Nacre playground
A self-hosted knowledge index with fine-grained access control. Two ways in: sign into the demo company and see the permission model from the inside, or take an organization of your own for 24 hours.
The demo company
Three people, three different answers to one question. Sign in at
https://playground.nacre.work with organization
demo and search for
“what is the contract number for Northwind”.
| Sign in as | Password | Can read |
|---|---|---|
engineer@demo.nacre.work | quartz-shale-clover-marlin-cinder-ember-88 | handbook, engineering |
contractor@demo.nacre.work | bramble-aurora-bloom-fathom-opal-pillar-54 | handbook |
Neither finds the contract number. Not a shorter list of results — nothing
at all, because the permission filter runs inside the index traversal, so
their search never reached the document. Both hold read and nothing
else, which is why these credentials can be printed on a public page.
An organization of your own
Administrator access to a real organization: create layers, grant access, ingest documents, connect an MCP client. It is erased 24 hours later, along with everything in it.
No email address is asked for and none is stored. The password below is shown once and kept nowhere — if you lose it, take another organization.
Limits: 200 documents, 500 searches a day. No object storage on this stand, so PDF upload is refused — text and URLs work.
Connect an agent
MCP over Streamable HTTP, one endpoint:
https://playground.nacre.work/mcp
Point any MCP client at it. Authorization is OAuth and the client discovers
the rest for itself: the first call comes back 401 naming the
RFC 9728 document, and the client walks from there to registration, to a
consent screen in your browser, to a token. With Claude Code that is one
command:
claude mcp add --transport http nacre https://playground.nacre.work/mcpSix tools: search, list_layers, get_document, ingest_status, ingest_document, delete_document.
What they return is bounded by whoever approved
the connection — and when you approve it you choose a
ceiling: which layers, and whether the client may write at all.
A search client that cannot delete a document is the default, not a setting you
have to find.
Or watch one get refused, here in this browser — a real agent connected to this stand over MCP, with the tool calls and what came back. Your own key, or a small model that runs on your GPU.
Or call the API
Same permissions, same answers, at
https://playground.nacre.work/v1. Sign in for a token, then
search:
TOKEN=$(curl -s https://playground.nacre.work/v1/auth/login \
-H 'content-type: application/json' \
-d '{"email":"…","password":"…","organization":"demo"}' \
| jq -r .access_token)
curl -s https://playground.nacre.work/v1/search \
-H "authorization: Bearer $TOKEN" \
-H 'content-type: application/json' \
-d '{"query":"how do I expense a laptop","top_k":3}'Use one of the demo logins above and you will get the handbook back and never
contracts — the same result the console gives, because it is
the same authorization service answering. organization may be
omitted where the address matches exactly one account; it is a lookup key, never
a claim, and the organization in the token always comes from the row that
authenticated.
The whole contract is
docs/openapi.yaml,
and there is a tool
reference beside it. npm i -g @nacre.work/cli wraps both:
nacre login, nacre ingest, nacre search.