MCP Server

Knox Anchor

com.bonissystems/knox-anchor
Legal & Compliance Security Public & reachable MCP 2026-07-28

What this MCP does

Anchors agent events, files, and MCP tool-call records in a tamper-evident Bitcoin-linked chain and supports public verification and audit metadata.

anchor_event
Anchor a generic agent action to the Knox chain. Accepts any event_type from the canonical taxonomy plus a payload object. Returns the anchor sequence, payload hash, predecessor hash, timestamp, and verify URL. Requires a Knox Bearer API key on the Authorization header — unauthenticated calls are rejected. Provision a key by contacting Bonis Systems.
Input schema
{'type': 'object', 'required': ['event_type', 'payload'], 'properties': {'payload': {'type': 'object', 'description': 'JSON-serializable payload describing the agent action. Hashed verbatim into the chain; do not include secrets — the payload is recoverable on verify.'}, 'event_type': {'type': 'string', 'description': 'Canonical event type (call list_event_types to enumerate). Free-form strings are accepted but not federal-citation-grade.'}}, 'additionalProperties': False}
anchor_file_hash
Anchor a SHA-256 file digest to Knox and return an affidavit architected for FRE 902(13)/(14) self-authentication. The file itself is not transmitted — the caller computes the hash and only the digest + filename + size + MIME type are anchored. Admissibility in any matter remains a determination of the presiding court. Requires a Knox Bearer API key on the Authorization header — unauthenticated calls are rejected.
Input schema
{'type': 'object', 'required': ['hash'], 'properties': {'hash': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'description': 'SHA-256 file digest (64 lowercase hex chars).'}, 'filename': {'type': 'string', 'description': 'Original filename (max 256 chars).'}, 'mime_type': {'type': 'string', 'description': 'MIME type (max 128 chars).'}, 'size_bytes': {'type': 'integer', 'minimum': 0, 'description': 'File size in bytes.'}}, 'additionalProperties': False}
anchor_mcp_tool_call
Convenience anchor for the AAM Model Context Protocol theater. Records an `agent_mcp_tool_call` event with structured tool-call metadata (server URL, tool name, argument digest, asserted agent identity, response digest). The record is sealed with a commitment to the authenticated principal that made the assertion, so a reader can tell WHO claimed it. Knox does not authenticate the named agent: this makes an assertion about an agent's actions independently checkable, not the agent itself independently identified.
Input schema
{'type': 'object', 'required': ['server_url', 'tool_name', 'arguments_digest', 'agent_identity', 'outcome'], 'properties': {'outcome': {'enum': ['success', 'error', 'timeout', 'rejected'], 'type': 'string', 'description': 'Outcome of the tool call.'}, 'tool_name': {'type': 'string', 'description': 'Name of the tool invoked.'}, 'server_url': {'type': 'string', 'description': 'MCP server endpoint the agent invoked.'}, 'agent_identity': {'type': 'string', 'maxLength': 256, 'description': 'Stable identifier the CALLER asserts for the agent (e.g., agent ID, principal, did:knox:agent-X). Recorded as an assertion attributed to your API key, never as an authenticated subject; the anchored payload carries agentIdentityVerified:false and a commitment to the asserting principal.'}, 'response_digest': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'description': 'Caller-computed SHA-256 of the JSON-stringified response (64 hex chars).'}, 'arguments_digest': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'description': 'Caller-computed SHA-256 of the JSON-stringified arguments (64 hex chars).'}}, 'additionalProperties': False}
get_chain_health
Return Knox service health: process uptime, database latency, total anchors written, latest anchor timestamp, and the Bitcoin anchor SLA target (OpenTimestamps interval, 1-6 hour confirmation window). Mirrors the public /api/knox/health endpoint under the MCP envelope.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
get_descriptor
Return the Knox MCP server self-description: operator, USPTO patent reference, jurisdiction, available tools, and links to the public AAM (Agent Audit and Management) documentation surface.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
list_event_types
Return the canonical Knox event-type taxonomy. Each event type is a citation token for federal-grade audit; the registry expands monotonically and is itself anchored on every expansion.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
verify_anchor
Given a SHA-256 anchor hash (64 hex chars), return the anchor record, chain link validity (predecessor present and matched), event type, sequence number, and verify URL. Public — no authentication required.
Input schema
{'type': 'object', 'required': ['hash'], 'properties': {'hash': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'description': 'SHA-256 anchor hash (64 lowercase hex chars).'}}, 'additionalProperties': False}
Changed
anchor_mcp_tool_call
Sept. 23, 2026, 2:52 a.m.
Added
anchor_file_hash
Sept. 17, 2026, 12:33 p.m.
Added
anchor_mcp_tool_call
Sept. 17, 2026, 12:33 p.m.
Added
anchor_event
Sept. 17, 2026, 12:33 p.m.
Added
verify_anchor
Sept. 17, 2026, 12:33 p.m.
Added
list_event_types
Sept. 17, 2026, 12:33 p.m.
Added
get_chain_health
Sept. 17, 2026, 12:33 p.m.
Added
get_descriptor
Sept. 17, 2026, 12:33 p.m.