tatastu-proof

tatastu-proof

Enables creating and verifying permanent, publicly verifiable content provenance stamps via MCP tools.

Category
Visit Server

README

Tatastu Proof

One API call stamps any content with a permanent, publicly verifiable provenance record. Works from any language, any agent, any pipeline.

import { stamp, hashText } from "@tatastu/proof"

const hash = await hashText("Hello, world!")
const receipt = await stamp({ contentHash: hash, title: "My post" })
console.log(receipt.verifyUrl)
// → https://tatastu.dev/p/prf_01jz...

Live service: proof.tatastu.dev — verification is always free.


What it does

A stamp takes the SHA-256 of any content (text, file, JSON, code, binary) and records:

  • Who signed it (a creator identity you provide, or anonymous)
  • When it was signed (millisecond-precision, bounded by the daily Merkle anchor)
  • An Ed25519 signature from the Tatastu Proof service's key-transparency log

Within 24 hours, stamps are batched into an RFC 6962 Merkle tree. The root is anchored to Arweave (permanent storage) and Base (EVM on-chain calldata). After anchoring, you can verify the stamp with zero network calls using the offline verifier in this repo.

What a stamp does not prove: authorship truth. The service records "this signer claimed this content at this time." The claimed time (signedAt) and proven time (anchored) are distinct and both shown on every verify page.


Install

npm install @tatastu/proof

Or use without installing:

npx tsx examples/eu-ai-act-label.ts

Quickstart

Stamp text

import { stamp, hashText } from "@tatastu/proof"

const hash = await hashText("The report content goes here.")
const receipt = await stamp({ contentHash: hash, title: "Q3 Report" })
console.log(receipt.verifyUrl)   // https://tatastu.dev/p/prf_...
console.log(receipt.byline)      // "Verified · https://tatastu.dev/p/prf_..."

Stamp a file (Node.js)

import { stamp, hashNodeBuffer } from "@tatastu/proof"
import { readFile } from "node:fs/promises"

const bytes = await readFile("./report.pdf")
const receipt = await stamp({
  contentHash: await hashNodeBuffer(bytes),
  contentType: "application/pdf",
  title: "Q3 Financial Report",
  apiKey: process.env.TATASTU_API_KEY,
})

Verify any content

import { verify, hashText } from "@tatastu/proof"

const { proofs } = await verify(await hashText("The report content goes here."))
if (proofs.length > 0) {
  console.log("Authentic:", proofs[0].verifyUrl)
  console.log("Status:", proofs[0].status)   // SIGNED | ANCHORED | CONFIRMED
}

Stamp a file in the browser (drag-and-drop)

import { stamp, hashBlob } from "@tatastu/proof"

const file = dropEvent.dataTransfer.files[0]
const receipt = await stamp({
  contentHash: await hashBlob(file),
  title: file.name,
})

See examples/browser-drop.html for a complete self-contained verify page with no build step.


MCP (agent use)

Add proof.tatastu.dev/mcp to your Claude Code, Cursor, or Windsurf config:

{
  "mcpServers": {
    "tatastu-proof": {
      "url": "https://proof.tatastu.dev/mcp"
    }
  }
}

The agent can then call create_proof and verify_proof directly. See examples/agent-mcp.md for the full config and tool reference.


EU AI Act compliance

EU AI Act Article 50(4) requires machine-readable provenance on AI-generated content. The deadline is 2 August 2026.

import { stamp, hashText } from "@tatastu/proof"

const aiOutput = "AI-generated text goes here."
const receipt = await stamp({ contentHash: await hashText(aiOutput) })

const labeledOutput = {
  text: aiOutput,
  _proof: {
    contentHash: receipt.contentHash,
    proofId: receipt.proofId,
    verifyUrl: receipt.verifyUrl,
    signedAt: receipt.signedAt,
    bylineHtml: receipt.bylineHtml,
  },
}

Run the full example with no setup:

npx tsx examples/eu-ai-act-label.ts

See docs/eu-ai-act.md for the compliance guide.


How verification works

Every stamp is:

  1. Signed immediately with an Ed25519 key from the service's transparency log
  2. Batched daily into an RFC 6962 Merkle tree (0x00/0x01 domain-separated prefixes)
  3. Anchored — the Merkle root written to Arweave (permanent) and Base (on-chain calldata)
  4. Confirmed once the Arweave transaction has sufficient confirmations

After anchoring you can verify with the public key and inclusion path — no network, no trust, no service required.

Four verified layers on every verify page

  1. Ed25519 signature — the service signed the canonical receipt
  2. RFC 6962 Merkle inclusion — the stamp is in the anchored batch
  3. Arweave anchor — the Merkle root is on Arweave
  4. Base calldata — the root is in an EVM transaction on Base

Offline verification

After a stamp reaches ANCHORED status, you can verify it with no network calls:

import { getBundle, hashNodeBuffer } from "@tatastu/proof"
import { verifyOffline } from "@tatastu/proof/verify/offline"
import { readFile } from "node:fs/promises"

const bytes = await readFile("./report.pdf")
const bundle = await getBundle("prf_01jz...")
const result = await verifyOffline(bundle, await hashNodeBuffer(bytes))
console.log(result.valid, result.signatureVerified, result.merkleVerified)

verify/offline.ts is a single 200-line file with zero dependencies. Copy it into any project. It uses only the Web Crypto API (SubtleCrypto), available in Node 18+, Deno, and modern browsers.


Pricing

Tier Price Stamps
Free $0 25/month
Starter bundle $8 100 (no expiry)
Creator bundle $35 500 (no expiry)
Creator subscription $12/month 500/month
Pay-per-stamp (x402) $0.10 or $0.05 with API key

Verification is always free and requires no account.

Full pricing: docs/pricing.md and tatastu.dev/proof.


Contributing

See CONTRIBUTING.md. The service, Worker, and D1 schema are in a private repo — this repo contains only the public SDK, offline verifier, and examples.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured