attest-mcp
MCP server for Spazio Genesi's attestation service that enables AI agents to attest, verify, and check digital works with full privacy, as file bytes never leave the device.
README
attest-mcp
MCP server for Spazio Genesi's attestation service — attest, verify, and check the existence of digital works from any MCP-capable AI agent (Claude Code, Claude Desktop, etc.).
Full privacy: file bytes never leave your device. The fingerprint (SHA-256) is computed locally, streamed from disk — only the hash and optional metadata are sent.
What it does
The attestation service timestamps a file's SHA-256 fingerprint, signs it (HMAC), and can produce a signed PDF certificate plus an OpenTimestamps proof anchored in Bitcoin. This server exposes that service as MCP tools, so an agent can attest and verify works on your behalf without a browser.
Install
Claude Desktop — one command, no manual JSON editing:
npx -y @spazio-genesi/attest-mcp-setup
This finds your claude_desktop_config.json (Windows/macOS/Linux), adds the
attest-mcp entry, and backs up the original file first. It refuses to touch
anything if the existing file isn't valid JSON — it never guesses. Restart
Claude Desktop afterwards. To remove it again: add --uninstall. To preview
without writing: add --dry-run.
Claude Code:
claude mcp add attest-mcp -- npx -y @spazio-genesi/attest-mcp
Manual / other clients — add this to your MCP client's config:
{
"mcpServers": {
"attest-mcp": {
"command": "npx",
"args": ["-y", "@spazio-genesi/attest-mcp"]
}
}
}
Authentication
Two ways to authenticate, matching the underlying service:
- API key (for partner integrations, issued manually by Spazio Genesi):
set the
IMGAUTH_API_KEYenvironment variable. - Device flow (for personal/agent use): call the
authorizetool with no arguments. It returns a URL — open it, approve with the human-verification widget, then callauthorizeagain with the returned code. The session token (24h, 20 attestations) is saved to~/.config/attest-mcp/credentials.json(permissions600where supported) and used automatically after that.
Either way, the credential only unlocks the anti-bot check on attestation — the server-side timestamp, cryptographic signature, and rate limits are unchanged.
Tools
| Tool | What it does |
|---|---|
authorize |
Start or continue the device-flow authorization. |
attest_file |
Hash a local file (streamed) and attest it. |
get_certificate_pdf |
Mint a fresh signed PDF, or recover an already-archived one, saved to disk. |
verify_file |
Hash a local file and check it against a declared hash + signature. |
verify_certificate |
Verify a certificate's signature without a local file. |
check_anchor |
Check/download the OpenTimestamps (Bitcoin) proof. |
service_status |
Traffic-light status of the attestation service. |
Configuration
| Env var | Default | Purpose |
|---|---|---|
IMGAUTH_API_KEY |
— | API key credential, bypasses the device flow. |
IMGAUTH_BASE_URL |
https://imgauth.spaziogenesi.org |
Override for local development (http://localhost:8787). |
IMGAUTH_CERT_PAGE_BASE |
https://attestazione.spaziogenesi.org |
Override for the permanent-certificate-page base URL. |
Known limitation
The certificate PDF and its text are in Italian (Spazio Genesi is an Italian non-profit and the certificate is a legal-facing document). The MCP tool descriptions and this README are in English for an international audience.
Development
npm install
npm test # unit tests (hash vectors)
IMGAUTH_BASE_URL=http://localhost:8787 npm start # against a local `wrangler dev`
License
MIT — see LICENSE. This is a client for the attestation service; the service itself (imgauth) is AGPL-3.0.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.