Servidor MCP

attest-mcp-remote

io.github.SPAZIO-GENESI/attest-mcp-remote
Seguridad Público y accesible MCP 2025-11-25

Qué hace este MCP

Creates and verifies signed SHA-256 attestations for files or works, with timestamping, certificates, and optional Bitcoin anchoring.

attest_hash
Attest a work: the service binds the SHA-256 fingerprint to a server-side timestamp and signs it (HMAC). Requires a credential (device flow via `authorize`, or an API key header). Optional declared metadata (title/author/year/notes) are normalized and BOUND by the signature — immutable after issuance, but they remain self-declared (they don't prove authorship). Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sha256'], 'properties': {'anno': {'type': 'string', 'description': 'Declared year/version (bound by the signature).'}, 'name': {'type': 'string', 'description': 'File name (descriptive only, shown on the certificate).'}, 'note': {'type': 'string', 'description': 'Declared notes (bound by the signature).'}, 'size': {'type': 'integer', 'maximum': 9007199254740991, 'description': 'File size in bytes (descriptive only).', 'exclusiveMinimum': 0}, 'type': {'type': 'string', 'description': 'MIME type (descriptive only).'}, 'autore': {'type': 'string', 'description': 'Declared author (bound by the signature).'}, 'sha256': {'type': 'string', 'description': 'SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.'}, 'titolo': {'type': 'string', 'description': 'Declared title of the work (bound by the signature).'}}}
authorize
Start the device-flow authorization to attest works in this session (up to 20 attestations, 24h). Returns a link the USER must open in a browser and approve (anti-bot check included). After the user approves, call `complete_authorization`. Not needed if the connection already carries an API key header, or for verification tools.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
check_anchor
Check whether a work's SHA-256 fingerprint has an OpenTimestamps proof anchored in Bitcoin. The proof is created at attestation time and matures (pending → Bitcoin-confirmed) within a few hours.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': 'SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.'}}}
complete_authorization
Complete the device-flow authorization after the user approved in the browser. Polls the service briefly; if approval hasn't happened yet, just call this tool again.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
create_certificate_pdf
Generate and archive the certificate PDF for a fingerprint attested in this session with `attest_hash`. The PDF is cryptographically signed, anchored in Bitcoin (OpenTimestamps) and archived server-side; this tool returns the permanent links (the PDF itself is downloadable from its URL — it is never inlined here).
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': 'SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.'}}}
lookup_certificate
Look up whether a work's SHA-256 fingerprint has an attestation certificate in the public archive, and get its permanent links (public certificate page, PDF download, OpenTimestamps proof, browser verification). Trust model: this information is reachable only by whoever knows the fingerprint.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': 'SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.'}}}
service_status
Health of the Spazio Genesi attestation service components: worker (attestation engine), archive (certificate storage), signer (PDF cryptographic signature), anchor (Bitcoin/OpenTimestamps calendars). Values: ok | degraded | down | n/d.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
verify_attestation
Verify the server HMAC signature of an attestation issued by the Spazio Genesi service. Confirms that the attestation string (fingerprint + timestamp) and any declared metadata are authentic and untampered. Note: this checks the SIGNATURE only. Whether a given file matches the fingerprint must be checked locally by re-hashing the file. If the certificate carried declared metadata (title/author/year/notes), they must be provided EXACTLY as printed for the signature to verify.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['sha256', 'attestazione', 'hmac'], 'properties': {'anno': {'type': 'string', 'description': 'Declared year/version, exactly as printed (only if the certificate shows it).'}, 'hmac': {'type': 'string', 'description': "The server HMAC signature exactly as printed on the certificate (base64, 44 characters ending with '=')."}, 'note': {'type': 'string', 'description': 'Declared notes, exactly as printed (only if the certificate shows them).'}, 'autore': {'type': 'string', 'description': 'Declared author, exactly as printed (only if the certificate shows it).'}, 'sha256': {'type': 'string', 'description': 'SHA-256 fingerprint of the work: 64 hexadecimal characters. Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot.'}, 'titolo': {'type': 'string', 'description': 'Declared title, exactly as printed (only if the certificate shows it).'}, 'attestazione': {'type': 'string', 'description': 'The attestation string exactly as printed on the certificate: "SHA-256:<hash>@<ISO timestamp>Z"'}}}
Añadido
create_certificate_pdf
17 de September de 2026 a las 12:52
Añadido
attest_hash
17 de September de 2026 a las 12:52
Añadido
complete_authorization
17 de September de 2026 a las 12:52
Añadido
authorize
17 de September de 2026 a las 12:52
Añadido
lookup_certificate
17 de September de 2026 a las 12:52
Añadido
verify_attestation
17 de September de 2026 a las 12:52
Añadido
check_anchor
17 de September de 2026 a las 12:52
Añadido
service_status
17 de September de 2026 a las 12:52