Skip to main content
Glama
SPAZIO-GENESI

attest-mcp-remote

attest-mcp-remote

Listed on the official MCP Registry as io.github.SPAZIO-GENESI/attest-mcp-remote.

Remote MCP server (Streamable HTTP) for the Spazio Genesi digital-work attestation service. Zero install: add the URL as a connector in your MCP client and start verifying and attesting.

No file ever transits — by design. MCP has no reliable client→server file channel, and this service doesn't want one: every tool works on the SHA-256 fingerprint of the work. Agents with code execution compute it locally (sha256sum <file>), so the file never leaves the machine it lives on — not even through this server. For local-file tooling use the stdio package @spazio-genesi/attest-mcp; for humans, the website (in-browser hashing, full privacy) or the Telegram bot @SGAttestBot.

Status

In production. Live at https://attest-mcp-remote.it-e3f.workers.dev/mcp. All 8 tools implemented, tested, and validated end-to-end against production, including a real zero-install run from claude.ai (connector by URL, human Turnstile approval, certificate PDF issued and archived).

Related MCP server: attest-mcp

Tools

Tool

Auth

What it does

service_status

none

Health of worker / archive / signer / Bitcoin anchor

check_anchor

none

OpenTimestamps proof lookup for a fingerprint

verify_attestation

none

Verify the server HMAC signature of an attestation

lookup_certificate

none

Archive lookup + permanent links for a fingerprint

authorize

starts device flow

User approves once in the browser (anti-bot check)

complete_authorization

device flow

Claims the 24h session token (kept in session state, never echoed)

attest_hash

session token or API key header

Bind a fingerprint to a signed server timestamp

create_certificate_pdf

session-scoped

Generate + archive the certificate PDF, returns permanent links

Credentials: either the zero-config device flow above, or an Authorization: Bearer sg_k_… header on the connection (e.g. Claude Code: claude mcp add --transport http attest <url> --header "Authorization: Bearer sg_k_…"). Self-service keys: https://imgauth.spaziogenesi.org/developer/keys

Develop

npm install
npm run dev            # wrangler dev (default port 8787)
node test/smoke.mjs http://127.0.0.1:8787

test/smoke.mjs drives the Streamable HTTP transport end-to-end (initialize → tools/list → tools/call) against real, public production data (read-only). test/smoke-auth.mjs covers the credentialed flow and is a local-only harness: it needs an isolated imgauth wrangler dev (own --persist-to state, SIGNER_URL emptied) because the user-approval step is simulated by writing the local D1 directly — see the header comment in the file.

⚠️ When bumping the version

This server is also advertised through an MCP Server Card published by the web interface, which repeats this server's name, version and endpoint:

https://attestazione.spaziogenesi.org/.well-known/mcp/server-card.json
→ file: imgauthweb/.well-known/mcp/server-card.json

That file is not generated from this repository, so a version bump here silently makes it wrong. When you change version in package.json and server.json, update serverInfo.version in the card too — same release, same day. (Publishing a card that misstates the version is the same class of problem as an openapi.json left behind: a descriptor that lies is worse than none.)

Security

Report vulnerabilities → /sicurezza/ (responsible disclosure policy, safe harbor for good-faith research) — this repo has no security.txt of its own (Worker with no static assets), but the policy covers the whole project, including this workers.dev service.

License

MIT — © Spazio Genesi ETS. This is a pure client of the public imgauth API; it defines no API contract of its own.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Document verification MCP server enabling AI agents to verify file authenticity by computing SHA-256 fingerprints locally and checking Bitcoin-anchored proofs via OpenTimestamps.
    5
    9
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    MCP server for Spazio Genesi's attestation service that enables AI agents to attest, verify, and check digital works with full privacy, as file bytes never leave the device.
    7
    50
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for issuing and scanning TDM reservation signals (HTTP, HTML, robots.txt, C2PA) and signing training-run liability shields to ensure EU AI Act compliance.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    MCP server for creating cryptographically signed and timestamped evidence of public web/API responses, with offline verification of attestations and paid access via x402.
    -