KeyHalve verify-MCP
Enables AI to verify KeyHalve-sealed documents from any platform. Verifies status, ciphertext integrity, rail attestation, time lock, and issuer trust without requiring decryption keys.
README
KeyHalve verify-MCP
Free, public, no-account MCP server that lets any AI verify KeyHalve-sealed documents — from any platform on the rail (ValidPay, CheckBooks, …). Seal = the door (a platform's paid MCP). Verify = the room (this one, free forever).
- Endpoint:
https://mcp.keyhalve.com/mcp(Streamable HTTP, stateless) - Tools:
keyhalve_verify·keyhalve_status·keyhalve_explain— all read-only, no auth
The blindness rule
This server never receives decryption keys. A verify URL carries the holder's key share in
the #key= fragment; parseInput discards any fragment before any other logic runs, and the
response says so. Verification here covers everything provable without the key:
| Check | Meaning |
|---|---|
| status | active / revoked (with reason) on the issuing platform |
| ciphertext integrity | SHA-256 of the served ciphertext = commitment recorded at issuance (v2) |
| rail attestation | Ed25519-verified against the pinned rail key; dual-sign content binding when present |
| time lock | validity window judged client-side (Patent D semantics) |
| issuer trust | fail-closed: declared at best, never proof |
Reading the sealed contents still happens only in the holder's browser — exactly like the web
verifier. The overall verdict fails closed: any failed check → FAILED — DO NOT TRUST.
Design notes
- Zero runtime dependencies. WebCrypto only; the whole protocol layer is hand-auditable.
Same reasoning as the pinned-key rail client in
keyhalve-website. - Stateless. No sessions, no SSE, no KV, no cookies; every POST gets
application/json. Request bodies are never logged. - Tenant-neutral. Platforms come from the same manifest data as the web verifier
(
TENANT_MANIFESTinsrc/verifier.ts); onboarding a platform = one data entry. - Fail closed. Unreachable rail, malformed share, partial dual-sign binding, unknown id prefix — all report NOT verified, never a soft pass.
Develop / deploy
npm ci
npm run typecheck && npm test # 32 tests
npm run dev # wrangler dev
Deploys are manual (deploy.yml via workflow_dispatch, same discipline as rail/console).
Needs the CLOUDFLARE_API_TOKEN repo secret; the route mcp.keyhalve.com is a custom domain
on the business CF account (same account as the watchdog scheduler).
Directory submissions (Mike-gated)
Submitting to the Claude Connectors Directory / ChatGPT App Directory is an outward-facing step — prepared separately, goes out only on Mike's go.
Listings
Directory-listing assets live in this repo — reuse them, don't invent copy:
llms-install.md— AI-agent install steps (Cline's AI-driven install; also the canonical per-client snippets).glama.json— Glama claim file (maintainers; their live schema is maintainers-only).assets/icon-400.png— 400×400 icon (white split-circle glyph on Ink #0E1116, from the brand kit).- Descriptions must stay byte-consistent with
src/tools.tsand pass the approved-claims register (no "split key", no "tamper-proof", no issuer-identity claims).
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.