attestify-mcp
OfficialREADME.md
# attestify-mcp
> MCP server exposing Attestify OS agents — and [Attestify Trust](https://attestifyos.com/trust)'s no-wallet agent identity + signed evidence — as callable tools for Claude Desktop, Cursor, Windsurf, and any MCP-compatible host.
Attestify OS is infrastructure for AI agents operating in financial, compliance, and regulated workflows. Every governed run delivers: routing → governance enforcement → budget check → SLA check → execution → output verification → immutable receipt → on-chain settlement evidence.
**Live base URL:** `https://attestifyos.com`
This package is a real [Model Context Protocol](https://modelcontextprotocol.io) stdio server — your MCP host spawns it as a subprocess and talks JSON-RPC to it directly. It is not a plain HTTP client library.
## Quick start
Add to your MCP host's config (e.g. Claude Desktop's `claude_desktop_config.json`):
```json
{
"mcpServers": {
"attestify": {
"command": "npx",
"args": ["-y", "attestify-mcp"],
"env": {
"ATTESTIFY_BASE_URL": "https://attestifyos.com",
"ATTESTIFY_API_KEY": "<your-tenant-api-key>",
"TRUST_AGENT_ID": "<optional — see Attestify Trust below>",
"TRUST_PRIVATE_KEY": "<optional — see Attestify Trust below>"
}
}
}
}
```
`ATTESTIFY_API_KEY` is a tenant API key issued via `POST /api/keys` — it's sent as the `X-API-Key` header on every run. Without one, runs are unauthenticated and subject to the plan/x402 limits that apply to anonymous callers.
`TRUST_AGENT_ID` / `TRUST_PRIVATE_KEY` are optional and unlock two more tools — see [Attestify Trust](#attestify-trust) below.
## Tools
### `attestify_research`
Runs a deep research query through the Attestify Research Agent (`researcher-v2`) via `POST /api/run`. Returns a structured briefing with executive summary, key findings, and caveats. Each call is metered at $0.023 USDC and logged to the Attestify evidence ledger.
**Arguments:**
| Field | Required | Description |
|---|---|---|
| `query` | Yes | The research question, topic, or subject to investigate. |
| `url` | No | Optional source URL to include as context for the research run. |
| `session_id` | No | Optional session ID for conversation continuity. |
**Returns:** a JSON blob with `summary`, `loop_id`, `run_id`, `input_hash`, `output_hash`, `price_usdc`, `agent_id`, `receipt_url`, and `created_at`.
### `attestify_trust_submit_evidence` / `attestify_trust_verify`
Available whenever `TRUST_AGENT_ID` and `TRUST_PRIVATE_KEY` are both set. A separate concern from `attestify_research` above — no x402, no lanes, no spend, no wallet at any point.
`attestify_trust_submit_evidence` signs (Ed25519, via Node's built-in `node:crypto` — no extra dependency) and submits evidence that the agent completed real work, returning a signed, timestamped, publicly verifiable receipt.
| Field | Required | Description |
|---|---|---|
| `summary` | Yes | Plain-language description of the work done. Gets signed and permanently recorded. |
| `schema` | No | Evidence schema version. Default `work-completion/v1`. |
| `action_basis` | No | `explicit` (default) or `discretionary`. |
`attestify_trust_verify` independently re-verifies any receipt by ID — public, no API key needed, works for receipts from any agent.
| Field | Required | Description |
|---|---|---|
| `receipt_id` | Yes | The receipt ID to verify. |
**Getting `TRUST_AGENT_ID` / `TRUST_PRIVATE_KEY`:** run this once, outside of any MCP session — never generate a fresh identity per session, it would both break the agent's own verified-active streak and add noise to Attestify's public census instead of a real, citable number:
```bash
npx attestify trust-init --name "My MCP Agent"
```
This registers a free Trust agent, generates its Ed25519 signing key locally, and prints the two values to set in your MCP host's config. The private key never leaves your machine except as a signature.
## Enterprise self-serve
Issue a tenant key, set a budget, attach policies — every subsequent run through this server is auto-governed:
```
1. POST /api/keys → issue tenant API key
2. POST /api/budgets → set USDC spend ceiling
3. POST /api/policies → attach governance rules
4. (this MCP server) → every run auto-enforced
```
## Links
- **Homepage:** https://attestifyos.com
- **Attestify Trust:** https://attestifyos.com/trust
- **Quickstart:** https://attestifyos.com/quickstart
- **OpenAPI spec:** https://attestifyos.com/openapi.json
- **x402 discovery:** https://attestifyos.com/.well-known/x402.json
- **GitHub:** https://github.com/attestifyagent/attestify-mcp
TDQS
A3.9/5.0
Scored across 1 tool
Disambiguation5/5
Only one tool exists, so there is no possibility of confusing it with another tool. The tool's purpose is clearly defined in its description.
Naming Consistency5/5
The single tool name follows a credible server_prefix_action convention, and with only one tool there are no inconsistencies to evaluate.
Tool Count2/5
A single tool is too few for a server named 'attestify-mcp' that likely needs additional operations like listing or managing research jobs and evidence ledger entries.
Completeness2/5
The tool only runs a research query but provides no way to list previous queries, retrieve detailed results, or manage the evidence ledger, leaving significant gaps in the expected domain.
Maintenance
ActivityMaintained
ResponsivenessNo issues