dsh-credential-retirement-proof
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@dsh-credential-retirement-proofVerify the credential retirement settlement receipts for this rotation."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
dsh-credential-retirement-proof
Offline, deterministic evidence that a supplied credential rotation activated a new credential for every declared consumer, rejected the old credential, stayed inside its overlap window and reached a fresh zero-residual closure. Inputs and reports contain hashes and bounded public metadata only—never secrets.
This is deliberately not another key rotator. Existing DSH plugins such as dsh-key-rotation and dsh-llm-key-rotation perform pool switching and failover. This plugin performs no issuance, distribution, switching, revocation, probing or live-system query. It only recomputes a redacted settlement verdict from explicit receipts.
npm test
npm run check
node bin/dsh-credential-retirement-proof.mjs verify examples/settled.jsonDSH tools: dsh_credential_retirement_inspect and dsh_credential_retirement_verify. MCP exposes equivalent proof-only inline tools. Reports explicitly retain authenticatesReceipts: false, provesConsumerSetExhaustive: false, and provesAbsenceOfUndeclaredBindings: false.
References: NIST SP 800-57 Part 1 Rev. 5 and NIST SP 800-63B revocation/termination guidance.
MIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
Cryptographically anchored evidence for agents: verified run receipts, proof-gated settlement.
Post-quantum, tamper-evident receipts for agent actions. Ed25519 + ML-DSA-65, offline verify.
Issue & verify signed (ed25519), hash-chained, timestamped provenance receipts for agent actions.
Paid cryptographic witness for agents: seal, attest, receipts. x402 USDC/Base.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceVerifies signed SAR v0.1 settlement receipts offline using Ed25519 signatures and bundled key registry.-
- AlicenseNot gradedqualityBmaintenanceProvides tools to create, run, and verify deterministic delivery receipts for completion claims, enabling reviewers to check freshness and correctness of evidence.MIT
- AlicenseAqualityBmaintenanceEnables AI agents to create cryptographically verifiable receipts of their delegated work, with capabilities for multi-party approval and offline verification.1154Apache 2.0
- AlicenseNot gradedqualityBmaintenanceIssue and verify signed receipts for agent actions, enabling durable, independently checkable proof of policy decisions. Supports offline verification via get_keyset and verify_receipt tools without an account.0Inno Setup