Skip to main content
Glama

tppv

Open-source CLI and MCP server for TPP Validation. Source: github.com/tppv-dev/tppv.

They talk to the hosted API (api.tppvalidation.com/v5). The validation engine itself stays a service — these packages are how you call it from a terminal or an agent.

Apache-2.0.

Install

npm install -g @tppv-dev/cli @tppv-dev/mcp

or without npm global:

# macOS / Linux
curl -fsSL https://tppv.dev/cli/install.sh | bash

# Windows (PowerShell)
irm https://tppv.dev/cli/install.ps1 | iex

From this repo:

npm install
npx tppv --help

Related MCP server: MCP Gatekeeper

CLI

tppv                              # interactive
tppv path/to/qsealc.pem           # drop-validate
tppv validate -f ./qsealc.pem --cc SE,FI
tppv trial --email dev@bank.com
tppv config token <jwt>
tppv integration --gateway kong --out ./gateway

Token is stored in ~/.config/tppv/config.json (Windows: %LOCALAPPDATA%\tppv\config.json). Existing ~/.config/tpp files are still read.

MCP (local stdio)

Same three tools as the hosted server: validate_certificate, audit_chain, search_entity.

Token from TPPV_TOKEN or the CLI config file.

Cursor / Claude Desktop

{
  "mcpServers": {
    "tppv": {
      "command": "npx",
      "args": ["-y", "@tppv-dev/mcp"],
      "env": {
        "TPPV_TOKEN": "your-jwt"
      }
    }
  }
}

Hosted alternative (no local process): https://ai.tppvalidation.com/mcp.

Packages

Package

What

@tppv-dev/cli

tppv command

@tppv-dev/mcp

stdio MCP server

Not in this repo

The Rust validator, Slack/Teams bots, marketplace, and hosted MCP worker are the product. This repo is the client surface.

License

Apache-2.0. See LICENSE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables checking trust of MCP tools before installation, listing trusted tools, and scoring MCP stacks via the Veragent trust registry.
    3
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables read-only verification of Foster Rx certificates against the public Ed25519 trust anchor, returning verdicts such as verified, signature_invalid, not_found, or tool_fault, and also allows retrieval of certificate records and trust anchor material.
    -