Attestify OS
MCP stdio server for Attestify OS — governed agent execution and Attestify Trust signed evidence.
Open source Open in the app JSON README (API)
About
MCP stdio server for Attestify OS — governed agent execution and Attestify Trust signed evidence.
Details
- Kind
- MCP servers
- Topic
- No topic detected
- Publisher
- attestifyagent
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 0.2.1
- Last push
- 2026-08-28T11:26:59Z
- Repository state
- ativo
- Language
- JavaScript
- Added
- 2026-08-29 03:02:27
- Updated
- 2026-08-29 03:02:27
- Origin id
io.github.attestifyagent/attestify-mcp
README
# attestify-mcp
> MCP server exposing Attestify OS agents — and [Attestify Trust](https://attestifyos.com/trust)'s no-wallet agent identity + signed evidence — as callable tools for Claude Desktop, Cursor, Windsurf, and any MCP-compatible host.
Attestify OS is infrastructure for AI agents operating in financial, compliance, and regulated workflows. Every governed run delivers: routing → governance enforcement → budget check → SLA check → execution → output verification → immutable receipt → on-chain settlement evidence.
**Live base URL:** `https://attestifyos.com`
This package is a real [Model Context Protocol](https://modelcontextprotocol.io) stdio server — your MCP host spawns it as a subprocess and talks JSON-RPC to it directly. It is not a plain HTTP client library.
## Quick start
Add to your MCP host's config (e.g. Claude Desktop's `claude_desktop_config.json`):
```json
{
"mcpServers": {
"attestify": {
"command": "npx",
"args": ["-y", "attestify-mcp"],
"env": {
"ATTESTIFY_BASE_URL": "https://attestifyos.com",
"ATTESTIFY_API_KEY": "<your-tenant-api-key>",
"TRUST_AGENT_ID": "<optional — see Attestify Trust below>",
"TRUST_PRIVATE_KEY": "<optional — see Attestify Trust below>"
}
}
}
}
```
`ATTESTIFY_API_KEY` is a tenant API key issued via `POST /api/keys` — it's sent as the `X-API-Key` header on every run. Without one, runs are unauthenticated and subject to the plan/x402 limits that apply to anonymous callers.
`TRUST_AGENT_ID` / `TRUST_PRIVATE_KEY` are optional and unlock two more tools — see [Attestify Trust](#attestify-trust) below.
## Tools
### `attestify_research`
Runs a deep research query through the Attestify Research Agent (`researcher-v2`) via `POST /api/run`. Returns a structured briefing with executive summary, key findings, and caveats. Each call is metered at $0.023 USDC and logged to the Attestify evidence ledger.
**Arguments:**
| Field | Required | Description |
|---|---|---|
| `query` | Yes | The research question, topic, or subject to investigate. |
| `url` | No | Optional source URL to include as context for the research run. |
| `session_id` | No | Optional session ID for conversation continuity. |
**Returns:** a JSON blob with `summary`, `loop_id`, `run_id`, `input_hash`, `output_hash`, `price_usdc`, `agent_id`, `receipt_url`, and `created_at`.
### `attestify_trust_submit_evidence` / `attestify_trust_verify`
Available whenever `TRUST_AGENT_ID` and `TRUST_PRIVATE_KEY` are both set. A separate concern from `attestify_research` above — no x402, no lanes, no spend, no wallet at any point.
`attestify_trust_submit_evidence` signs (Ed25519, via Node's built-in `node:crypto` — no extra dependency) and submits evidence that the agent completed real work, returning a signed, timestamped, publicly verifiable receipt.
| Field | Required | Description |
|---|---|---|
| `summary` | Yes | Plain-language description of the work done. Gets signed and permanently recorded. |
| `schema` | No | Evidence schema version. Default `work-completion/v1`. |
| `action_basis` | No | `explicit` (default) or `discretionary`. |
`attestify_trust_verify` independently re-verifies any receipt by ID — public, no API key needed, works for receipts from any agent.
| Field | Required | Description |
|---|---|---|
| `receipt_id` | Yes | The receipt ID to verify. |
**Getting `TRUST_AGENT_ID` / `TRUST_PRIVATE_KEY`:** run this once, outside of any MCP session — never generate a fresh identity per session, it would both break the agent's own verified-active streak and add noise to Attestify's public census instead of a real, citable number:
```bash
npx attestify trust-init --name "My MCP Agent"
```
This registers a free Trust agent, generates its Ed25519 signing key locally, and prints the two values to set in your MCP host's config. The private key never leaves your machine except as a signature.
## Enterprise self-serve
Issue a tenant key, set a budget, attach policies — every subsequent run through this server is auto-governed:
```
1. POST /api/keys → issue tenant API key
2. POST /api/budgets → set USDC spend ceiling
3. POST /api/policies → attach governance rules
4. (this MCP server) → every run auto-enforced
```
## Links
- **Homepage:** https://attestifyos.com
- **Attestify Trust:** https://attestifyos.com/trust
- **Quickstart:** https://attestifyos.com/quickstart
- **OpenAPI spec:** https://attestifyos.com/openapi.json
- **x402 discovery:** https://attestifyos.com/.well-known/x402.json
- **GitHub:** https://github.com/attestifyagent/attestify-mcp