MCP Hub
Back to servers

attest-mcp

Validation Failed

Credential enforcement middleware for MCP servers — verifies scoped tokens on every tool call

Registry
Stars
1
Updated
Apr 11, 2026
Validated
May 11, 2026

Validation Error:

Process exited with code 1. stderr: npm error could not determine executable to run npm error A complete log of this run can be found in: /home/runner/.npm/_logs/2026-05-11T03_05_24_678Z-debug-0.log

Quick Install

npx -y @attest-dev/mcp

Attest

License: Apache 2.0

Attest is a cryptographic credentialing standard for AI agent pipelines. When an orchestrator spawns sub-agents to complete a task, Attest issues each agent a short-lived, scope-limited JWT that is cryptographically bound to the original human instruction via a SHA-256 intent hash. Every delegation narrows scope, cannot outlive the parent, and is recorded in an append-only, hash-chained audit log — so the full chain of authority from a human principal down to any tool call is provable, revocable in a single operation, and independently verifiable by any party with access to the public key.


Quickstart (TypeScript)

import { AttestClient, isScopeSubset } from '@attest-dev/sdk';

const client = new AttestClient({ baseUrl: 'http://localhost:8080', apiKey: 'dev' });

// 1. Issue a root credential for your orchestrator
const { token: rootToken, claims: root } = await client.issue({
  agent_id:    'orchestrator-v1',
  user_id:     'usr_alice',
  scope:       ['research:read', 'gmail:send'],
  instruction: 'Research our top 3 competitors and email a summary to the board',
});

// 2. Delegate a narrowed credential to a sub-agent
const { token: childToken, claims: child } = await client.delegate({
  parent_token: rootToken,
  child_agent:  'email-agent-v1',
  child_scope:  ['gmail:send'],        // subset of parent — enforced server-side
});

// 3. Verify offline (no network call after fetching JWKS once)
const jwks   = await client.fetchJWKS('org_abc123');
const result = await client.verify(childToken, jwks);
console.log(result.valid, result.warnings);

// 4. Revoke the entire task tree in one call
await client.revoke(root.jti);

// 5. Retrieve the tamper-evident audit chain
const chain = await client.audit(root.att_tid);
chain.events.forEach(e => console.log(e.event_type, e.jti, e.created_at));

Scope syntax

Scopes follow the pattern resource:action. Either field may be * as a wildcard.

ExpressionMeaning
gmail:sendSend via Gmail only
gmail:*All Gmail actions
*:readRead access to any resource
*:*Full access (root grants only)

Delegation enforces that the child scope is a strict subset of the parent scope. The utility isScopeSubset(parentScope, childScope) replicates this check client-side.


Getting started

Prerequisites: Docker and Docker Compose.

# Clone and start everything
git clone https://github.com/attest-dev/attest
cd attest
docker compose up

# The server is now running at http://localhost:8080
# PostgreSQL at localhost:5432

# Issue your first credential (replace YOUR_API_KEY with the key from POST /v1/orgs)
curl -s -X POST http://localhost:8080/v1/credentials \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer YOUR_API_KEY' \
  -d '{
    "agent_id":    "orchestrator-v1",
    "user_id":     "usr_alice",
    "scope":       ["research:read", "gmail:send"],
    "instruction": "Research competitors and email the board"
  }' | jq .

# Open the interactive demo
open demo/index.html

Without Docker (dev mode — ephemeral key, no database):

cd server
go run ./cmd/attest          # starts on :8080, warns about missing DB

API reference

MethodPathDescription
POST/v1/orgsCreate an organization and get an API key
POST/v1/credentialsIssue a root credential
POST/v1/credentials/delegateDelegate to a child agent
DELETE/v1/credentials/{jti}Revoke credential and all descendants
GET/v1/revoked/{jti}Check revocation status (public, no auth)
GET/v1/tasks/{tid}/auditRetrieve the audit chain for a task
POST/v1/audit/reportReport an agent action to the audit log
POST/v1/audit/statusReport agent lifecycle event (started/completed/failed)
POST/v1/approvalsRequest human-in-the-loop approval
POST/v1/approvals/{id}/grantGrant a pending HITL approval
GET/orgs/{orgId}/jwks.jsonPublic key set for offline verification
GET/healthHealth check

Specification

The credential format is defined in spec/WCS-01.md (Attest Credential Standard, revision 01).


License

Apache 2.0 — see LICENSE.

Reviews

No reviews yet

Sign in to write a review