Back to the catalog

ArtifactGuard Signed AI Deliverable QA

Signed PASS/WARN/FAIL QA receipts for AI-generated JSON, ZIP, PDF, and DOCX deliverables.

Open source Repository Open in the app JSON README (API)

About

Signed PASS/WARN/FAIL QA receipts for AI-generated JSON, ZIP, PDF, and DOCX deliverables.

Details

Kind
MCP servers
Topic
Files & documents
Publisher
blackcow4234-lab
Origin
official
Category
ferramentas
Transport
http
Version
1.0.0
Last push
2026-08-06T14:04:08Z
Repository state
ativo
Language
Python
Added
2026-08-29 03:02:31
Updated
2026-08-29 03:02:31
Origin id
io.github.blackcow4234-lab/artifactguard

README

# ArtifactGuard: Signed AI Deliverable QA

Use ArtifactGuard as the last step before an AI agent delivers a JSON, ZIP,
PDF, or DOCX file to a customer. The buyer receives a deterministic
`PASS`, `WARN`, or `FAIL` receipt containing the artifact hash, contract hash,
individual checks, validator version, timestamp, and an Ed25519 signature.

## One purchase case

An AI report agent creates `result.json`. Before delivery, it asks
ArtifactGuard to verify that the file is valid JSON, contains a `status` field
equal to `ready`, and does not contain configured forbidden patterns. The agent
then attaches the signed receipt to its final handoff.

This is delivery-contract QA, not antivirus scanning, legal certification, or
a guarantee that the document's claims are true.

## Buy through Apify

Set your own Apify API token locally. Never commit it.

```bash
export APIFY_TOKEN="your-token"
curl --fail-with-body \
  -X POST \
  "https://api.apify.com/v2/acts/analytical_gratefulness~artifactguard-agent/run-sync-get-dataset-items?format=json" \
  -H "Authorization: Bearer ${APIFY_TOKEN}" \
  -H "Content-Type: application/json" \
  --data-binary @examples/validate_artifact.json \
  --output receipt-response.json
```

`validate-manifest` costs USD 0.01 and `validate-artifact` costs USD 0.05.
Malformed requests and readiness checks do not trigger an application event
charge. A completed inspection whose result is `FAIL` is still a valid paid
result.

- [ArtifactGuard Agent on Apify](https://apify.com/analytical_gratefulness/artifactguard-agent)
- [ArtifactGuard REST/MCP Actor](https://apify.com/analytical_gratefulness/artifactguard)

## Buy directly with x402

The direct endpoint returns a standards-based `402 Payment Required` response
with the price and payment requirements before any artifact is processed:

```bash
curl -i \
  -X POST \
  https://artifactguard-kl4hfo6j2q-as.a.run.app/v1/validate/artifact \
  -H "Content-Type: application/json" \
  --data-binary @examples/x402_validate_artifact.json
```

An x402-compatible buyer can satisfy that payment requirement and repeat the
same request with a payment signature. Do not place wallet private keys in a
request body, repository, or log.

Free discovery endpoints:

- `GET https://artifactguard-kl4hfo6j2q-as.a.run.app/capabilities`
- `GET https://artifactguard-kl4hfo6j2q-as.a.run.app/examples`
- `GET https://artifactguard-kl4hfo6j2q-as.a.run.app/presets`

## MCP

The Apify Standby Actor exposes Streamable HTTP MCP at:

```text
https://analytical-gratefulne--artifactguard.apify.actor/mcp
```

Supply your own Apify token as an `Authorization: Bearer ...` header in the MCP
client. Available tools include `validate_manifest`, `validate_artifact`, and
the free `verify_receipt` tool.

## Verify a receipt independently

Install the single verifier dependency and pass either a receipt object or the
full ArtifactGuard response envelope:

```bash
python -m pip install -r requirements.txt
python verify_receipt.py receipt-response.json
```

The verifier retrieves only the public Ed25519 key identified by the receipt,
recomputes the canonical receipt hash, and verifies the signature. It never
needs an API token, payment credential, or private key.

## Files

- `examples/validate_artifact.json`: Apify Actor input.
- `examples/x402_validate_artifact.json`: direct x402 API input.
- `examples/validate_manifest.json`: inexpensive manifest-only Actor input.
- `verify_receipt.py`: independent receipt hash and signature verifier.
- `server.json`: Official MCP Registry metadata for the authenticated remote.

More