MCP-Server

Council of AI GSPC

io.github.CSOAI-ORG/gspc
Daten & Analytik Recht & Compliance Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Publishes and verifies signed measurement cards, trust snapshots, registry evidence, and machine-readable compliance-related evidence without issuing certifications.

art50_marking_evidence
Article 50 marking evidence (paid, x402; preview free)
PAID (x402 or CSOAI LTD invoice). Article 50 marking-evidence pack via https://councilof.ai/api/art50/marking-evidence: is a machine-readable mark DETECTABLE in these bytes right now (C2PA manifest store, assertion hashes, hard binding, claim signature; IPTC digitalSourceType), beside the verbatim Art 50(2) excerpt hash and the Art 99(4) ceiling. Watermarks are UNCHECKABLE where no public detector exists and the pack says so. Point-in-time detection — never a conformity opinion, never a compliance word of any kind. preview=true is free and returns the same measurement unsigned. Without x_payment the tool returns the 402 challenge. If the route is not deployed on this origin the tool says NOT_DEPLOYED rather than inventing a result.
Externer Zugriff
Eingabeschema
{'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Public http(s) URL of the generative output to measure (â\x89¤20 MiB).'}, 'preview': {'type': 'boolean', 'description': 'true = free unsigned measurement (no card sha, no signature).'}, 'bytes_b64': {'type': 'string', 'description': 'Alternatively the output bytes, base64 (â\x89¤20 MiB decoded).'}, 'x_payment': {'type': 'string', 'description': 'The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge.'}, 'manifest_b64': {'type': 'string', 'description': 'Alternatively a detached C2PA manifest store, base64 (manifest-only mode).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['status'], 'properties': {'tool': {'type': 'string'}, 'route': {'type': 'string'}, 'status': {'type': 'string', 'description': 'PAYMENT_REQUIRED, DELIVERED, NOT_DEPLOYED, UNREACHABLE, UNREADABLE_RESPONSE, BAD_ARGUMENTS or HTTP_<code>'}, 'accepts': {'type': 'array'}, 'resource': {'type': 'object'}, 'deliverable': {}, 'http_status': {'type': 'integer'}, 'x402Version': {'type': 'integer'}, 'delivery_state': {'type': 'string'}, 'settlement_state': {'type': 'string'}, 'payment_presented': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}}, 'description': "The wrapper's status fields. On PAYMENT_REQUIRED (isError:true) the route's x402 PaymentRequired object (x402Version, resource, accepts, extensions) is spread at the top level too, per the x402 MCP transport."}
board_totals
Live GSPC board totals
Live GSPC board totals from https://councilof.ai/api/gspc. Returns the slot count and the measured count as two labelled numbers WITH their kind — a slot is a declared position on the board, a measurement is a real run behind it; the two are never summed and never swapped — plus the board's separation line, and as_of dates for the board and for this fetch. Compact by default; pass detail "full" for the long-form count grammar, the per-family counts and the board's full measured_on block. We measure, never certify. If the board cannot be fetched the answer is a distinct UNREACHABLE state: no cached number is ever presented as live.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'detail': {'enum': ['summary', 'full'], 'type': 'string', 'default': 'summary', 'description': "summary (default): counts, public_count, the separation line, dates and source. full: also count_grammar, by_family and the board's measured_on block."}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'as_of': {}, 'state': {'type': 'string', 'description': 'LIVE or UNREACHABLE'}, 'counts': {'type': 'array', 'items': {'type': 'object', 'properties': {'kind': {'type': 'string'}, 'name': {'type': 'string'}}}}, 'detail': {'type': 'string', 'description': 'summary or full'}, 'source': {'type': 'string'}, 'by_family': {}, 'separation': {}, 'public_count': {'type': ['string', 'null']}, 'count_grammar': {}, 'not_a_certification': {'type': 'boolean'}}}
commission_card
Commission a measurement card (paid, x402)
PAID (x402). Commission one signed card-v0 receipt (surface ras.commission) for a named subject on the frozen bank via https://councilof.ai/api/request-attestation. Re-serves every signed measurement card already on file for the subject; a payment never mints a MEASURED cell (fresh_run stays UNMEASURED until a published run exists). Without x_payment the tool returns the 402 challenge (accepts[] with asset, amount, payTo) plus a free preview of the cards already on file. Measurement, not certification — never a rank, a grade or a certificate. Verification stays free.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['subject'], 'properties': {'axis': {'type': 'string', 'description': 'Optional axis slug; omit for the subject-level commission.'}, 'subject': {'type': 'string', 'description': 'Subject to commission: a model id, instrument id or card sha (1-120 chars of [A-Za-z0-9._:/@+-]).'}, 'x_payment': {'type': 'string', 'description': 'The X-PAYMENT header value (base64 x402 payload) signed by your wallet against accepts[] from the previous 402. Omit to receive the challenge.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['status'], 'properties': {'tool': {'type': 'string'}, 'route': {'type': 'string'}, 'status': {'type': 'string', 'description': 'PAYMENT_REQUIRED, DELIVERED, NOT_DEPLOYED, UNREACHABLE, UNREADABLE_RESPONSE, BAD_ARGUMENTS or HTTP_<code>'}, 'accepts': {'type': 'array'}, 'resource': {'type': 'object'}, 'deliverable': {}, 'http_status': {'type': 'integer'}, 'x402Version': {'type': 'integer'}, 'delivery_state': {'type': 'string'}, 'settlement_state': {'type': 'string'}, 'payment_presented': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}}, 'description': "The wrapper's status fields. On PAYMENT_REQUIRED (isError:true) the route's x402 PaymentRequired object (x402Version, resource, accepts, extensions) is spread at the top level too, per the x402 MCP transport."}
evidence_bundle
Evidence bundle for one obligation (paid, x402; preview free)
PAID (x402). An evidence bundle for ONE obligation (article-50, article-53 GPAI transparency, dora or cra) and an optional subject via https://councilof.ai/api/evidence-bundle: OSCAL 1.1.0 assessment-results assembled only from already-signed measurement cards (each with its card bytes and Merkle inclusion proof), plus one manifest card-v0, signed when the signing key is present. Observations are relevant-to the obligation, never satisfied or not satisfied; zero relevant cards ships as an empty bundle, and the free preview says so first (preview=true here, or the free tool evidence_bundle_preview). Article 53 output is evidence for review, not a legal determination. Evidence for obligation work — not a conformity assessment, certification, audit opinion or compliance determination; grants no status. Measurement, not certification. Without x_payment the tool returns the 402 challenge, which is the only place terms appear. Verification of any card is free at https://councilof.ai/gspc-verify.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['obligation'], 'properties': {'preview': {'type': 'boolean', 'description': 'true = the free preview (relevant-card count and first cards); nothing is charged.'}, 'subject': {'type': 'string', 'maxLength': 120, 'description': 'Optional: a model id, vendor or instrument the cards must name.'}, 'x_payment': {'type': 'string', 'description': 'The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge.'}, 'obligation': {'enum': ['article-50', 'article-53', 'dora', 'cra'], 'type': 'string', 'description': 'article-50, article-53, dora or cra.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['status'], 'properties': {'tool': {'type': 'string'}, 'route': {'type': 'string'}, 'status': {'type': 'string', 'description': 'PAYMENT_REQUIRED, DELIVERED, NOT_DEPLOYED, UNREACHABLE, UNREADABLE_RESPONSE, BAD_ARGUMENTS or HTTP_<code>'}, 'accepts': {'type': 'array'}, 'resource': {'type': 'object'}, 'deliverable': {}, 'http_status': {'type': 'integer'}, 'x402Version': {'type': 'integer'}, 'delivery_state': {'type': 'string'}, 'settlement_state': {'type': 'string'}, 'payment_presented': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}}, 'description': "The wrapper's status fields. On PAYMENT_REQUIRED (isError:true) the route's x402 PaymentRequired object (x402Version, resource, accepts, extensions) is spread at the top level too, per the x402 MCP transport."}
evidence_bundle_preview
Signed cards relevant to one obligation (free)
For ONE obligation (article-50, article-53 GPAI transparency, dora or cra) and an optional subject: the obligation record, its counsel-gate status and the already-signed measurement cards that are relevant to it (count plus the first cards, each with its verify link), read live from https://councilof.ai/api/evidence-bundle. Relevant-to is never a determination: no answer says satisfied or not satisfied, and zero relevant cards is answered EMPTY, never as an error and never as a clean bill. Article 53 output is evidence for review, not a legal determination. Evidence for obligation work — not a conformity assessment, certification, audit opinion or compliance determination; grants no status. Measurement, not certification. Verification of any card is free at https://councilof.ai/gspc-verify.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['obligation'], 'properties': {'subject': {'type': 'string', 'maxLength': 120, 'description': 'Optional: a model id, vendor or instrument the cards must name. Omit for the obligation-wide selection.'}, 'obligation': {'enum': ['article-50', 'article-53', 'dora', 'cra'], 'type': 'string', 'description': 'article-50 (AI-generated content marking), article-53 (GPAI provider documentation), dora (ICT third-party oversight) or cra (Cyber Resilience Act).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'cards': {'type': 'array', 'items': {'type': 'object'}}, 'state': {'enum': ['RELEVANT_CARDS_FOUND', 'EMPTY', 'UNKNOWN_OBLIGATION', 'BAD_ARGUMENTS', 'UNREACHABLE'], 'type': 'string'}, 'corpus': {}, 'reason': {'type': 'string'}, 'source': {'type': 'string'}, 'subject': {'type': ['string', 'null']}, 'relation': {'type': 'string'}, 'obligation': {'type': 'object'}, 'review_note': {'type': 'string'}, 'determination': {'type': 'string', 'const': 'NONE'}, 'counsel_confirmed': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}, 'relevant_signed_cards': {'type': 'integer'}}}
get_axis
One GSPC board axis
One axis row from the live GSPC board at https://councilof.ai/api/gspc — every axis the board carries, behavioural and financial families alike, addressed by the axis id exactly as the board spells it: n, accuracy, interval, MEASURED or UNMEASURED status, family, kind, the bank or run-artifact URL behind the row, and dates. An unmeasured axis is a first-class answer — a declared slot with no run behind it, published so the gap is visible — never an error and never a zero. Never a certification.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['axis'], 'properties': {'axis': {'type': 'string', 'description': 'The axis name as it appears on the board, e.g. governance, safety, jail, provenance-controls. Case-insensitive. An unknown name returns the list of names the board actually carries.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'n': {}, 'axis': {'type': ['string', 'null']}, 'state': {'type': 'string', 'description': 'LIVE, NOT_ON_BOARD, BAD_INPUT or UNREACHABLE'}, 'family': {}, 'leader': {}, 'source': {'type': 'string'}, 'status': {'type': ['string', 'null']}, 'dataset': {}, 'accuracy': {}, 'interval': {}, 'measured': {'type': 'boolean'}, 'board_carries': {'type': 'array'}, 'resolved_from': {'type': 'string', 'description': 'present when the caller named an alias (e.g. gov) that resolved to this board axis'}, 'not_a_certification': {'type': 'boolean'}}}
get_card
One public-root card-v0 leaf
GET one public-root card-v0 leaf by sha256 (64 hex) from https://councilof.ai/cards/{sha16}.json. UNMEASURED cells stay visible. States: VALID (fetched); NOT_IN_THIS_CORPUS (the id is in the signed card index, not the public root, so use verify_card on it); INVALID (in neither the live root nor the signed card index); UNCHECKABLE (a source could not be read). Not a GSPC measurement-card.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': '64-char hex payload SHA-256 of the card-v0 leaf.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'next': {'type': 'object', 'description': 'With NOT_IN_THIS_CORPUS: the tool call that checks this id.'}, 'state': {'type': 'string', 'description': 'VALID, NOT_IN_THIS_CORPUS, INVALID or UNCHECKABLE'}, 'corpus': {'type': 'string', 'description': 'With NOT_IN_THIS_CORPUS: the set the id belongs to (signed_card_index).'}, 'reason': {'type': 'string'}, 'sha256': {'type': 'string'}, 'source': {'type': 'string'}, 'surface': {}, 'card_url': {'type': ['string', 'null'], 'description': 'With NOT_IN_THIS_CORPUS: the signed card body to pass to verify_card.'}, 'not_gspc': {'type': 'boolean'}, 'unmeasured': {}, 'sig_ed25519': {}}}
get_root
Public Merkle root
GET the permissionless public-root at https://councilof.ai/root.json. Returns merkle_root, card_count, as_of, and UNMEASURED notes. Separate from GSPC. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable). Never a certificate.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'kind': {}, 'as_of': {}, 'state': {'type': 'string', 'description': 'VALID, UNREACHABLE or UNCHECKABLE'}, 'source': {'type': 'string'}, 'not_gspc': {'type': 'boolean'}, 'card_count': {}, 'merkle_root': {'type': ['string', 'null']}}}
list_cards
List signed card index rows
The published signed-card index (https://councilof.ai/signed/card_index.json): what the index declares (n_cards) and how many rows it actually carries, reported next to — never reconciled with — the count the card store endpoint (https://councilof.ai/api/cards) reports for itself. Two labelled numbers from two surfaces; if they disagree, this tool shows the disagreement rather than picking one. Optional filters return recent rows: axis, limit. Each row carries card_url, the signed body; pass it, or the row's 64-hex card id, to verify_card.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'axis': {'type': 'string', 'description': 'Only list rows whose axis matches this name (case-insensitive).'}, 'limit': {'type': 'integer', 'maximum': 150, 'minimum': 0, 'description': 'How many rows to include in the listing (newest first). Default 10. The two counts are always reported in full regardless of this limit.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'properties': {'rows': {'type': ['array', 'null'], 'items': {'type': 'object', 'properties': {'ts': {}, 'axis': {'type': 'string'}, 'card': {'type': 'string'}, 'signed': {}, 'card_url': {'type': ['string', 'null'], 'description': 'The signed card body, https://councilof.ai/signed/cards/{id}.json. verify_card takes this URL or the bare card id.'}}}}, 'index': {'type': ['object', 'null']}, 'state': {'enum': ['LIVE', 'UNREACHABLE'], 'type': 'string', 'description': 'Read state of the signed card index on this call: LIVE (read now) or UNREACHABLE. Listing is not verification; verify_card checks a row.'}, 'doctrine': {'type': 'string'}, 'axis_query': {'type': 'object', 'properties': {'asked': {'type': 'string'}, 'canonical': {'type': 'string'}, 'spellings': {'type': 'array', 'items': {'type': 'string'}}, 'index_names_matched': {'type': 'array', 'items': {'type': 'string'}}}}, 'state_basis': {'type': 'string'}, 'not_a_certification': {'type': 'boolean'}, 'card_store_count_endpoint': {'type': ['object', 'null']}}}
mcp_trust
MCP handshake census snapshot
GET the latest MCP handshake trust snapshot (https://councilof.ai/interop/mcp-trust/latest.json): counts of how many internet-facing MCP servers answer a correct initialize handshake, how many respond with an auth challenge, and how many are unreachable. Counts only by doctrine — host details withheld by design. A partial round or a cap change is disclosed in the snapshot. Measurement, never certification. Three states: VALID (fetched), UNREACHABLE (could not fetch), UNCHECKABLE (body unreadable).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'diff': {}, 'kind': {}, 'as_of': {'type': ['string', 'null']}, 'state': {'type': 'string', 'description': 'VALID or UNREACHABLE'}, 'counts': {'type': ['object', 'null']}, 'source': {'type': 'string'}, 'partial': {'type': 'boolean', 'description': 'true whenever the enumeration did not complete â\x80\x94 a cap-limited read is partial'}, 'headline': {'type': ['string', 'null']}, 'enumeration': {'type': ['object', 'null']}, 'partial_reason': {'type': ['string', 'null']}}}
measurement_index
Measurement-capsule index
Read the latest signed measurement-capsule index published at https://councilof.ai/measurement-capsules/latest.json: the index root over every capsule, each batch (adapter, kind, capsule count, measurement states, batch Merkle root, record sha256, record signature and OpenTimestamps state), the index's own board signature re-verified here against the pinned did:web:csoai.org#board-attestation-1 key, and the anchor states published beside it (OpenTimestamps, Rekor, XRPL) — PENDING is never called attested. States only: measurement, not endorsement; no verdict, score or ranking. NOT_PUBLISHED when no index is served; UNREACHABLE when the source could not be fetched.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'state': {'enum': ['PUBLISHED', 'NOT_PUBLISHED', 'UNREACHABLE', 'UNCHECKABLE'], 'type': 'string'}, 'reason': {'type': 'string'}, 'anchors': {'type': 'object'}, 'batches': {'type': 'array', 'items': {'type': 'object'}}, 'version': {'type': 'string'}, 'doctrine': {'type': 'string', 'const': 'measurement, not endorsement'}, 'n_batches': {'type': 'integer'}, 'signature': {'type': 'object'}, 'index_root': {'type': ['string', 'null']}, 'n_capsules_total': {'type': ['integer', 'null']}}}
receipts_batch
Receipts batch (paid, x402; preview free)
PAID (x402 or CSOAI LTD invoice). A historical batch of the estate's measurement receipts via https://councilof.ai/api/receipts/batch: every signed card-v0 leaf whose as_of falls in [from,to] (≤200), each with its Merkle inclusion path and the public root(s) that carried it, plus the root index for the window and one signed manifest card citing the batch sha256. preview=true is free and returns count, span, root count and the sha256 of the exact bytes the paid call returns. Recent leaves are free at /root.json, /cards/ and /api/proof?sha= — the batch sells assembly across history, never a conclusion. No settlement-receipt stream exists (/api/receipts/latest is UNPUBLISHED) and this tool never claims one. Without x_payment the tool returns the 402 challenge.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['from'], 'properties': {'to': {'type': 'string', 'description': 'Window end, ISO-8601. Defaults to now.'}, 'from': {'type': 'string', 'description': 'Window start, ISO-8601. Required.'}, 'preview': {'type': 'boolean', 'description': 'true = free: count, span, roots and batch sha256 without the leaves.'}, 'x_payment': {'type': 'string', 'description': 'The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['status'], 'properties': {'tool': {'type': 'string'}, 'route': {'type': 'string'}, 'status': {'type': 'string', 'description': 'PAYMENT_REQUIRED, DELIVERED, NOT_DEPLOYED, UNREACHABLE, UNREADABLE_RESPONSE, BAD_ARGUMENTS or HTTP_<code>'}, 'accepts': {'type': 'array'}, 'resource': {'type': 'object'}, 'deliverable': {}, 'http_status': {'type': 'integer'}, 'x402Version': {'type': 'integer'}, 'delivery_state': {'type': 'string'}, 'settlement_state': {'type': 'string'}, 'payment_presented': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}}, 'description': "The wrapper's status fields. On PAYMENT_REQUIRED (isError:true) the route's x402 PaymentRequired object (x402Version, resource, accepts, extensions) is spread at the top level too, per the x402 MCP transport."}
route
GSPC Route: decide a path under your policy (free, decide-only)
GSPC Route (free, decide-only). Applies YOUR policy and the fixed GSPC floor to a candidate set and returns the chosen candidate, the basis of the choice and an unsigned route record (csoai.evidence-event/0.1, profile csoai.route-evidence/0.1). Candidates are the GSPC MCP tools by default, or ones you declare: your models, your local GPU, MCP tools, A2A agents, x402 resources. Policy is Cedar: presets read-only, local-only, eu-only, no-unmeasured, plus forbid_providers and allow_kinds; anything the router does not understand grants nothing. For the quality axis you name it reads the live board (https://councilof.ai/api/gspc). Routing is not ranking: a choice is called a separated leader only when the board separated that comparison; otherwise it is TIE or UNTESTED and your tie_break decides. A candidate the board holds no number for is UNTESTED, never 0. Sponsor, bid and placement fields are ignored. The task text is hashed, never stored. Nothing is executed, called or charged; mode execute answers NOT_ENABLED. Measurement, not certification.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'mode': {'enum': ['decide', 'execute'], 'type': 'string', 'description': 'decide (default). execute is not enabled and answers NOT_ENABLED.'}, 'task': {'type': 'string', 'maxLength': 20000, 'description': 'The task. Hashed (sha256) and never stored or echoed.'}, 'policy': {'type': 'object', 'properties': {'presets': {'type': 'array', 'items': {'type': 'string'}}, 'allow_kinds': {'type': 'array', 'items': {'type': 'string'}}, 'caller_wallet': {'type': 'boolean'}, 'forbid_providers': {'type': 'array', 'items': {'type': 'string'}}, 'confirm_destructive': {'type': 'boolean'}}, 'description': 'presets [read-only, local-only, eu-only, no-unmeasured], forbid_providers [..], allow_kinds [..], confirm_destructive, caller_wallet. Unknown keys grant nothing.'}, 'objective': {'type': 'object', 'properties': {'weights': {'type': 'object', 'properties': {'cost': {'type': 'number'}, 'latency': {'type': 'number'}, 'quality': {'type': 'number'}}}, 'tie_break': {'anyOf': [{'type': 'string'}, {'type': 'array', 'items': {'type': 'string'}}], 'description': 'cheapest_declared, local_first, lexical_id (default in that order)'}, 'quality_axis': {'type': 'string', 'description': 'A board axis id, e.g. governance'}}}, 'candidates': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'kind'], 'properties': {'id': {'type': 'string'}, 'kind': {'enum': ['model', 'mcp_tool', 'a2a_agent', 'x402_resource', 'local_gpu'], 'type': 'string'}, 'paid': {'type': 'boolean'}, 'model': {'type': 'string'}, 'region': {'type': 'string'}, 'endpoint': {'type': 'string', 'description': 'https://public-host/... or local:<name> for an endpoint you run'}, 'provider': {'type': 'string'}, 'read_only': {'type': 'boolean'}, 'destructive': {'type': 'boolean'}, 'cost_declared': {'type': 'number', 'minimum': 0}, 'data_class_allowed': {'type': 'array', 'items': {'enum': ['public', 'internal', 'confidential', 'pii'], 'type': 'string'}}, 'latency_declared_ms': {'type': 'number', 'minimum': 0}}}, 'maxItems': 32, 'description': 'Omit to route among the GSPC MCP tools. A candidate field the router does not know makes that candidate UNCHECKABLE (never permitted); sponsor/bid/placement fields are ignored.'}, 'data_class': {'enum': ['public', 'internal', 'confidential', 'pii'], 'type': 'string', 'description': 'Default public. A non-public class is routed only to candidates that declare it in data_class_allowed.'}, 'needs_write': {'type': 'boolean'}, 'task_sha256': {'type': 'string', 'pattern': '^[0-9a-fA-F]{64}$', 'description': 'Alternative to task: its sha256.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'mode': {'type': 'string'}, 'note': {'type': 'string'}, 'label': {'type': ['string', 'null']}, 'state': {'enum': ['ROUTED', 'NO_PERMITTED_CANDIDATE', 'BAD_ARGUMENTS', 'NOT_ENABLED'], 'type': 'string'}, 'chosen': {'type': ['object', 'null']}, 'errors': {'type': 'array'}, 'record': {'type': 'object'}, 'signed': {'type': 'boolean'}, 'preview': {'type': 'boolean'}, 'forbidden': {'type': 'array'}, 'permitted': {'type': 'integer'}, 'considered': {'type': 'integer'}, 'separation': {'type': 'string'}, 'http_status': {'type': 'integer'}}}
rwa_evidence
RWA asset evidence (paid, x402; preview free)
PAID (x402). Per-request signed evidence card of ONE XRPL issued asset's deterministic on-ledger state via https://councilof.ai/api/rwa/evidence: AccountRoot lsf* flags, Domain, the two-way xrp-ledger.toml check (PASS / FAIL / UNCHECKABLE — unreachable is never FAIL), gateway_balances obligation, holders as the free reader has them, every raw fetch sha256'd. preview=true is free (unsigned state). Historical state at fetched_at — not a rating, not a guarantee, not a conformity mark; /api/xrpl and /root.json stay free. Without x_payment the tool returns the 402 challenge. If the route is not deployed on this origin the tool says NOT_DEPLOYED.
Externer Zugriff
Eingabeschema
{'type': 'object', 'required': ['asset'], 'properties': {'asset': {'type': 'string', 'description': 'Symbol (as listed by https://councilof.ai/api/xrpl) or issuer r-address.'}, 'preview': {'type': 'boolean', 'description': 'true = free unsigned state.'}, 'x_payment': {'type': 'string', 'description': 'The X-PAYMENT header value signed against accepts[] from the previous 402. Omit to receive the challenge.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['status'], 'properties': {'tool': {'type': 'string'}, 'route': {'type': 'string'}, 'status': {'type': 'string', 'description': 'PAYMENT_REQUIRED, DELIVERED, NOT_DEPLOYED, UNREACHABLE, UNREADABLE_RESPONSE, BAD_ARGUMENTS or HTTP_<code>'}, 'accepts': {'type': 'array'}, 'resource': {'type': 'object'}, 'deliverable': {}, 'http_status': {'type': 'integer'}, 'x402Version': {'type': 'integer'}, 'delivery_state': {'type': 'string'}, 'settlement_state': {'type': 'string'}, 'payment_presented': {'type': 'boolean'}, 'not_a_certification': {'type': 'boolean'}}, 'description': "The wrapper's status fields. On PAYMENT_REQUIRED (isError:true) the route's x402 PaymentRequired object (x402Version, resource, accepts, extensions) is spread at the top level too, per the x402 MCP transport."}
server_evidence
Every published capsule about one endpoint
Trust per server, not totals: every published measurement capsule about ONE endpoint URL across all batches — MCP contract-parity dimensions (AUTH, PAYMENT, PROTOCOL, TOOLS, VERSION), A2A card-signature state, self-parity cells for CSOAI's own doors, and any later adapter (e.g. tool drift) — each with its measurement_state, observed_at, correction_pointer, limitations, batch Merkle root and an inclusion pointer (verify_capsule re-derives inclusion). Read from a static per-endpoint shard keyed by sha256 of the normalised URL. An endpoint with no capsule answers NOT_MEASURED with an empty list — never an error and never a clean bill. No verdict, score or ranking: measurement, not endorsement.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['endpoint_url'], 'properties': {'endpoint_url': {'type': 'string', 'description': 'The endpoint URL, e.g. https://example.com/mcp or an agent-card URL.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'state': {'enum': ['MEASURED', 'NOT_MEASURED', 'NOT_PUBLISHED', 'UNREACHABLE', 'UNCHECKABLE'], 'type': 'string'}, 'reason': {'type': 'string'}, 'capsules': {'type': 'array', 'items': {'type': 'object'}}, 'doctrine': {'type': 'string', 'const': 'measurement, not endorsement'}, 'endpoint': {'type': ['string', 'null']}, 'n_capsules': {'type': 'integer'}}}
verify_capsule
Verify one measurement capsule
Verify one measurement capsule. Pass capsule_json as the capsule's JSON TEXT (exact: number lexemes are kept) or as an object. Recomputes capsule_id (sha256 of the canonical JSON without capsule_id), picks the rule by the capsule's schema (csoai.measurement-capsule/0.2: RFC 6962 Merkle with 0x00/0x01 domain separation; the superseded v0.1 capsule schema: the v0.1 rule), finds the published batch of the same kind, recomputes that batch's root from its published leaves, and returns the audit path of this capsule against the root named by the signed index. States: INCLUDED, NOT_INCLUDED, ID_MISMATCH, UNCHECKABLE, NOT_PUBLISHED. Verifying is free forever. It proves the bytes were published and bound; what they measured is the capsule's own measurement_state and limitations — measurement, not endorsement.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['capsule_json'], 'properties': {'capsule_json': {'type': ['string', 'object'], 'description': 'The capsule: its JSON text (preferred, byte-exact) or the parsed object.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'batch': {'type': 'object'}, 'state': {'enum': ['INCLUDED', 'NOT_INCLUDED', 'ID_MISMATCH', 'UNCHECKABLE', 'NOT_PUBLISHED', 'UNREACHABLE'], 'type': 'string'}, 'reason': {'type': 'string'}, 'doctrine': {'type': 'string', 'const': 'measurement, not endorsement'}, 'inclusion': {'type': 'object'}, 'capsule_id': {'type': 'object'}, 'index_signature': {'type': 'object'}}}
verify_card
Verify a signed measurement card (free)
Verify a signed gspc.measurement-card under the published rule (https://councilof.ai/signed/HOW-TO-VERIFY.md): recompute the id from the canonical body bytes, then check the Ed25519 signature under a key PINNED in this verifier and published in the did:web:csoai.org DID document: #card-attestation-1 (the card key of the signed card index) or #card-attestation-2 (the card key added on rotation, 27 Sep 2026; a card names the key it was signed under), plus the board key for the cards it signed. pinned_key in the result names the key that matched. A card that carries its own key proves only that the file is self-consistent — anyone can alter a body and sign it with a key they just generated — so an inline key outside the pinned set is reported INVALID, and a DID key reference outside it UNCHECKABLE. Three verdicts, never two: VALID, INVALID (with the reason), or UNCHECKABLE when the check could not be completed — 'could not check' is a different claim from 'forged'. Accepts the card as a JSON object, a JSON string, a councilof.ai / csoai.org URL, or a 64-hex card id (the record id shown on the site and the card field of list_cards), which resolves to https://councilof.ai/signed/cards/{id}.json. Never a certification.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['card'], 'properties': {'card': {'anyOf': [{'type': 'object'}, {'type': 'string'}], 'description': 'The signed card: an object, a JSON string, a councilof.ai / csoai.org URL to one, or a 64-hex card id (resolved to https://councilof.ai/signed/cards/{id}.json).'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'id': {'type': ['string', 'null']}, 'note': {'type': 'string'}, 'rule': {'type': 'string'}, 'state': {'type': 'string', 'description': 'VALID, INVALID or UNCHECKABLE'}, 'checks': {'type': 'array', 'items': {'type': 'object', 'properties': {'ok': {'type': ['boolean', 'null'], 'description': 'true = passed, false = failed, null = not applicable or not run (detail says UNCHECKED)'}, 'code': {'type': 'string'}, 'check': {'type': 'string'}, 'detail': {'type': 'string'}, 'advisory': {'type': 'boolean', 'description': 'true = reported but never decides the verdict (the live did.json cross-check)'}}}}, 'family': {'type': ['string', 'null']}, 'reason': {'type': ['string', 'null']}, 'reasons': {'type': 'array', 'items': {'type': 'string'}}, 'pinned_key': {'type': ['string', 'null']}, 'resolved_from': {'type': 'object', 'properties': {'id': {'type': 'string'}, 'url': {'type': 'string'}}, 'description': 'Present when a 64-hex card id was passed: the id asked about and the URL fetched for it.'}, 'not_a_certification': {'type': 'boolean'}}}
verify_inclusion
Merkle inclusion check
Check a sha256 against the live public-root merkle via GET /api/proof?sha=. Three states only: VALID (included), INVALID (not a leaf), UNCHECKABLE (proof endpoint unreachable). Does not claim Ed25519 unless sig_ed25519 is present and checked separately. Never a grade.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': '64-char hex digest to test for inclusion.'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'state': {'type': 'string', 'description': 'VALID, INVALID or UNCHECKABLE'}, 'reason': {}, 'sha256': {'type': 'string'}, 'merkle_root': {'type': ['string', 'null']}}}
x402_trust
x402 catalog trust snapshot
GET the latest x402 catalog trust snapshot: counts of how many catalogued x402 resources open a correct 402 challenge vs how many are phantom on the wire. Counts only by doctrine — host details withheld; a 402 is NOT delivery; measurement, never certification.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['state'], 'properties': {'kind': {}, 'as_of': {'type': ['string', 'null']}, 'state': {'type': 'string', 'description': 'VALID or UNREACHABLE'}, 'counts': {'type': ['object', 'null']}, 'source': {'type': 'string'}, 'headline': {'type': ['string', 'null']}}}
Hinzugefügt
evidence_bundle
1. October 2026 02:44
Hinzugefügt
route
1. October 2026 02:44
Hinzugefügt
evidence_bundle_preview
1. October 2026 02:44
Geändert
get_card
1. October 2026 02:44
Geändert
list_cards
1. October 2026 02:44
Geändert
verify_card
1. October 2026 02:44
Geändert
verify_card
29. September 2026 02:51
Geändert
board_totals
29. September 2026 02:51
Geändert
receipts_batch
27. September 2026 02:44
Geändert
rwa_evidence
27. September 2026 02:44
Geändert
art50_marking_evidence
27. September 2026 02:44
Geändert
commission_card
27. September 2026 02:44
Hinzugefügt
server_evidence
27. September 2026 02:44
Hinzugefügt
verify_capsule
27. September 2026 02:44
Hinzugefügt
measurement_index
27. September 2026 02:44
Geändert
mcp_trust
27. September 2026 02:44
Geändert
x402_trust
27. September 2026 02:44
Geändert
verify_inclusion
27. September 2026 02:44
Geändert
get_card
27. September 2026 02:44
Geändert
get_root
27. September 2026 02:44
Geändert
list_cards
27. September 2026 02:44
Geändert
verify_card
27. September 2026 02:44
Geändert
get_axis
27. September 2026 02:44
Geändert
board_totals
27. September 2026 02:44
Geändert
get_axis
23. September 2026 02:42
Hinzugefügt
receipts_batch
17. September 2026 12:41
Hinzugefügt
rwa_evidence
17. September 2026 12:41
Hinzugefügt
art50_marking_evidence
17. September 2026 12:41
Hinzugefügt
commission_card
17. September 2026 12:41
Hinzugefügt
mcp_trust
17. September 2026 12:41

DB Query Guard MCP

com.clauxel.dbqueryguard/dbqueryguard-mcp

Supports governed database query review, SQL simulation, approvals, and audit trails.

Crypto Bot Audit + Market Data (x402 paid)

io.github.kaminariouji/x402-audit-agent

Audits crypto bot source code and provides paid crypto market, token, gas, stablecoin, and DeFi TVL data.

TunnelMind Data API

ai.tunnelmind/data

Aggregates web, routing, supply-chain, tracker, threat, and agent-registry intelligence into risk verdicts, evidence, receipts, a…

Govparse Government Data Gateway

io.govparse/gateway

Searches and aggregates US government records for company research, compliance screening, regulated industries, enforcement event…

Polyform

org.polyform/polyform

Offers pay-per-call APIs for economic, financial, geographic, healthcare, domain, email, sanctions, blockchain, and business risk…

Dados Abertos Senado BR MCP

io.github.SidneyBissoli/senado-br-mcp-cloudflare

Searches and retrieves Brazilian Federal Senate legislative, administrative, budgetary, contracting, speech, committee, and e-Cid…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

Medicare Coverage

io.github.pipeworx-io/medicare-coverage

Provides structured Medicare coverage documents, policy timelines, utilization, enrollment, supplier, and payment-related data fr…