attest-mcp
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ATTEST_BASE_URL | No | Override the Attest API base URL. Only needed for self-hosting or testing. | https://attestagent.org |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| attest_scanA | Scan an agent payment endpoint (x402 / MPP / AP2 / L402 / HTTP 402) and return a letter grade A–F with a safety verdict. Call this BEFORE authorizing a payment to an unfamiliar endpoint to check for impersonation, blocklisted payout wallets, bait-and-switch pricing, and protocol problems. |
| attest_gradeA | Quickly look up the most recent Attest grade for a host that has already been scanned. Useful for a fast pre-check. If the host has never been scanned, use attest_scan instead. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools are clearly distinct: attest_scan performs a full scan of an endpoint and returns a grade, while attest_grade retrieves a previously cached grade. There is no ambiguity about which to use.
Both tools follow the consistent verb_noun pattern 'attest_scan' and 'attest_grade', using the same prefix and a clear action word.
With only two tools, the set is minimal but focused. It covers the core scan-and-check workflow without unnecessary bloat. A third tool for listing or managing hosts would be nice but is not essential.
The two tools cover the primary use case of scanning and retrieving grades, but there are missing operations like listing all scanned hosts, deleting a host, or forcing a rescan. The surface is somewhat incomplete for lifecycle management.