The tool runtime's own client, mesh serve, started by the mesh on the credential it sealed to the machine (novox/hq ADR 0152, design 34): invokes every tool, listens from the machine only, holds no state. Checked with module check before it was ever registered (hq issue 148).
mesh-console
The mesh's tools, on the machine a person sits at, served by a module the mesh assigned there (novox/hq ADR 0152, design 34).
Assign it to a machine and an agent on that machine has the mesh's tools at
http://127.0.0.1:<port>/mcp — MCP over HTTP, initialize, tools/list, tools/call. A person at
a terminal reaches the same endpoint with mesh tools --console http://127.0.0.1:<port> and
mesh call <module>.<tool> --console …, with no credential of their own: the console holds it.
What it is
The tool runtime's own client, mesh serve, started by the mesh on the credential it sealed to the
machine for <node>.mesh-console. The manifest says three things nothing else in the catalogue says
together:
invokes: ["*"]— it calls every tool on the mesh, and the bus grants exactly that publish side;- a listener
from: machine— loopback only, and the filter opens nothing for it; - no
emits, noconsumes, notools— nothing on the bus can address it.
Loopback is the authority boundary. Whoever can connect is on the machine, and whoever is on the
machine is the account that owns the mesh there (ADR 0034, ADR 0144). There is no token and no login,
and mesh serve refuses to bind anything but a loopback address.
What it lists
What the running modules answer: every tool runtime serves a tools verb for its module, and the
console asks the catalogue which modules the mesh holds and each module what it serves. A module that
did not answer — not assigned, not up, or built before the runtime answered tools — is named in the
list's _meta.notAnswering and can still be called by <module>.<tool>.
The mesh's own verbs (status, push, assign) are the mesh-controller seat's tools under
ADR 0132 and are not served on the bus yet; they appear here when they are.
Port
The manifest declares port 4270 and the mesh assigns the machine port as it does for any listener;
the console binds 127.0.0.1:${port:4270}. node show <machine> says which port a machine was given.