Skip to main content
Glama
Omicron6

KLAIM MCP server

by Omicron6

KLAIM

Pay-Per-Use Human Verification API for AI Agents

Verify users without exposing their documents.

KLAIM is a privacy-first verification infrastructure that allows applications and AI agents to verify claims about a user โ€” such as Age > 18 โ€” without receiving the user's underlying identity documents or raw PII.

Algorand x402 MCP Privacy


๐Ÿš€ What is KLAIM?

Modern applications increasingly need to verify that a user is eligible for a service.

For example:

  • Is this user over 18?

  • Is this user a resident of a particular country?

  • Does this user possess a valid credential?

  • Has this user completed a required verification?

  • Is this a verified human?

The traditional approach is to collect the actual identity document.

That creates a major privacy problem.

An application may only need to know:

Age > 18 = TRUE

but instead receives:

Name
Date of Birth
Address
Aadhaar/PAN information
Document number
Issuer information
Full document

KLAIM changes this model.

Instead of applications receiving documents, KLAIM exposes a pay-per-use human verification API.

The application or AI agent asks:

"Is this person over 18?"

KLAIM performs the verification internally and returns:

{
  "verified": true,
  "claim": "AGE_OVER_18"
}

The underlying credential and personal information remain private.

KLAIM sells verification, not identity data.

Related MCP server: AgentStamp

๐Ÿ”— Verified Algorand Testnet Transactions

KLAIM uses the x402 payment protocol to enable pay-per-use human verification.

For the MVP, payments are settled in USDC on Algorand Testnet. The following transactions are real on-chain transfers from the payer wallet โ†’ provider wallet, each representing a 0.01 USDC verification payment.

These are not simulated transaction IDs. They are real Algorand Testnet transactions and can be independently verified using the AlgoKit Lora explorer.

Live x402 Payment Evidence

#

Amount

Network

Flow

Transaction

1

0.01 USDC

Algorand Testnet

Payer โ†’ Provider

View on Lora

2

0.01 USDC

Algorand Testnet

Payer โ†’ Provider

View on Lora

3

0.01 USDC

Algorand Testnet

Payer โ†’ Provider

View on Lora

4

0.01 USDC

Algorand Testnet

Payer โ†’ Provider

View on Lora

What This Demonstrates

The payment layer is designed around the following flow:

AI Agent
   โ”‚
   โ”‚ MCP tool call
   โ–ผ
KLAIM Verification API
   โ”‚
   โ”‚ No payment
   โ–ผ
HTTP 402 Payment Required
   โ”‚
   โ”‚ x402 payment requirements
   โ–ผ
AI Agent / Payer Wallet
   โ”‚
   โ”‚ Sign USDC payment
   โ–ผ
GoPlausible Facilitator
   โ”‚
   โ”‚ Verify + settle
   โ–ผ
Algorand Testnet
   โ”‚
   โ”‚ Real USDC transaction
   โ–ผ
Provider Wallet
   โ”‚
   โ”‚ Settlement confirmed
   โ–ผ
KLAIM Verification
   โ”‚
   โ–ผ
Verified Claim
---

# ๐ŸŽฏ Problem

Digital onboarding and AI-agent workflows have three major problems.

### 1. Over-collection of personal information

Applications collect complete identity documents even when they only need one attribute.

### 2. AI agents cannot easily perform trusted identity verification

AI agents can interact with APIs and tools, but identity verification still requires manual document workflows.

### 3. Verification APIs are not naturally machine-payable

Traditional verification providers usually depend on subscriptions, accounts, billing systems, or manual payment workflows.

KLAIM combines:

* **MCP** for AI-agent interoperability
* **x402** for machine-to-machine payments
* **Algorand** for on-chain settlement
* **DID / VC** for identity
* **Zero-Knowledge Proofs** for privacy-preserving verification

into a single verification infrastructure layer.

---

# ๐Ÿ’ก The Core Idea

KLAIM separates identity from verification.

### Traditional Verification

```text
User
 โ”‚
 โ”‚ Upload document
 โ–ผ
Application
 โ”‚
 โ”œโ”€โ”€ Name
 โ”œโ”€โ”€ DOB
 โ”œโ”€โ”€ Address
 โ”œโ”€โ”€ ID Number
 โ””โ”€โ”€ Full Document

KLAIM Archetecture

User
 โ”‚
 โ”‚ Credential + Consent
 โ–ผ
KLAIM
 โ”‚
 โ”‚ Verify privately
 โ”‚
 โ”‚ ZK Proof
 โ–ผ
Application / AI Agent
 โ”‚
 โ””โ”€โ”€ "AGE > 18 = TRUE"

The application receives the answer, not the document.


๐Ÿ—๏ธ Architecture

flowchart TD

    H[Human User]

    DL[DigiLocker / Credential Issuer]

    DID[DID + Verifiable Credential]

    H -->|Consent| DL
    DL -->|Credential| DID

    A[AI Agent<br/>Claude / GPT / Custom Agent]

    MCP[KLAIM MCP Server]

    X402[x402 Payment Middleware]

    FAC[GoPlausible Facilitator]

    ALGO[Algorand Testnet]

    API[Verification API]

    PA[Provider Agent<br/>Strands]

    ZK[ZK Proof Engine<br/>Midnight-ready]

    RESULT[Verified Claim<br/>No Raw PII]

    A -->|MCP Tool Call| MCP
    MCP --> API

    API --> X402

    X402 -->|402 Payment Required| A

    A -->|USDC Payment| X402

    X402 --> FAC
    FAC --> ALGO

    ALGO -->|Settlement TX| X402

    X402 --> API

    API --> PA

    PA -->|Check DID| DID
    PA -->|Check Credential| DID
    PA -->|Check Claim| DID

    PA --> ZK

    ZK --> RESULT

    RESULT --> API
    API --> MCP
    MCP --> A

๐Ÿ”„ Complete Verification Flow

1. Human onboarding

The user connects their identity credential source.

For the MVP, DigiLocker is the intended credential source.

Human
  โ”‚
  โ–ผ
DigiLocker
  โ”‚
  โ–ผ
Credential
  โ”‚
  โ–ผ
KLAIM DID

KLAIM stores credential references and derived claims rather than exposing complete identity documents to verification consumers.


2. AI Agent connects through MCP

AI agents connect to KLAIM through the Model Context Protocol (MCP).

Claude / GPT / Custom Agent
            โ”‚
            โ”‚ MCP
            โ–ผ
     KLAIM MCP Server

The MCP server exposes verification tools such as:

verify_human_age

An agent can therefore request:

Verify whether DID xyz is over 18.

3. Agent authentication

Every verifier receives a unique KLAIM agent credential.

Example:

Agent ID:
agent_xxxxxxxxx

Agent Key:
klm_xxxxxxxxxxxxxxxxx

The key is:

  • generated by KLAIM

  • displayed once

  • hashed before storage

  • revocable

  • rotatable


4. Verification Request

The MCP tool calls the protected verification API.

POST /api/v1/verify/age

Example:

{
  "did": "did:klaim:demo-user-001"
}

5. x402 Payment Boundary

The verification API is protected by x402.

If no valid payment is attached:

HTTP/1.1 402 Payment Required

The x402 layer provides the payment requirements required by the client.

The flow becomes:

AI Agent
   โ”‚
   โ”‚ POST /verify/age
   โ–ผ
KLAIM
   โ”‚
   โ”‚ HTTP 402
   โ–ผ
AI Agent
   โ”‚
   โ”‚ Prepare payment
   โ–ผ
x402

6. USDC Payment

The verifier agent pays for the verification using USDC on Algorand Testnet.

AI Agent
    โ”‚
    โ”‚ USDC
    โ–ผ
x402
    โ”‚
    โ–ผ
GoPlausible Facilitator
    โ”‚
    โ–ผ
Algorand Testnet

The payment is settled on-chain.

A successful verification contains the settlement transaction ID.

Example:

{
  "payment": {
    "txId": "REAL_ALGORAND_TX_ID",
    "explorerUrl": "https://lora.algokit.io/testnet/transaction/..."
  }
}

7. Provider Agent

Only after successful payment settlement does the verification pipeline execute.

The KLAIM Provider Agent is designed around the Strands Agents SDK, with a deterministic fallback for the MVP.

The verification pipeline is:

check_did
    โ†“
check_credential
    โ†“
check_claim
    โ†“
generate_zk_proof
    โ†“
verify_zk_proof

Critical invariant

NO PAYMENT
     โ†“
NO VERIFICATION

The verification business logic does not execute before the payment boundary succeeds.


8. Credential Verification

The Provider Agent checks whether the requested credential exists for the user's DID.

For example:

Requested:

AGE > 18

Available:

DigiLocker Credential
       โ”‚
       โ””โ”€โ”€ DOB available

The required claim is derived internally.

The actual DOB is never returned to the verifier.


9. Zero-Knowledge Verification

KLAIM follows a simple principle:

Prove the claim without revealing the underlying data.

Instead of exposing:

Date of Birth:
12/03/2002

KLAIM aims to produce a proof of:

AGE > 18

The verifier only needs:

verified = true

The architecture contains a ZK abstraction layer designed to connect with a Midnight prover.

Current MVP architecture:

ZK Service
    โ”‚
    โ”œโ”€โ”€ Local / deterministic engine
    โ”‚
    โ””โ”€โ”€ Midnight prover integration point

The system explicitly identifies the proof engine rather than falsely representing a local simulation as production cryptographic ZK.


๐Ÿ” Privacy Model

KLAIM follows a minimum-disclosure architecture.

Data that remains private

Name
Date of Birth
Address
Aadhaar
PAN
Document Number
Raw Identity Document

Data returned

Verification Result
Claim
Proof Descriptor
Payment Receipt
Algorand Transaction ID

Example:

{
  "verified": true,
  "claim": "AGE_OVER_18",
  "proof": {
    "type": "zk",
    "notDisclosed": [
      "date_of_birth",
      "name",
      "address",
      "document"
    ]
  }
}

๐Ÿค– AI Agent Architecture

KLAIM is designed specifically for machine-to-machine verification.

sequenceDiagram

    participant C as Claude / AI Agent
    participant M as KLAIM MCP
    participant API as Verification API
    participant X as x402
    participant F as GoPlausible
    participant A as Algorand
    participant P as Provider Agent
    participant Z as ZK Engine

    C->>M: verify_human_age(DID)

    M->>API: POST /verify/age

    API->>X: Check payment

    X-->>C: HTTP 402 + requirements

    C->>X: Signed USDC payment

    X->>F: Verify + settle

    F->>A: Algorand Testnet settlement

    A-->>F: Transaction ID

    F-->>X: Settlement successful

    X->>API: Payment verified

    API->>P: Start verification

    P->>P: Check DID

    P->>P: Check credential

    P->>P: Evaluate claim

    P->>Z: Generate / verify proof

    Z-->>P: Proof

    P-->>API: Verified claim

    API-->>M: Result + TX ID

    M-->>C: Verified claim

๐Ÿงฉ Why MCP?

Without MCP, every AI agent would require a custom KLAIM integration.

Claude โ†’ Custom SDK
GPT โ†’ Custom SDK
Agent X โ†’ Custom SDK
Agent Y โ†’ Custom SDK

With MCP:

Claude
GPT
Custom Agent
     โ”‚
     โ–ผ
    MCP
     โ”‚
     โ–ผ
   KLAIM

KLAIM becomes a reusable verification capability that AI agents can discover and invoke.


๐Ÿ’ฐ Why x402?

x402 enables HTTP-native machine payments.

The agent does not need:

  • subscriptions

  • manual checkout

  • credit-card forms

  • human billing intervention

Instead:

Request
   โ†“
402
   โ†“
Pay
   โ†“
Retry
   โ†“
Verification

This creates a natural model for pay-per-verification APIs.


๐ŸŒ Why Algorand?

Algorand is used as the settlement network for the MVP because it provides:

  • fast settlement

  • low transaction costs

  • USDC support

  • accessible testnet infrastructure

  • independently verifiable transactions

The payment receipt can be inspected on Algorand Testnet.


โญ USP

KLAIM is not another identity dashboard.

KLAIM is a verification infrastructure layer for AI agents.

Traditional identity verification

Application
     โ”‚
     โ–ผ
Identity Provider
     โ”‚
     โ–ผ
Upload Document
     โ”‚
     โ–ผ
PII Processing
     โ”‚
     โ–ผ
Verification

KLAIM

AI Agent
   โ”‚
   โ–ผ
MCP
   โ”‚
   โ–ผ
x402 Payment
   โ”‚
   โ–ผ
KLAIM
   โ”‚
   โ”œโ”€โ”€ DID / Credential
   โ”œโ”€โ”€ Provider Agent
   โ””โ”€โ”€ ZK Proof
          โ”‚
          โ–ผ
   Boolean Verification

The key difference

KLAIM sells verification, not identity data.


๐Ÿ‘ฅ Product Roles

Human

The human controls their identity.

Capabilities:

  • Create / manage DID

  • Connect credentials

  • View credentials

  • Delete credentials

  • Manage verification permissions

  • View verification history

The human does not pay for verification.


Verifier

The verifier represents an application or AI agent.

Capabilities:

  • Create AI agents

  • Generate MCP credentials

  • Rotate / revoke agent keys

  • Connect MCP to Claude

  • Request verification

  • Monitor x402 payments

  • View transaction history

  • View verification activity


๐Ÿ”‘ Agent Authentication

KLAIM generates unique credentials for verifier agents.

Example:

Agent ID
agent_xxxxxxxxx

Agent Key
klm_xxxxxxxxxxxxxxxxx

The raw key is shown once.

KLAIM stores a SHA-256 hash of the key.

Agent Key
    โ”‚
    โ–ผ
 SHA-256
    โ”‚
    โ–ผ
Stored Hash

๐Ÿ—๏ธ Project Structure

KLAIM/
โ”‚
โ”œโ”€โ”€ src/
โ”‚   โ”œโ”€โ”€ routes/
โ”‚   โ”‚   โ”œโ”€โ”€ api/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ public/
โ”‚   โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ mcp.ts
โ”‚   โ”‚   โ”‚   โ”‚
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ v1/
โ”‚   โ”‚   โ”‚       โ”œโ”€โ”€ verify/
โ”‚   โ”‚   โ”‚       โ”‚   โ””โ”€โ”€ age.ts
โ”‚   โ”‚   โ”‚       โ”œโ”€โ”€ agents.ts
โ”‚   โ”‚   โ”‚       โ”œโ”€โ”€ credentials.ts
โ”‚   โ”‚   โ”‚       โ”œโ”€โ”€ digilocker.ts
โ”‚   โ”‚   โ”‚       โ”œโ”€โ”€ integrations.ts
โ”‚   โ”‚   โ”‚       โ””โ”€โ”€ transactions.ts
โ”‚   โ”‚   โ”‚
โ”‚   โ”‚   โ”œโ”€โ”€ human.*
โ”‚   โ”‚   โ”œโ”€โ”€ verifier.*
โ”‚   โ”‚   โ””โ”€โ”€ index.tsx
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ lib/
โ”‚   โ”‚   โ””โ”€โ”€ klaim/
โ”‚   โ”‚       โ”œโ”€โ”€ server/
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ mcp.server.ts
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ x402.server.ts
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ provider-agent.server.ts
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ zkp.server.ts
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ digilocker.server.ts
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ store.server.ts
โ”‚   โ”‚       โ”‚   โ””โ”€โ”€ env.server.ts
โ”‚   โ”‚       โ”‚
โ”‚   โ”‚       โ”œโ”€โ”€ api.ts
โ”‚   โ”‚       โ”œโ”€โ”€ services.ts
โ”‚   โ”‚       โ”œโ”€โ”€ types.ts
โ”‚   โ”‚       โ””โ”€โ”€ mock-data.ts
โ”‚   โ”‚
โ”‚   โ””โ”€โ”€ components/
โ”‚       โ”œโ”€โ”€ app/
โ”‚       โ”œโ”€โ”€ ui/
โ”‚       โ””โ”€โ”€ klaim-landing.tsx
โ”‚
โ”œโ”€โ”€ scripts/
โ”‚   โ”œโ”€โ”€ provision-agent.ts
โ”‚   โ””โ”€โ”€ test-x402.ts
โ”‚
โ”œโ”€โ”€ tests/
โ”‚   โ””โ”€โ”€ mcp-x402-flow.test.ts
โ”‚
โ”œโ”€โ”€ .env.example
โ”œโ”€โ”€ package.json
โ””โ”€โ”€ README.md

๐Ÿ› ๏ธ Technology Stack

Layer

Technology

Frontend

React

Framework

TanStack Start

Routing

TanStack Router

Styling

Tailwind CSS

UI

shadcn/ui / Radix

Backend

Nitro / TanStack server routes

Language

TypeScript

Runtime

Bun / Node

AI Agent

Strands Agents SDK

AI Integration

MCP

Payment

x402

Facilitator

GoPlausible

Blockchain

Algorand Testnet

Payment Asset

USDC

Identity

DID / VC

Credential Source

DigiLocker

ZK Layer

Midnight-ready abstraction

State

Repository-based ephemeral store


๐Ÿงช Running Locally

Requirements

Install:

  • Node.js or Bun

  • Git

  • Claude Desktop (optional for MCP testing)

Clone the repository:

git clone <YOUR_GITHUB_REPOSITORY_URL>
cd KLAIM

Install dependencies:

npm install

or:

bun install

Create your environment file:

cp .env.example .env

Start the development server:

npm run dev

The application will be available at:

http://localhost:8080

๐Ÿ”Œ Testing MCP

The MCP endpoint is:

http://localhost:8080/api/public/mcp

The MCP server supports:

initialize
ping
tools/list
tools/call

The main verification tool is:

verify_human_age

๐Ÿค– Connect Claude Desktop

After provisioning a KLAIM verifier agent, configure Claude Desktop with:

{
  "mcpServers": {
    "klaim": {
      "type": "http",
      "url": "http://localhost:8080/api/public/mcp",
      "headers": {
        "X-KLAIM-Agent-Id": "YOUR_AGENT_ID",
        "Authorization": "Bearer YOUR_AGENT_KEY"
      }
    }
  }
}

Restart Claude Desktop.

Then ask:

Use KLAIM to verify whether did:klaim:demo-user-001 is over 18.

Claude should discover and invoke:

verify_human_age

๐Ÿ’ณ Testing x402

Configure the required Algorand Testnet wallets.

The complete flow is:

POST /api/v1/verify/age
        โ”‚
        โ–ผ
HTTP 402
        โ”‚
        โ–ผ
Payment Requirements
        โ”‚
        โ–ผ
USDC Payment
        โ”‚
        โ–ผ
GoPlausible
        โ”‚
        โ–ผ
Algorand Testnet
        โ”‚
        โ–ผ
Settlement TX
        โ”‚
        โ–ผ
Provider Agent
        โ”‚
        โ–ผ
Verification
        โ”‚
        โ–ผ
HTTP 200

Run the independent x402 test client:

npm run test:x402

A successful result should contain a real Algorand Testnet transaction ID.


๐Ÿ”Ž Algorand Testnet Transaction

A successful KLAIM x402 transaction can be independently verified using Lora.

Example

Replace the placeholder below with an actual transaction generated by the project:

https://lora.algokit.io/testnet/transaction/YOUR_REAL_TX_ID

Important: The transaction link above must be replaced with a real KLAIM transaction before final submission.


๐Ÿงช Complete Demo Flow

Run the system in the following order.

Terminal 1 โ€” Start KLAIM

npm run dev

Terminal 2 โ€” Provision an agent

npx tsx scripts/provision-agent.ts

Store the generated:

KLAIM_AGENT_ID
KLAIM_AGENT_KEY

in the appropriate environment/configuration.

Terminal 3 โ€” Execute x402 test

npm run test:x402

Then connect Claude Desktop to:

/api/public/mcp

Ask Claude:

Verify whether the user is over 18 using KLAIM.

Expected architecture:

Claude
   โ†“
MCP
   โ†“
KLAIM
   โ†“
HTTP 402
   โ†“
USDC Payment
   โ†“
GoPlausible
   โ†“
Algorand Testnet
   โ†“
Provider Agent
   โ†“
Credential Verification
   โ†“
ZK Proof
   โ†“
Verified Claim
   โ†“
Claude

๐Ÿ” Security & Privacy

KLAIM is designed around data minimization.

KLAIM does not expose:

โŒ Aadhaar number
โŒ PAN number
โŒ Date of Birth
โŒ Address
โŒ Raw identity document
โŒ Private wallet keys
โŒ Agent private credentials

KLAIM exposes:

โœ“ Verification result
โœ“ Claim
โœ“ Proof metadata
โœ“ Payment receipt
โœ“ Algorand transaction ID

โš ๏ธ MVP Status

KLAIM is currently an MVP / hackathon implementation.

The architecture intentionally separates production integrations behind service interfaces.

Implemented

  • Human / Verifier role separation

  • DID-oriented identity model

  • Credential management

  • MCP server

  • MCP authentication

  • MCP tool discovery

  • Verification API

  • x402 payment boundary

  • Algorand Testnet settlement flow

  • GoPlausible facilitator integration

  • Provider Agent architecture

  • Strands integration point

  • ZK abstraction

  • DigiLocker integration interface

  • Agent provisioning

  • Agent key rotation / revocation

  • Verification history

  • Transaction history

Integration-dependent

DigiLocker production credentials
        โ†“
Official DigiLocker OAuth / issuer integration

Midnight prover
        โ†“
MIDNIGHT_PROVER_URL

Strands / Bedrock
        โ†“
AWS credentials + model configuration

These integrations can be enabled without changing the core MCP and x402 architecture.


๐Ÿš€ Roadmap

Phase 1 โ€” MVP

โœ“ MCP
โœ“ x402
โœ“ Algorand Testnet
โœ“ USDC settlement
โœ“ Agent authentication
โœ“ Credential abstraction
โœ“ Provider Agent
โœ“ Verification API
โœ“ ZK abstraction

Phase 2 โ€” Production Identity

DigiLocker production integration
        โ†“
Verifiable Credentials
        โ†“
DID interoperability

Phase 3 โ€” Production ZK

Midnight prover
        โ†“
Cryptographically verifiable claims

Phase 4 โ€” Agent Economy

KLAIM can become a general-purpose verification marketplace for autonomous agents.

Potential APIs:

verify_age
verify_residency
verify_credential
verify_student_status
verify_business_registration
verify_human

Each verification becomes a machine-payable API.


๐ŸŒ Use Cases

Age-restricted applications

AI Agent
   โ†“
KLAIM
   โ†“
AGE > 18

No DOB is exposed.

Financial onboarding

AI Agent
   โ†“
KLAIM
   โ†“
Credential Valid

The application does not need the complete identity document.

Education

AI Agent
   โ†“
KLAIM
   โ†“
Student Credential = TRUE

Human-only services

AI Agent
   โ†“
KLAIM
   โ†“
Human Verification

๐Ÿ† Why KLAIM?

Most identity systems ask:

"Who is this person?"

KLAIM asks:

"Can I verify the one thing I need to know without seeing everything else?"

KLAIM combines:

Privacy-Preserving Verification
            +
AI Agent Interoperability
            +
Pay-Per-Use Payments
            +
Zero-Knowledge Architecture
            +
On-Chain Settlement

into a single verification API.


๐Ÿ“œ License

MIT

KLAIM

Human Verification Infrastructure for the Agent Economy

Don't send the document.

Prove the claim.

F
license - not found
Not graded
quality - not tested
B
maintenance

Maintenance

โ€“Maintainers
โ€“Response time
โ€“Release cycle
โ€“Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Omicron6/Klaim'

If you have feedback or need assistance with the MCP directory API, please join our Discord server