Skip to main content
Glama
izzy-Ti

Fayda MCP

by izzy-Ti

Fayda MCP Python Library (fayda-mcp)

PyPI version License

An importable, headless Python library providing Model Context Protocol (MCP) tools and verification services for Ethiopian National ID (Fayda eSignet).

Key Capabilities

  • Explicit FastMCP Tools: start_verification, get_verification_status, get_verification_result, cancel_verification.

  • Zero Raw Demographic / Biometric Leaks: Outputs minimal boolean predicates (identity_verified, age_over_18), strictly forbidding citizen biometrics, OTPs, or demographic dumps from entering LLM contexts.

  • Cryptographic Security: OIDC PKCE S256, RFC 7523 private_key_jwt client assertions, and strict JWT signature/nonce validation.

  • Pluggable Architecture: Zero mandatory database or web framework runtime dependencies in core; optional extras for FastAPI, Redis, and Neon/PostgreSQL.

  • Multi-Tenant Caller Isolation: Built-in tenant and principal boundaries ensuring Caller A cannot access Caller B verification records.


Related MCP server: signet

Installation

# Core library (headless FastMCP + Fayda OIDC verification engine)
pip install fayda-mcp

# With optional FastAPI integration
pip install "fayda-mcp[fastapi]"

# Full bundle with Redis and Neon/Postgres adapters
pip install "fayda-mcp[fastapi,redis,postgres]"

Quick Start (Sandbox)

import base64
from fayda_mcp import FaydaConfig, FaydaVerificationService
from fayda_mcp.storage.memory import MemorySessionStore, MemoryResultRepository
from fayda_mcp.mcp.factory import create_mcp_server

# Configure your Fayda / eSignet credentials
config = FaydaConfig(
    client_id="YOUR_CLIENT_ID",
    redirect_uri="http://localhost:3000/callback",
    authorization_endpoint="[https://esignet.ida.fayda.et/authorize](https://esignet.ida.fayda.et/authorize)",
    token_endpoint="[https://esignet.ida.fayda.et/v1/esignet/oauth/v2/token](https://esignet.ida.fayda.et/v1/esignet/oauth/v2/token)",
    userinfo_endpoint="[https://esignet.ida.fayda.et/v1/esignet/oidc/userinfo](https://esignet.ida.fayda.et/v1/esignet/oidc/userinfo)",
    issuer="[https://esignet.ida.fayda.et](https://esignet.ida.fayda.et)",
    jwks_uri="[https://esignet.ida.fayda.et/v1/esignet/oauth/v2/jwks.json](https://esignet.ida.fayda.et/v1/esignet/oauth/v2/jwks.json)",
    private_key=base64.b64decode("YOUR_PRIVATE_KEY_B64").decode("utf-8"),
)

service = FaydaVerificationService(
    config=config,
    sessions=MemorySessionStore(),
    results=MemoryResultRepository(),
)

server = create_mcp_server(service=service)

if __name__ == "__main__":
    server.run(transport="stdio")

Running the Complete Sandbox Flow

Run the included standalone sandbox walkthrough:

python examples/sandbox_flow.py

This runs the entire end-to-end lifecycle (starts verification -> builds authorization link -> simulates citizen callback -> queries status -> retrieves privacy-preserving boolean result -> verifies caller isolation) without editing library internals.


Examples


Documentation


License

MIT License. See LICENSE for details.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    MCP server for AI agent identity — verify agents with Ed25519 signatures, check trust scores, sign and verify content, exchange encrypted messages. Built on the Agent Identity Protocol (AIP).
    8
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Open-source MCP server that exposes Signet cryptographic tools over stdio. It provides tools to generate Ed25519 keypairs, sign MCP actions, verify Signet receipts, and compute canonical content hashes for AI agent audit and accountability workflows.
    4
    38
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides AI agents with a DID-based identity, secure wallet, and cloud KMS-backed signing keys, enabling trusted interactions with persons, companies, and other agents via standards like OIDC4VCI, OIDC4VP, and SD-JWT.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to prove knowledge of a private key through a three-pass commitment, challenge, and response exchange, paired with SHA-256 Merkle inclusion proofs, JWT HMAC-SHA256 claim validation, constant-time secret comparison, and sliding-window nonce replay protection. Runs as a zero-dependency JSON-RPC 2.0 stdio server compatible with Claude Desktop, Cursor, and Windsurf.
    7
    MIT