nacre.work/v1/auth/login \
  -H 'content-type: application/json' \
  -d '{"email":"…","password":"…","organization":"demo"}' \
  | jq -r .access_token)

curl -s https://playground.nacre.work/v1/search \
  -H "authorization: Bearer $TOKEN" \
  -H 'content-type: application/json' \
  -d '{"query":"how do I expense a laptop","top_k":3}'

Use one of the demo logins above and you will get the handbook back and never contracts — the same result the console gives, because it is the same authorization service answering. organization may be omitted where the address matches exactly one account; it is a lookup key, never a claim, and the organization in the token always comes from the row that authenticated.

The whole contract is docs/openapi.yaml, and there is a tool reference beside it. npm i -g @nacre.work/cli wraps both: nacre login, nacre ingest, nacre search.