Serveur MCP

FreeSign — Free e-signature

com.free-sign/signing
Juridique et conformité Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Creates and verifies hash-based PDF signing envelopes, receipts, audit chains, document hashes, and timestamp proofs.

create_signing_envelope
Create signing envelope
Create a FreeSign envelope from a PDF SHA-256 hash. Do not send PDF bytes. The created envelope is NOT yet session-bound — the browser that opens the returned signing_url generates an ECDSA P-256 keypair locally and POSTs the public JWK to /api/envelopes/{id}/session-bind before any protected request will succeed. AI agents calling this tool just hand the signing_url to a human, who continues in a browser.
Schéma d’entrée
{'type': 'object', 'required': ['document_sha256'], 'properties': {'document_sha256': {'type': 'string', 'pattern': '^[a-f0-9]{64}$', 'description': 'SHA-256 of the original PDF bytes, computed locally by the user or agent.'}}}
Schéma de sortie
{'type': 'object', 'required': ['envelope_id', 'signing_url', 'expires_at'], 'properties': {'expires_at': {'type': 'string'}, 'envelope_id': {'type': 'string'}, 'signing_url': {'type': 'string'}, 'session_binding_required': {'type': 'boolean', 'description': 'True when the envelope still needs the browser to call /api/envelopes/{id}/session-bind. Always true for MCP-created envelopes.'}}}
get_ots_proof
Get OpenTimestamps proof
Return the .ots proof (base64) for a given OpenTimestamps anchor on an envelope. Use the official `ots-cli` to verify offline against Bitcoin block headers. Each seal has two anchors: `kind: "byterange"` commits to the signed document, `kind: "signed_attrs"` commits to SHA-256 of the CMS SignedAttributes (which carry the post-quantum key commitment).
Schéma d’entrée
{'type': 'object', 'required': ['envelope_id', 'anchor_id'], 'properties': {'anchor_id': {'type': 'string', 'pattern': '^ots_[a-f0-9]{32}$'}, 'envelope_id': {'type': 'string', 'pattern': '^env_[a-f0-9]{32}$'}}}
Schéma de sortie
{'type': 'object', 'required': ['envelope_id', 'anchor_id', 'status', 'anchored_hash', 'proof_base64'], 'properties': {'kind': {'enum': ['byterange', 'signed_attrs'], 'type': 'string'}, 'status': {'enum': ['pending', 'confirmed'], 'type': 'string'}, 'anchor_id': {'type': 'string'}, 'envelope_id': {'type': 'string'}, 'proof_base64': {'type': 'string', 'description': 'Complete .ots file bytes, base64.'}, 'anchored_hash': {'type': 'string'}, 'calendar_urls': {'type': 'array', 'items': {'type': 'string'}}, 'btc_block_hash': {'type': ['string', 'null']}, 'btc_block_height': {'type': ['integer', 'null']}}}
get_receipt
Get receipt
Return the envelope record (including final_pdf_sha256, final_signature_base64url, final_payload_json), per-signer signing receipts, and OpenTimestamps anchor metadata. Evidence only, never PDF bytes.
Schéma d’entrée
{'type': 'object', 'required': ['envelope_id'], 'properties': {'envelope_id': {'type': 'string'}}}
Schéma de sortie
{'type': 'object', 'required': ['envelope', 'receipts', 'ots_anchors'], 'properties': {'envelope': {'type': 'object'}, 'receipts': {'type': 'array', 'items': {'type': 'object'}}, 'ots_anchors': {'type': 'array', 'items': {'type': 'object'}}}}
verify_audit_chain
Verify audit chain
Return an envelope's append-only audit-event hash chain together with a server-computed integrity verdict: every event_hash is recomputed from its canonical material, and the prev_event_hash linkage and per-envelope seq contiguity are checked. Evidence only, never PDF bytes. The raw events are included verbatim so the caller can independently re-derive the verdict instead of trusting `chain.valid`.
Schéma d’entrée
{'type': 'object', 'required': ['envelope_id'], 'properties': {'envelope_id': {'type': 'string', 'pattern': '^env_[a-f0-9]{32}$'}}}
Schéma de sortie
{'type': 'object', 'required': ['envelope_id', 'attested_audit_chain_head_hash', 'attested_head_signature_verified', 'chain', 'events'], 'properties': {'chain': {'type': 'object', 'required': ['valid', 'event_count', 'broken_at', 'reason', 'head_checked', 'head_match', 'events'], 'properties': {'valid': {'type': 'boolean'}, 'events': {'type': 'array', 'items': {'type': 'object'}}, 'reason': {'enum': ['hash_mismatch', 'broken_link', 'seq_bad_start', 'seq_gap', 'seq_duplicate', 'head_mismatch', None], 'type': ['string', 'null']}, 'broken_at': {'type': ['integer', 'null'], 'description': 'seq of the first broken event, or null (also null for a head_mismatch — no single event is at fault).'}, 'head_match': {'type': ['boolean', 'null'], 'description': 'Result of the head cross-check, or null when no attested head was available.'}, 'event_count': {'type': 'integer'}, 'head_checked': {'type': 'boolean', 'description': 'True when an attested head was supplied and cross-checked against the recomputed chain.'}}}, 'events': {'type': 'array', 'items': {'type': 'object'}}, 'envelope_id': {'type': 'string'}, 'attested_audit_chain_head_hash': {'type': ['string', 'null'], 'description': "The audit-chain head derived from the signer-signed v2 final payload (G-01), fed into the verdict's head cross-check. NULL until the envelope is finalized."}, 'attested_head_signature_verified': {'type': 'boolean', 'description': "True when the final-payload signature carrying the attested head was re-verified against the signer's on-file public key. False when not finalized or the signature did not verify."}}}
verify_document_hash
Verify document hash
Find FreeSign receipts matching a local document SHA-256 hash.
Schéma d’entrée
{'type': 'object', 'required': ['document_sha256'], 'properties': {'document_sha256': {'type': 'string', 'pattern': '^[a-f0-9]{64}$'}}}
Schéma de sortie
{'type': 'object', 'required': ['matches'], 'properties': {'matches': {'type': 'array', 'items': {'type': 'object'}}}}
Ajouté
verify_audit_chain
17 September 2026 12:34
Ajouté
get_ots_proof
17 September 2026 12:34
Ajouté
get_receipt
17 September 2026 12:34
Ajouté
verify_document_hash
17 September 2026 12:34
Ajouté
create_signing_envelope
17 September 2026 12:34