Veridexa MCP Gateway
README.md
# Veridexa MCP Gateway
Separate, minimal MCP server that exposes the Veridexa S2S API to MCP clients
(e.g. ChatGPT) over **MCP Streamable HTTP**. This project is intentionally
independent of the Veridexa application repository and does not modify it.
## Runtime
- Node.js **>= 20**
- Official `@modelcontextprotocol/sdk`
- Transport: MCP **Streamable HTTP** (`StreamableHTTPServerTransport`) mounted
at `POST/GET/DELETE /mcp`. Deploy behind HTTPS (any reverse proxy / platform
that terminates TLS is fine — the process itself speaks HTTP on `PORT`).
## Upstream
Fixed upstream base URL: `https://veridexa.io`
- `POST https://veridexa.io/api/s2s/verify`
- `GET https://veridexa.io/api/s2s/report/{jobId}`
## Secret handling
- API key is read **only** from `process.env.VERIDEXA_S2S_API_KEY`.
- Sent upstream as `Authorization: Bearer <key>`.
- Never returned in a tool response, never logged, never echoed in errors.
## Tools
Exactly two tools are registered. Nothing else.
### `verify_document`
Submit exactly one document for verification.
Input:
```
{
"filename": string, // e.g. "passport.pdf"
"contentBase64": string, // base64-encoded document bytes
"mimeType"?: string // optional, defaults to "application/octet-stream"
}
```
Behavior: POSTs `multipart/form-data` with a single `file` field to
`https://veridexa.io/api/s2s/verify`. Returns the upstream JSON body verbatim
(typically `{ "jobId": "..." }`).
### `get_report`
Retrieve the production report for a completed job.
Input:
```
{ "jobId": string }
```
Behavior: GETs `https://veridexa.io/api/s2s/report/{jobId}`. Returns the
upstream JSON body verbatim (typically `{ "productionReport": { ... } }`).
Verification results are never modified.
## Scripts
```
npm install
npm run typecheck
npm run build
npm test
VERIDEXA_S2S_API_KEY=vxd_live_... npm start
```
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessSyncing