agent-envelope-mcp
This server provides tools to verify and manage delegated action authority for AI agents, acting as a neutral authority layer.
Offline sovereign verification:
ae_verify_sovereignperforms cryptographic verification of a signed message against a known agent address without any API key, network connection, or vault. It is always free and available.Hosted governance operations (require
AE_API_KEYfor secure, fail-closed access):ae_get_agent: Fetch the public record for a registered agent.ae_verify_action: Verify a signed action against the agent's vault-held record.ae_mint: Issue a capability (mint) via hosted governance using a MintDelegate and signed MintRequest, returning a receipt.
The server is framework-agnostic, suitable for embedding in any MCP client or for programmatic use.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-envelope-mcpCan you verify this signed message from agent 0x9f8e?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
agent-envelope-mcp
The neutral authority layer for action-performing systems, as an MCP server.
Any MCP client — Claude, an OpenAI agent, LangChain, CrewAI, a custom runtime — can call these tools to check delegated action authority without building its own verification stack. AgentEnvelope is owned by no framework, so every framework can embed it.
An AgentEnvelope "agent" is a bounded action identity: a named actor, operation, resources, decay policy, and verifiable address. That actor can be an AI agent, backend worker, workflow step, service, device command, access grant, order, or instruction.
Run
npx agent-envelope-mcpIt speaks MCP over stdio. No API key is needed to start, or to use sovereign
signature/record verification — only the hosted-governance tools require AE_API_KEY.
Related MCP server: dingdawg-governance
Wire it into an MCP client
Point your client at the command and pass the portal-issued API key in the environment (only needed for hosted-governance tools):
{
"mcpServers": {
"agent-envelope": {
"command": "npx",
"args": ["-y", "agent-envelope-mcp"],
"env": { "AE_API_KEY": "your-portal-issued-api-key" }
}
}
}Tools
Tool | Mode | Credential |
| Sovereign signature check | none — offline, always free |
| Sovereign public-record check | none — offline, always free |
| Hosted governance |
|
| Hosted governance |
|
| Hosted governance |
|
ae_verify_sovereign— verify a signed message against a known agent address. Pure crypto: no vault, no key, no network. This is a signature-only check; it does not check action-envelope scope, expiry, usage limits, or hosted record status.ae_verify_sovereign_record— verify a signed action against a public action record. Checks record status, action index, signature/address match, optional expected envelope hash, and time decay without a network call.ae_get_agent— fetch the hosted public record for an agent id.ae_verify_action— verify a signed action against the hosted public record.ae_mint— verify aMintDelegateand signedMintRequestthrough hosted governance, returning a mint receipt. It does not return private capability material. This is a governed action.
The sovereign verifier needs no account and no key. The hosted-governance tools are the governed surface a framework offloads rather than rebuilds. API keys meter and protect hosted service routes; signatures prove authority.
Programmatic use
import { createServer } from 'agent-envelope-mcp';
// mount createServer() on your own MCP transportEnvironment
Variable | Required for | Purpose |
|
| Portal-issued API key for hosted governance |
The server is fail-closed: hosted-governance tools return an error result when
AE_API_KEY is absent rather than exposing an unauthenticated surface.
License
Apache-2.0 — see NOTICE for attribution.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAgent network intelligence for trust verification, broker discovery, and capability matching. Ed25519 identity, graph-based trust scoring, USDC payments, and MCP tools for agent registration, search, and trust attestation.1,1645MIT
- AlicenseAqualityBmaintenanceUniversal governance layer for AI agents — MCP-native, fail-closed, LNN interpretability. Governed receipts, IPFS audit proofs, and rollback for any agent in any framework.398Apache 2.0
- AlicenseNot gradedqualityDmaintenanceMCP Server for AI agent identity and authorization. Create, verify, and manage agent identities with trust scores and scoped authorization tokens.MIT
- AlicenseAqualityDmaintenanceMCP server for AI agent trust verification, enabling agents to verify identities, check trust scores, and build reputation across multiple blockchain and web platforms.12341MIT
Related MCP Connectors
MCP-native Trust Infrastructure for AI Agents. Persistent encrypted memory with Trust Quotient.
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
Hosted AgentLux MCP server for marketplace, identity, creator, services, and social flows.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/BlackBoxEngineering/agent-envelope-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server