Skip to main content
Glama

witnessd-mcp

MCP server for witnessd — a neutral third-party witness for the machine-readable web.

Give your agent the ability to create tamper-evident evidence: witnessd independently fetches any public URL or API endpoint, hashes and timestamps the response, archives it, and issues a signed certificate. Snapshot hashes are Merkle-batched hourly and anchored on Base, so certificates verify forever — by anyone, without trusting the operator.

Use it before transacting with a counterparty ("witness their published price/terms"), before acting on third-party data ("witness what the API returned"), or whenever a dispute might later hinge on what a URL said at a moment in time.

Tools

Tool

Price

What it does

witness_url

$0.02

Independent fetch + hash + timestamp + archive of a URL right now; returns snapshot id + signed certificate

get_certificate

free

Certificate for any snapshot id: manifest, Ed25519 signature, Merkle proof, Base anchor transaction

retrieve_snapshot

$0.05

The archived response body + certificate — works for any snapshot id, any payer (this is how third parties obtain evidence)

Related MCP server: @citizenofthecloud/mcp-server

Install

npx -y witnessd-mcp

Claude Desktop / Cursor config:

{
  "mcpServers": {
    "witnessd": {
      "command": "npx",
      "args": ["-y", "witnessd-mcp"],
      "env": {
        "EVM_PRIVATE_KEY": "0x…"
      }
    }
  }
}

Payment — two options

Set one of these environment variables:

  • EVM_PRIVATE_KEY — a wallet key holding USDC on Base. The server auto-pays each call via x402 (the buyer only signs; no ETH needed for gas). Use a small dedicated wallet, never your main one.

  • WITNESSD_API_KEY — a prepaid credit key (buy a $1 pack via POST https://witnessd.vip/api/credits, x402-payable).

Optional: WITNESSD_URL to point at a different witnessd instance (default https://witnessd.vip).

Verify without trusting us

Certificates are self-verifying: leaf_hash = sha256(canonical-json(manifest)), Ed25519-signed, Merkle-proven into an hourly batch root anchored on Base (calldata 0x + wtns1 + root). Standalone checker: witnessd.vip/verify.js.

Privacy & scope

Certificates (hashes, timestamps, proofs) are public; archived content is delivered only to paying requesters and never republished. witnessd only witnesses what any stranger can see — no logins, no private networks, bodies ≤10 MB. Machine-readable service docs: llms.txt · openapi.json · /.well-known/x402.

MIT license.

Related MCP Connectors

Related MCP Servers

  • A
    license
    C
    quality
    C
    maintenance
    MCP server for safely reading public URLs for AI agents, providing tools to fetch, extract, cache, and inspect web content as evidence.
    15
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Local MCP server that signs and records agent actions into a tamper-evident log using Ed25519 keys for frictionless integration with Touchstone.
    17 npm
    Apache 2.0