Skip to main content
Glama
veridexaweb2026

Veridexa MCP Gateway

README.md
# Veridexa MCP Gateway

Separate, minimal MCP server that exposes the Veridexa S2S API to MCP clients
(e.g. ChatGPT) over **MCP Streamable HTTP**. This project is intentionally
independent of the Veridexa application repository and does not modify it.

## Runtime

- Node.js **>= 20**
- Official `@modelcontextprotocol/sdk`
- Transport: MCP **Streamable HTTP** (`StreamableHTTPServerTransport`) mounted
  at `POST/GET/DELETE /mcp`. Deploy behind HTTPS (any reverse proxy / platform
  that terminates TLS is fine — the process itself speaks HTTP on `PORT`).

## Upstream

Fixed upstream base URL: `https://veridexa.io`

- `POST https://veridexa.io/api/s2s/verify`
- `GET  https://veridexa.io/api/s2s/report/{jobId}`

## Secret handling

- API key is read **only** from `process.env.VERIDEXA_S2S_API_KEY`.
- Sent upstream as `Authorization: Bearer <key>`.
- Never returned in a tool response, never logged, never echoed in errors.

## Tools

Exactly two tools are registered. Nothing else.

### `verify_document`
Submit exactly one document for verification.

Input:
```
{
  "filename": string,               // e.g. "passport.pdf"
  "contentBase64": string,          // base64-encoded document bytes
  "mimeType"?: string               // optional, defaults to "application/octet-stream"
}
```
Behavior: POSTs `multipart/form-data` with a single `file` field to
`https://veridexa.io/api/s2s/verify`. Returns the upstream JSON body verbatim
(typically `{ "jobId": "..." }`).

### `get_report`
Retrieve the production report for a completed job.

Input:
```
{ "jobId": string }
```
Behavior: GETs `https://veridexa.io/api/s2s/report/{jobId}`. Returns the
upstream JSON body verbatim (typically `{ "productionReport": { ... } }`).
Verification results are never modified.

## Scripts

```
npm install
npm run typecheck
npm run build
npm test
VERIDEXA_S2S_API_KEY=vxd_live_... npm start
```

Maintenance

ActivityMaintained
ResponsivenessSyncing