attest-mcp
About
https://github.com/SPAZIO-GENESI/attest-mcp
Details
- Author
- spazio-genesi
- Categories
- Other, Security, Finance
Jump to
Setup
Install attest-mcp in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/spazio-genesi/attest-mcp
Follow the installation instructions in the repository README, then restart your MCP client.
Listed on theofficial MCP Registryasio.github.SPAZIO-GENESI/attest-mcp.
Full privacy: file bytes never leave your device. The fingerprint (SHA-256) is computed locally, streamed from disk — only the hash and optional metadata are sent.
📖 English documentation:attestazione.spaziogenesi.org/en— site, developer docs, and tiers/terms are all available in English.
The attestation service timestamps a file's SHA-256 fingerprint, signs it (HMAC), and can produce a signed PDF certificate plus an OpenTimestamps proof anchored in Bitcoin. This server exposes that service as MCP tools, so an agent can attest and verify works on your behalf without a browser.
Why this, not just an OpenTimestamps wrapper
Several MCP servers can submit a hash to an OpenTimestamps calendar. As far as we know, this is the only one that hands back acomplete proof of existence— a signed PDF certificate, a recognized RFC 3161 timestamp, and a Bitcoin anchor — forfree, with the file's bytes never leaving the caller's machine. No account, no upload, no paid notarization chain. If you know of another MCP server with the same combination (full certificate + free + local hashing), we'd genuinely like to hear about it — open an issue.
Built for the European legal and regulatory context
Spazio Genesi is an Italian non-profit (ETS –Ente del Terzo Settore). The attestation service behind this package was designed with the EU regulatory environment in mind, not adapted to it afterwards:
- GDPR-first, privacy by design: the file itself never reaches our servers — only its SHA-256 fingerprint (and any metadata you choose to declare) is sent.
- EU data residency: certificates and proofs are archived on Cloudflare R2 under EU jurisdiction.
- Recognized timestamping, no single point of trust: every certificate carries an RFC 3161 timestamp from an AATL-rooted authority (trusted by Adobe and most PDF readers)andan independent Bitcoin anchor via OpenTimestamps.
- Honest about eIDAS: this isnot(yet) an eIDAS qualified trust service — the signer identity is currently self-signed, and a qualified electronic seal is a planned but unimplemented upgrade. See thetechnical whitepaperfor the full, unvarnished breakdown of what is and isn't guaranteed.
Full tiers and terms:attestazione.spaziogenesi.org/en/condizioni.
Claude Desktop— one command, no manual JSON editing:
This finds yourclaude_desktop_config.json(Windows/macOS/Linux), adds theattest-mcpentry, and backs up the original file first. It refuses to touch anything if the existing file isn't valid JSON — it never guesses. Restart Claude Desktop afterwards. To remove it again: add--uninstall. To preview without writing: add--dry-run.
claude mcp add attest-mcp -- npx -y @spazio-genesi/attest-mcp
Manual / other clients— add this to your MCP client's config:
{ "mcpServers": { "attest-mcp": { "command": "npx", "args": ["-y", "@spazio-genesi/attest-mcp"] } } }
Two ways to authenticate, matching the underlying service:
- API key(for partner integrations, issued manually by Spazio Genesi): set theIMGAUTH_API_KEYenvironment variable.
- Device flow(for personal/agent use): call theauthorizetool with no arguments. It returns a URL — open it, approve with the human-verification widget, then callauthorizeagain with the returned code. The session token (24h, 20 attestations) is saved to~/.config/attest-mcp/credentials.json(permissions600where supported) and used automatically after that.
Either way, the credential only unlocks the anti-bot check on attestation — the server-side timestamp, cryptographic signature, and rate limits are unchanged.
Same package, no separate install. The CLI is abinalongside the MCP server, sharing the same hashing/API/config code — same full privacy (streamed local hash, file bytes never sent), same credentials.
npx -y -p @spazio-genesi/attest-mcp sg-attest attest ./work.png npx -y -p @spazio-genesi/attest-mcp sg-attest verify ./work.png --hash <sha256>
(-pis required:sg-attestis a secondarybinof the package, and plainnpx -y @spazio-genesi/attest-mcpruns the MCP server instead.)
One advantage over the site:no 1 GB cap. The browser is limited by WebCrypto (which loads the whole file into memory); this CLI streams from disk on Node, so it can attest files of any size.
Every command accepts--json(emits one JSON object on stdout, for scripting) and--quiet(reduces non-essential human-readable output). Errors go to stderr; the CLI never prints a credential (API key or session token) to stdout, stderr, or--jsonoutput — same discipline as the MCP server.
Exit codes(a stable contract, for CI/scripting):
Authentication is the same as the MCP server:IMGAUTH_API_KEYenv var, or a session token saved bysg-attest authorize(device flow). There is no--keyflag — a credential on the command line ends up in shell history; use the env var (or a CI secret) instead.
A GitHub Action that uses this CLI to attest build artifacts in CI lives in a companion repo:attest-action.
For a machine or CI runner without Node.js, download a pre-compiledsg-attestexecutable from theReleases page— same commands, same behavior, nothing to install.
Each release also includesSHA256SUMS.txt. Verify the download before running it:
sha256sum -c SHA256SUMS.txt --ignore-missing # Linux/macOS
(Get-FileHash .\sg-attest-windows-x64.exe -Algorithm SHA256).Hash # compare by eye to SHA256SUMS.txt
⚠️ The binaries arenot code-signed: expect an "unknown publisher" warning from Windows SmartScreen or macOS Gatekeeper the first time you run one. The checksum above is the integrity guarantee in the meantime — the binary is built and published byGitHub Actionsdirectly from this repo's source, nothing hand-uploaded.
Usage is identical to the npm-installed CLI, just call the file directly:
chmod +x ./sg-attest-linux-x64 # Linux/macOS only ./sg-attest-linux-x64 attest ./work.png --pdf cert.pdf ./sg-attest-linux-x64 status
npx/npmremain the primary distribution channel (and whatattest-actionuses in CI) — the binaries are an additional channel, not a replacement.
The checksum above answers "is this file intact?" — it says nothing aboutwhere the bytes came from. Every release sincev0.4.2also carries a signedbuild provenance attestation(actions/attest-build-provenance, jobreleaseinrelease-binaries.yml): cryptographic proof that the file was built by this repo's own workflow, from a specific commit and tag, not hand-uploaded or swapped afterward.
The GitHub CLI can verify it, butgh attestation verifyrequires anauthenticatedghsession even on this public repo (confirmed: it fails with "please run gh auth login" without one) — a real gap if the point is a check anyone can run with zero setup:
gh attestation verify sg-attest-linux-x64 --repo SPAZIO-GENESI/attest-mcp
scripts/verify-provenance.mjsdoes the same verificationwith no GitHub credentials at all— only the public attestations REST endpoint (confirmed reachable unauthenticated, even on this public repo) and thesigstorelibrary, which checks the signature against Sigstore's own public infrastructure (Rekor, Fulcio, TUF — no account needed there either):
git clone https://github.com/SPAZIO-GENESI/attest-mcp cd attest-mcp && npm install node scripts/verify-provenance.mjs ./sg-attest-linux-x64 \ --repo SPAZIO-GENESI/attest-mcp --tag v0.4.2
Exits0on success,1if the file doesn't match anything the workflow actually built (e.g. a single altered byte makes the digest — and therefore the lookup key itself — no longer match any attestation).
If your client reports"Server disconnected", check its log first: this server writes diagnostics to stderr, which MCP clients capture. On Claude Desktop the log lives in%APPDATA%\Claude\logs\mcp-server-attest-mcp.log(Windows) or~/Library/Logs/Claude/mcp-server-attest-mcp.log(macOS).
You should see one line per lifecycle event:
[attest-mcp 2026-07-21T11:14:12.948Z] v0.2.2 ready on stdio (node v22.22.2, pid 32316) [attest-mcp 2026-07-21T11:14:12.965Z] exiting (code 0)
- exiting (code 0)— ordinary shutdown: the client closed stdin. After a laptop sleep or a client restart this is expected; just restart the client to reconnect.
- fatal: …followed byexiting (code 1)— a real crash, with the stack trace on the preceding line. Pleaseopen an issuewith it.
- Noreadyline at all — the process never started: check thatnodeis on PATH and at least v18 (node --version).
stdout carries the JSON-RPC protocol and is never used for logging.
The certificate PDF and its text are inItalian(Spazio Genesi is an Italian non-profit and the certificate is a legal-facing document). The MCP tool descriptions and this README are in English for an international audience.
npm install npm test # unit tests (hash vectors, CLI argument parsing) IMGAUTH_BASE_URL=http://localhost:8787 npm start # MCP server against a local wrangler dev IMGAUTH_BASE_URL=http://localhost:8787 node src/cli.js status # CLI against the same
test/cli-smoke.local.mjsis a local-only harness (not run bynpm test) that exercises everysg-attestcommand end-to-end against an isolatedwrangler devimgauth instance — see the header comment in that file for the required env vars.
Report vulnerabilities →/sicurezza/(responsible disclosure policy, safe harbor for good-faith research) — this repo has nosecurity.txtof its own (npm package, no static assets), but the policy covers the whole project.
Bug reports and feature requests:open an issue. Pull requests are welcome — keep them focused (one change per PR), make surenpm testpasses, and explain the "why" in the description, not just the "what".Test policy: any PR that adds new functionality should add a test for it undertest/;npm run lintandnpm testboth run in CI on every push and pull request. For anything that touches the attestation contract itself (hashing, HMAC verification, the API surface), open an issue first: this client mirrors a contract owned byimgauth, so changes need to stay compatible with it.
MIT — seeLICENSE. This is a client for the attestation service; the service itself (imgauth) is AGPL-3.0.
Turns the Agent into a vLEI/KERI protocol expert
Personal wealth & portfolio tracker — 23 OAuth-scoped tools for holdings, performance, FIRE status, crypto P&L, and confirm-gated transaction writes across 20+ markets.
ALTER - identity infrastructure for the AI economy
Auth0, but for agents. Identity and authentication service for AI agents.
AgentTrust is a pure MCP-only reputation and trust scoring server for AI agents.
Drive a personal UK Tesco grocery account: search, basket, delivery slots, orders, and on-pack nutrition. Filter and rank products by macros + micros. Catalogue and nutrition tools need no auth.
Latvian property portal MCP: search rentals, sales & nightly stays, market stats; owner tools via OAuth. Remote server at https://bezbaseina.lv/mcp
Live space data for AI agents — rocket launches, ISS passes, launch news. Free, no auth.
It connects Agents to data wallet with DID and verifiable credentials
An observatory that probes every MCP server in the official MCP registry and reports which ones actually work: live, auth-gated, dead, or erroring.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



