booklint stamp
Server Details
Signed timestamp receipts for a SHA-256 hash. Send only the hash; we never see the document.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
TDQS
Scored across 2 tools
The two tools form a clear create/verify pair with no overlap: stamp_hash produces a signed receipt and verify_receipt validates one. An agent can unambiguously pick the right tool based on whether it holds a hash or a receipt.
Both names follow the same verb_noun snake_case pattern (stamp_hash, verify_receipt), and the verbs map directly to the create/verify actions. No mixing of conventions.
Two tools is thin in the abstract, but the service is deliberately narrow—sign a hash, verify a receipt—so each tool earns its place. No obvious third operation is missing from the core workflow.
The stamp/verify pair covers the full lifecycle of the stated purpose, with a public_key_url enabling out-of-band key checks. Minor gaps like key listing or receipt lookup exist but are outside the stateless, no-storage design.
Available Tools
2 toolsstamp_hashStamp a SHA-256 hashAInspect
Returns a signed receipt {sha256, stamped_at, key_id, signature, public_key_url}: a booklint-family service saw this hash at stamped_at, signed with key key_id. Send ONLY a SHA-256 hex digest (64 characters). We never see or store the document — only the hash you send. This is not legal proof, notary service, evidence, or a certificate of anything. Not advice.
| Name | Required | Description | Default |
|---|---|---|---|
| sha256 | Yes | 64 hex characters you computed yourself. | |
| api_key | No | Optional key. Same as the Bearer header. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With annotations present, the description still adds real value: it discloses the privacy model ('We never see or store the document — only the hash'), the response shape, and explicit scope disclaimers (not legal proof, notary, evidence, or a certificate). It does not address idempotency behavior despite idempotentHint=false, but the privacy and scope disclosure goes well beyond the annotation set.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The return shape is front-loaded in the first clause, followed by the input constraint, privacy note, and disclaimers. Every sentence carries information, though the disclaimer sentence is long and slightly dilutes the core call instructions.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, so the description appropriately enumerates the returned fields and explains the trust model behind them. Combined with the schema's api_key documentation, an agent has what it needs, though auth requirements and any cost/rate behavior are not stated.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3; the description earns a point by reinforcing the strict input contract ('Send ONLY a SHA-256 hex digest (64 characters)') and clarifying that the document itself is never sent. The optional api_key is left entirely to the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: it returns a signed receipt (sha256, stamped_at, key_id, signature, public_key_url) attesting that a booklint-family service saw the hash at a given time. That is far more than a restatement of the name. It does not explicitly contrast with the sibling verify_receipt, so it falls short of a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a clear input rule ('Send ONLY a SHA-256 hex digest (64 characters)') and an implicit purpose, but never states when to use stamp_hash versus verify_receipt, or any prerequisites such as whether a key is required. Usage is implied rather than guided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
verify_receiptVerify a stamp receiptARead-onlyIdempotentInspect
Checks a receipt from stamp_hash against the published public keys (same check as POST /v1/verify; pass the receipt fields as arguments). Returns valid true or false with a reason. valid true means only that this service signed that hash and time with that key. This is not legal proof, notary service, evidence, or a certificate of anything.
| Name | Required | Description | Default |
|---|---|---|---|
| key_id | Yes | ||
| sha256 | Yes | ||
| api_key | No | Optional key. Same as the Bearer header. | |
| signature | Yes | ||
| statement | No | ||
| stamped_at | Yes | ||
| public_key_url | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/closed-world, and the description goes further by explaining the return shape (valid true/false with a reason) and, importantly, the limits of what 'valid' means — not legal proof, notary, evidence, or certificate. That semantic caveat is exactly the kind of context annotations cannot convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three tight sentences with the core action front-loaded, followed by usage mapping and then the result/limits. No filler; each sentence carries distinct information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description correctly explains the return value and its interpretation, plus the non-guarantees. The only shortfall is the absence of per-parameter guidance, though that is primarily a schema-side gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is only 14% — just api_key is documented — and the description does not compensate, saying only 'pass the receipt fields as arguments.' The meaning, format, and source of sha256, stamped_at, key_id, signature, statement, and public_key_url are left entirely to inference.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource (verifies a stamp receipt), and ties it to the sibling workflow by saying the receipt comes from stamp_hash. An agent can immediately distinguish this read/verify tool from the stamping tool without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear context: take the receipt produced by stamp_hash and pass its fields as arguments, mirroring POST /v1/verify. It does not explicitly state when NOT to use it or name alternatives, but the workflow position is unambiguous.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
- First observed
stamp_hash - First observed
verify_receipt
Related MCP Connectors
Stamp or notarize data into a public witnessed transparency log. Proves timing, not truth.
Stamp content with permanent, verifiable provenance. Hash locally, verify free forever.
Capture a web source, or seal a hash you hold, into a signed receipt anyone can verify offline.
Timestamp & verify evidence on-chain, free. Proofpack: a portable BEEF+BUMP proof bundle per txid.
Related MCP Servers
AlicenseAqualityBmaintenanceVerifies blockchain-anchored timestamp proofs entirely on the user's machine, with five tools: hash a file, verify a file against a proof, verify a known hash against inline proof data, explain what a proof asserts, and create a new proof through ProofLedger. Verification recomputes the SHA-256 and walks the Merkle path locally instead of asking the issuer; only create uses the network.535 PyPIMIT- AlicenseAqualityBmaintenanceProvides cryptographic truth infrastructure for AI agents, enabling them to seal content with SHA-256 and Ed25519, verify receipts, anchor them to Bitcoin via OpenTimestamps, generate citations, and audit chains of receipts.537 npm1MIT
- AlicenseNot gradedqualityCmaintenanceEnables tamper-evident anchoring of file, text, or JSON hashes to the BSV blockchain via MCP tools, with verification and lookup capabilities.MIT
- AlicenseAqualityAmaintenanceStamp, upgrade, and verify Bitcoin timestamps via AI agents using the OpenTimestamps protocol. No API keys required.29110 npm3MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.