Agent♥︎Age
Catalog

io.github.chudah1/attest-mcp

Official

by chudah1 · Go

Credential enforcement middleware for MCP servers — verifies scoped tokens on every tool call

io.github.chudah1/attest-mcp — Credential enforcement middleware for MCP

The MCP server described by this repository provides credential enforcement middleware for MCP servers. It verifies scoped tokens on every tool call to help ensure risky AI actions are controlled. It supports signed, scope-limited credentials, routes high-risk mutations through policy and optional approval, issues short-lived execution grants, and produces signed receipts.

🛠️ Key Features

  • Verifies scoped tokens on every tool call
  • Signed, scope-limited credentials
  • Policy routing for high-risk mutations (optional approval)
  • Short-lived execution grants
  • Signed receipts that can be verified later

🚀 Use Cases

  • Credential enforcement for MCP server tool calls
  • Controlling “risky AI actions” before they reach production systems
  • Adding policy/approval gates for high-risk mutations

⚡ Developer Benefits

  • Verifiable signed receipts for later verification
  • Scoped token checks per tool call for tighter access control

⚠️ Limitations

  • Source material does not specify tool inventory, configuration options, or supported transports beyond MCP tool calls

Related servers

More in Security