Servidor MCP

mcp

com.pcrzero/mcp
Seguridad Público y accesible MCP 2025-11-25

Qué hace este MCP

Issues signed receipts for policy-based attestations and verifies those receipts against published signing keys.

get_keyset
Returns the current PCRZERO signing keyset — key ids, public halves, and each key's status. Public and unauthenticated: no API key, no cost, no account. This is the same document an outside party fetches to check a PCRZERO receipt without trusting us, and fetching it is how you stop taking our word for anything.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
issue_receipt
Adjudicates an attestation document against a policy and returns the verdict together with a signed receipt pair — the durable, independently checkable proof that this decision was made, by these keys, over this document. **Metered: every call bills one `receipt_verifications` unit against the API key configured for this server, and a `fail` verdict bills exactly like a `pass`. You are paying for the adjudication, not for the answer you wanted.** This is the only tool here that spends. If you already hold a receipt and want to know whether it is genuine, that is `verify_receipt`, which is free and needs no key.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'nonce': {'type': 'string'}, 'policy': {'type': 'object', 'description': 'Inline policy object (API wire shape).', 'additionalProperties': {}}, 'receipt': {'type': 'boolean', 'description': 'Request a signed receipt (default true).'}, 'document': {'type': 'string', 'description': 'Base64 attestation document (single-document form).'}, 'documents': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Base64 attestation documents (batch form).'}, 'policy_id': {'type': 'string', 'description': 'Stored policy id (pol_…).'}}, 'additionalProperties': False}
verify_receipt
Checks a PCRZERO receipt pair against the signing keyset: whether the signature holds, and whether the receipt says what it appears to say. **Free, with no API key and no account, and it stays free.** Offline by default — supply `keyset` and this call touches the network not at all; omit it and the server fetches the public keyset from api.pcrzero.com once. The result field `keyset_source` tells you which of the two happened, every time. This tool issues nothing, bills nothing, and cannot spend. It is the half of PCRZERO you never pay for.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['receipt'], 'properties': {'keyset': {'type': 'object', 'required': ['keys'], 'properties': {'keys': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': {}}}}, 'description': 'Optional keyset in GET /v1/keys shape. When supplied, no network is used.', 'additionalProperties': False}, 'receipt': {'type': 'string', 'description': 'Base64url receipt envelope from issue_receipt / the API.'}, 'conformance': {'enum': ['full', 'classical-only'], 'type': 'string'}}, 'additionalProperties': False}
Añadido
get_keyset
17 de September de 2026 a las 12:36
Añadido
verify_receipt
17 de September de 2026 a las 12:36
Añadido
issue_receipt
17 de September de 2026 a las 12:36