MCP Server

GENESIS ProofRelay MCP Verifier

io.genesisre/proofrelay-mcp-verifier

What this MCP does

Builds and verifies hash-only evidence bundles, attestations, audit manifests, payment proofs, MCP tool evidence, and readiness or risk signals without signing or certifying external claims.

proofrelay.adapt_agent_identity_evidence
Adapt agent identity evidence
Map Concordium, ERC-8004, DID, domain, wallet-controller, or IAM identity references into a hash-only PREP-3 input. ProofRelay accepts identity as evidence; it does not issue identity or certify people.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['identity'], 'properties': {'identity': {'type': 'object', 'required': ['provider', 'agent_id_hash'], 'properties': {'provider': {'enum': ['concordium_agent_registry', 'erc_8004', 'did', 'domain_control', 'wallet_controller', 'enterprise_iam', 'other'], 'type': 'string'}, 'issued_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'expires_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'domain_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'agent_id_hash': {'type': 'string'}, 'controller_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'attestation_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'action_binding_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'registry_record_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'verification_method_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'adapt_agent_identity_evidenceDictOutput', 'additionalProperties': True}
proofrelay.adapt_x402_payment_proof
Adapt x402 payment proof
Map public-safe x402 request, 402 challenge, payment payload, facilitator response, and resource response hashes into ProofRelay's payment_context evidence profile.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['x402'], 'properties': {'x402': {'type': 'object', 'required': ['request_hash', 'payment_required_hash', 'payment_payload_hash', 'payment_response_hash', 'resource_response_hash'], 'properties': {'amount': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'network': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'currency': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'replay_key': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'request_hash': {'type': 'string'}, 'facilitator_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_payload_hash': {'type': 'string'}, 'payment_required_hash': {'type': 'string'}, 'payment_response_hash': {'type': 'string'}, 'resource_response_hash': {'type': 'string'}}}}}
Output schema
{'type': 'object', 'title': 'adapt_x402_payment_proofDictOutput', 'additionalProperties': True}
proofrelay.build_audit_pack_manifest
Build audit pack manifest
Build a portable hash-only audit pack manifest from bundle, verifier, policy, and evidence hashes without uploading private files or logs.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['audit_pack'], 'properties': {'audit_pack': {'type': 'object', 'required': ['subject_hash'], 'properties': {'pack_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'control_refs': {'type': 'array', 'items': {'type': 'string'}}, 'generated_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'subject_hash': {'type': 'string'}, 'bundle_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'policy_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'evidence_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'verifier_response_hashes': {'type': 'array', 'items': {'type': 'string'}}}}}}
Output schema
{'type': 'object', 'title': 'build_audit_pack_manifestDictOutput', 'additionalProperties': True}
proofrelay.build_bundle_draft
Build unsigned ProofRelay bundle draft
Build a canonical, unsigned, non-attesting ProofRelay bundle draft from public-safe event hashes. The public MCP server does not sign or certify caller-provided facts.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['draft'], 'properties': {'draft': {'type': 'object', '$defs': {'BundleDraftEventInput': {'type': 'object', 'required': ['receipt_id', 'ts_ms', 'service', 'event_type'], 'properties': {'ts_ms': {'type': 'integer'}, 'payload': {'type': 'object', 'additionalProperties': True}, 'service': {'type': 'string'}, 'event_type': {'type': 'string'}, 'receipt_id': {'type': 'string'}, 'policy_digest': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}, 'PaymentProofEnvelopeInput': {'type': 'object', 'required': ['provider', 'protocol', 'request_hash', 'challenge_or_session_hash', 'payment_proof_or_charge_hash', 'settlement_or_entitlement_hash', 'response_hash'], 'properties': {'amount': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'currency': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'protocol': {'type': 'string'}, 'provider': {'type': 'string'}, 'expires_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'replay_key': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'request_hash': {'type': 'string'}, 'response_hash': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'challenge_or_session_hash': {'type': 'string'}, 'payment_proof_or_charge_hash': {'type': 'string'}, 'settlement_or_entitlement_hash': {'type': 'string'}}}}, 'required': ['service', 'created_ts_ms', 'events'], 'properties': {'events': {'type': 'array', 'items': {'$ref': '#/$defs/BundleDraftEventInput'}, 'minItems': 1}, 'service': {'type': 'string'}, 'created_ts_ms': {'type': 'integer'}, 'payment_context': {'anyOf': [{'$ref': '#/$defs/PaymentProofEnvelopeInput'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'build_bundle_draftDictOutput', 'additionalProperties': True}
proofrelay.build_closing_proof_pack
Build closing proof pack
Build a hash-only closing proof pack manifest from settlement, title, lender, funding, notary, disbursement, and approval hashes. The tool does not authorize closing or disbursement.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['closing_pack'], 'properties': {'closing_pack': {'type': 'object', 'required': ['closing_file_hash'], 'properties': {'notary_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'closing_file_hash': {'type': 'string'}, 'title_policy_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'disbursement_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'lender_package_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'approval_receipt_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'settlement_statement_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'funding_authorization_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'build_closing_proof_packDictOutput', 'additionalProperties': True}
proofrelay.build_human_approval_receipt
Build human approval receipt draft
Build an unsigned, hash-only human approval receipt draft for authority, policy, and subject evidence. The tool does not create approval authority or certify the approver's identity.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['approval'], 'properties': {'approval': {'type': 'object', 'required': ['approver_role', 'approver_hash', 'decision', 'subject_hash'], 'properties': {'decision': {'enum': ['approved', 'rejected', 'needs_changes'], 'type': 'string'}, 'expires_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'scope_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'approval_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'approved_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'policy_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'reason_codes': {'type': 'array', 'items': {'type': 'string'}}, 'subject_hash': {'type': 'string'}, 'approver_hash': {'type': 'string'}, 'approver_role': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}}}}}
Output schema
{'type': 'object', 'title': 'build_human_approval_receiptDictOutput', 'additionalProperties': True}
proofrelay.build_registry_entry
Build registry entry draft
Build a public-safe ProofRelay Registry entry draft for an agent, API, MCP server, workflow, or adapter using only hashes and profile markers.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['entry'], 'properties': {'entry': {'type': 'object', 'required': ['entry_type', 'name', 'subject_hash'], 'properties': {'name': {'type': 'string'}, 'status': {'enum': ['draft', 'evidence_submitted', 'verified_bundle', 'replay_tested', 'listed'], 'type': 'string'}, 'profiles': {'type': 'array', 'items': {'type': 'string'}}, 'entry_type': {'enum': ['mcp_server', 'agent', 'api', 'workflow', 'adapter'], 'type': 'string'}, 'subject_hash': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'replay_test_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'openapi_schema_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'proof_envelope_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'evidence_bundle_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'mcp_server_card_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_context_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'verifier_response_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'identity_reference_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'conformance_fixture_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'build_registry_entryDictOutput', 'additionalProperties': True}
proofrelay.build_title_production_evidence
Build title production evidence
Build a hash-only title production evidence profile from order, property, title-search, commitment, exception, and tax-cert hashes. The tool does not certify title status or legal sufficiency.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['title_evidence'], 'properties': {'title_evidence': {'type': 'object', 'required': ['order_hash', 'property_hash'], 'properties': {'order_hash': {'type': 'string'}, 'property_hash': {'type': 'string'}, 'tax_cert_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'exception_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'production_status': {'enum': ['open', 'clear', 'exceptions', 'review_required'], 'type': 'string'}, 'title_search_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'title_commitment_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'build_title_production_evidenceDictOutput', 'additionalProperties': True}
proofrelay.compute_readiness_signal
Compute readiness signal
Compute a public-safe readiness signal from title, closing, wire, lender-condition, approval, exception, and risk hashes/counts. The tool does not certify readiness to close or fund.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['readiness'], 'properties': {'readiness': {'type': 'object', 'required': ['workflow_hash', 'target_milestone'], 'properties': {'workflow_hash': {'type': 'string'}, 'target_milestone': {'enum': ['title_clear_to_close', 'closing', 'funding', 'disbursement', 'post_close'], 'type': 'string'}, 'wire_review_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'closing_pack_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'critical_risk_count': {'type': 'integer', 'minimum': 0}, 'title_evidence_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'open_condition_count': {'type': 'integer', 'minimum': 0}, 'approval_receipt_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'lender_condition_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'unresolved_exception_count': {'type': 'integer', 'minimum': 0}}}}}
Output schema
{'type': 'object', 'title': 'compute_readiness_signalDictOutput', 'additionalProperties': True}
proofrelay.describe_cli_sdk_helper
Describe CLI and SDK helper
Return public-safe setup guidance for connecting MCP clients to ProofRelay and preparing hash-only evidence inputs without exposing secrets or requiring package installation.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['helper'], 'properties': {'helper': {'type': 'object', 'properties': {'client': {'enum': ['generic', 'claude', 'cursor', 'windsurf', 'codex'], 'type': 'string'}, 'endpoint': {'type': 'string'}}}}}
Output schema
{'type': 'object', 'title': 'describe_cli_sdk_helperDictOutput', 'additionalProperties': True}
proofrelay.describe_stripe_entitlement_flow
Describe Stripe entitlement flow
Return the agent-native Stripe checkout entitlement workflow for ProofRelay paid verification, including token, status, redemption, and replay expectations.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Output schema
{'type': 'object', 'title': 'describe_stripe_entitlement_flowDictOutput', 'additionalProperties': True}
proofrelay.generate_paid_tool_receipt
Generate paid tool receipt draft
Generate an unsigned, hash-only paid MCP/API tool receipt draft that callers can include in a signed ProofRelay bundle. The tool does not charge, redeem, settle, or attest to external facts.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['receipt'], 'properties': {'receipt': {'type': 'object', 'required': ['tool_name', 'ts_ms', 'tool_call_hash', 'result_hash', 'payment_context_hash'], 'properties': {'ts_ms': {'type': 'integer'}, 'tool_name': {'type': 'string'}, 'receipt_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'result_hash': {'type': 'string'}, 'authority_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'tool_call_hash': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'entitlement_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_context_hash': {'type': 'string'}}}}}
Output schema
{'type': 'object', 'title': 'generate_paid_tool_receiptDictOutput', 'additionalProperties': True}
proofrelay.get_verifier_status
Get ProofRelay verifier status
Read the ProofRelay verifier status, accepted bundle shape, and trust boundary before submitting evidence. Use this first when an agent needs to understand what ProofRelay verifies and what it does not.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Output schema
{'type': 'object', 'title': 'get_verifier_statusDictOutput', 'additionalProperties': True}
proofrelay.issue_conformance_badge
Issue conformance badge draft
Build an unsigned ProofRelay evidence-conformance badge draft such as PREP-compatible, Verified Bundle, Verified MCP, or Replay Tested. This is not legal, security, model-safety, or platform certification.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['badge'], 'properties': {'badge': {'type': 'object', 'required': ['badge_type', 'subject_hash', 'criteria_hash'], 'properties': {'profile': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'issued_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'badge_type': {'enum': ['prep_compatible', 'verified_bundle', 'verified_mcp', 'replay_tested'], 'type': 'string'}, 'expires_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'subject_hash': {'type': 'string'}, 'criteria_hash': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'replay_test_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'proof_envelope_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'registry_entry_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'evidence_bundle_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'verifier_response_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'issue_conformance_badgeDictOutput', 'additionalProperties': True}
proofrelay.map_lender_condition_evidence
Map lender condition evidence
Map lender condition text, evidence, reviewer, and waiver hashes into a portable condition profile without satisfying lender conditions.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['condition'], 'properties': {'condition': {'type': 'object', 'required': ['condition_id', 'condition_type', 'condition_hash'], 'properties': {'status': {'enum': ['pending', 'satisfied', 'rejected', 'waived', 'needs_review'], 'type': 'string'}, 'waiver_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'condition_id': {'type': 'string'}, 'reviewer_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'condition_hash': {'type': 'string'}, 'condition_type': {'type': 'string'}, 'evidence_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}}}}}
Output schema
{'type': 'object', 'title': 'map_lender_condition_evidenceDictOutput', 'additionalProperties': True}
proofrelay.map_openapi_operation_evidence
Map OpenAPI operation evidence
Map public OpenAPI operation metadata and schema hashes into a ProofRelay event plan with checkpoint recommendations for paid, mutating, or relied-upon API operations.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['operation'], 'properties': {'operation': {'type': 'object', 'required': ['operation_id', 'method', 'path_template'], 'properties': {'method': {'enum': ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string'}, 'operation_id': {'type': 'string'}, 'path_template': {'type': 'string'}, 'server_url_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_required': {'type': 'boolean'}, 'request_schema_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'idempotency_required': {'type': 'boolean'}, 'response_schema_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'security_scheme_refs': {'type': 'array', 'items': {'type': 'string'}}}}}}
Output schema
{'type': 'object', 'title': 'map_openapi_operation_evidenceDictOutput', 'additionalProperties': True}
proofrelay.normalize_payment_proof
Normalize payment proof envelope
Validate rail-agnostic payment or entitlement proof hashes and return the ProofRelay payment_context evidence profile. This does not charge, settle, custody funds, or verify external payment finality.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['payment_proof'], 'properties': {'payment_proof': {'type': 'object', 'required': ['provider', 'protocol', 'request_hash', 'challenge_or_session_hash', 'payment_proof_or_charge_hash', 'settlement_or_entitlement_hash', 'response_hash'], 'properties': {'amount': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'currency': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'protocol': {'type': 'string'}, 'provider': {'type': 'string'}, 'expires_at': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'replay_key': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'request_hash': {'type': 'string'}, 'response_hash': {'type': 'string'}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'challenge_or_session_hash': {'type': 'string'}, 'payment_proof_or_charge_hash': {'type': 'string'}, 'settlement_or_entitlement_hash': {'type': 'string'}}}}}
Output schema
{'type': 'object', 'title': 'normalize_payment_proofDictOutput', 'additionalProperties': True}
proofrelay.plan_replay_rejection_test
Plan replay rejection test
Return a deterministic replay rejection test plan and optionally classify observed first/replay responses. The tool does not redeem tokens or call paid endpoints.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['replay_test'], 'properties': {'replay_test': {'type': 'object', '$defs': {'ReplayObservation': {'type': 'object', 'properties': {'first_error': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'first_status': {'anyOf': [{'type': 'integer'}, {'type': 'null'}]}, 'second_error': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'second_status': {'anyOf': [{'type': 'integer'}, {'type': 'null'}]}}}}, 'properties': {'observed': {'anyOf': [{'$ref': '#/$defs/ReplayObservation'}, {'type': 'null'}]}, 'redeem_url': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'bundle_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'entitlement_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_protocol': {'enum': ['stripe_checkout_entitlement', 'x402', 'other'], 'type': 'string'}}}}}
Output schema
{'type': 'object', 'title': 'plan_replay_rejection_testDictOutput', 'additionalProperties': True}
proofrelay.recommend_checkpoint
Recommend next checkpoint
Choose the next public-safe GENESIS checkpoint for a paid, material, or relied-upon agent workflow. Submit normalized context only; the tool returns reason codes without protected routing internals.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['workflow_context'], 'properties': {'workflow_context': {'type': 'object', 'required': ['action_class', 'payment_context_present', 'authority_envelope_present', 'evidence_bundle_present', 'counterparty_reliance_expected', 'dispute_or_audit_plausible'], 'properties': {'action_class': {'type': 'string'}, 'reliance_tier': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'action_receipt_present': {'type': 'boolean'}, 'dispute_replay_present': {'type': 'boolean'}, 'evidence_bundle_present': {'type': 'boolean'}, 'payment_context_present': {'type': 'boolean'}, 'artifact_delivery_expected': {'type': 'boolean'}, 'authority_envelope_present': {'type': 'boolean'}, 'dispute_or_audit_plausible': {'type': 'boolean'}, 'verification_result_present': {'type': 'boolean'}, 'counterparty_reliance_expected': {'type': 'boolean'}, 'receiver_acknowledgement_present': {'type': 'boolean'}}}}}
Output schema
{'type': 'object', 'title': 'recommend_checkpointDictOutput', 'additionalProperties': True}
proofrelay.review_vendor_risk_profile
Review vendor risk profile
Review public vendor or MCP server risk metadata for governance signals using hashes and declared boundaries only. This is not legal, security, or procurement certification.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['vendor'], 'properties': {'vendor': {'type': 'object', 'required': ['vendor_name', 'vendor_profile_hash'], 'properties': {'terms_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'vendor_name': {'type': 'string'}, 'control_refs': {'type': 'array', 'items': {'type': 'string'}}, 'data_boundary': {'enum': ['none', 'metadata', 'pii', 'unknown'], 'type': 'string'}, 'requires_payment': {'type': 'boolean'}, 'security_docs_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'subprocessors_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'prior_incident_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'vendor_profile_hash': {'type': 'string'}, 'stores_customer_data': {'type': 'boolean'}, 'requires_authentication': {'type': 'boolean'}}}}}
Output schema
{'type': 'object', 'title': 'review_vendor_risk_profileDictOutput', 'additionalProperties': True}
proofrelay.review_wire_payoff_change
Review wire/payoff change evidence
Review hash-only wire, payoff, or disbursement change metadata for red flags and required controls without approving funds movement.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['wire_change'], 'properties': {'wire_change': {'type': 'object', 'required': ['change_type', 'change_request_hash', 'new_instruction_hash'], 'properties': {'change_type': {'enum': ['wire_instruction', 'payoff_statement', 'disbursement_instruction', 'other'], 'type': 'string'}, 'requester_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'approval_hashes': {'type': 'array', 'items': {'type': 'string'}}, 'observed_red_flags': {'type': 'array', 'items': {'type': 'string'}}, 'change_request_hash': {'type': 'string'}, 'new_instruction_hash': {'type': 'string'}, 'payoff_statement_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'callback_evidence_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'original_instruction_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'review_wire_payoff_changeDictOutput', 'additionalProperties': True}
proofrelay.scan_mcp_risk
Scan MCP risk metadata
Return a read-only, public-metadata MCP risk score from tool descriptors, schemas, and registry claims. Use before listing, integrating, or wrapping another MCP server; it does not fetch network data, require auth, mutate systems, inspect source code, or certify vulnerability status.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['risk_scan'], 'properties': {'risk_scan': {'type': 'object', 'properties': {'tools': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'maxItems': 128}, 'server_name': {'anyOf': [{'type': 'string', 'maxLength': 512}, {'type': 'null'}]}, 'declared_read_only': {'type': 'boolean'}, 'requires_authentication': {'type': 'boolean'}, 'payment_or_entitlement_required': {'type': 'boolean'}}}}}
Output schema
{'type': 'object', 'title': 'scan_mcp_riskDictOutput', 'additionalProperties': True}
proofrelay.summarize_agent_action_log
Summarize agent action log
Summarize public-safe agent action log counts and hashes into a governance review profile without ingesting raw logs or traces.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['action_log'], 'properties': {'action_log': {'type': 'object', 'required': ['log_hash', 'action_count'], 'properties': {'log_hash': {'type': 'string'}, 'actor_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'last_ts_ms': {'anyOf': [{'type': 'integer'}, {'type': 'null'}]}, 'error_count': {'type': 'integer', 'minimum': 0}, 'first_ts_ms': {'anyOf': [{'type': 'integer'}, {'type': 'null'}]}, 'action_count': {'type': 'integer', 'minimum': 0}, 'session_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'authority_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'action_type_counts': {'type': 'object', 'additionalProperties': {'type': 'integer'}}, 'payment_context_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'summarize_agent_action_logDictOutput', 'additionalProperties': True}
proofrelay.verify_bundle
Verify ProofRelay evidence bundle
Verify a submitted non-confidential ProofRelay V1 or V2 evidence bundle for hash integrity, monotonic ordering, signatures, and chain continuity. The tool does not charge, settle, mutate storage, or certify external facts.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['bundle'], 'properties': {'bundle': {'oneOf': [{'type': 'object', '$defs': {'ReceiptEvent': {'type': 'object', 'required': ['receipt_id', 'ts_ms', 'service', 'event_type', 'event_hash'], 'properties': {'v': {'type': 'integer'}, 'sig': {'anyOf': [{'$ref': '#/$defs/ReceiptSignature'}, {'type': 'null'}]}, 'ts_ms': {'type': 'integer'}, 'payload': {'type': 'object', 'additionalProperties': True}, 'service': {'type': 'string'}, 'prev_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'event_hash': {'type': 'string'}, 'event_type': {'type': 'string'}, 'receipt_id': {'type': 'string'}, 'policy_digest': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}, 'ReceiptSignature': {'type': 'object', 'required': ['alg', 'key_id', 'sig'], 'properties': {'alg': {'type': 'string'}, 'sig': {'type': 'string'}, 'key_id': {'type': 'string'}}}}, 'required': ['bundle_hash', 'created_ts_ms', 'service', 'count', 'receipt_ids', 'events'], 'properties': {'v': {'type': 'integer'}, 'count': {'type': 'integer'}, 'events': {'type': 'array', 'items': {'$ref': '#/$defs/ReceiptEvent'}}, 'service': {'type': 'string'}, 'bundle_hash': {'type': 'string'}, 'receipt_ids': {'type': 'array', 'items': {'type': 'string'}}, 'created_ts_ms': {'type': 'integer'}}}, {'type': 'object', '$defs': {'EvidenceEventV2': {'type': 'object', 'required': ['event_id', 'tenant_id', 'service_id', 'sequence', 'occurred_at_ms', 'event_type', 'evidence', 'event_hash', 'producer_signature'], 'properties': {'schema': {'type': 'string', 'const': 'io.genesisre.proofrelay.evidence-event.v2'}, 'event_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'evidence': {'type': 'object', 'maxProperties': 64, 'minProperties': 1, 'propertyNames': {'maxLength': 64, 'minLength': 1}, 'patternProperties': {'^[a-z][a-z0-9_]*$': {'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}}}, 'sequence': {'type': 'integer', 'maximum': 9223372036854775807, 'minimum': 1}, 'tenant_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'event_hash': {'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}, 'event_type': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'service_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'policy_digest': {'anyOf': [{'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}, {'type': 'null'}]}, 'hash_algorithm': {'type': 'string', 'const': 'SHA-256'}, 'occurred_at_ms': {'type': 'integer', 'maximum': 9223372036854775807, 'minimum': 0}, 'canonicalization': {'type': 'string', 'const': 'RFC8785-JCS'}, 'producer_signature': {'$ref': '#/$defs/ProducerSignatureV1'}, 'previous_event_hash': {'anyOf': [{'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}, {'type': 'null'}]}}, 'additionalProperties': False}, 'ProducerSignatureV1': {'type': 'object', 'required': ['algorithm', 'key_id', 'signature'], 'properties': {'key_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'schema': {'type': 'string', 'const': 'io.genesisre.proofrelay.producer-signature.v1'}, 'algorithm': {'enum': ['Ed25519', 'ES256'], 'type': 'string'}, 'signature': {'type': 'string', 'pattern': '^[A-Za-z0-9_-]+$', 'maxLength': 256, 'minLength': 43}}, 'additionalProperties': False}}, 'required': ['tenant_id', 'service_id', 'created_at_ms', 'sequence_start', 'sequence_end', 'event_count', 'events', 'bundle_hash'], 'properties': {'events': {'type': 'array', 'items': {'$ref': '#/$defs/EvidenceEventV2'}, 'maxItems': 10000, 'minItems': 1}, 'schema': {'type': 'string', 'const': 'io.genesisre.proofrelay.evidence-bundle.v2'}, 'tenant_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'service_id': {'type': 'string', 'pattern': '^[a-z0-9](?:[a-z0-9._:-]*[a-z0-9])?$', 'maxLength': 128, 'minLength': 1}, 'bundle_hash': {'type': 'string', 'pattern': '^sha256:[0-9a-f]{64}$'}, 'event_count': {'type': 'integer', 'maximum': 10000, 'minimum': 1}, 'sequence_end': {'type': 'integer', 'minimum': 1}, 'created_at_ms': {'type': 'integer', 'maximum': 9223372036854775807, 'minimum': 0}, 'hash_algorithm': {'type': 'string', 'const': 'SHA-256'}, 'sequence_start': {'type': 'integer', 'minimum': 1}, 'canonicalization': {'type': 'string', 'const': 'RFC8785-JCS'}}, 'additionalProperties': False}]}, 'public_keys': {'type': 'array', 'items': {'type': 'object', 'required': ['tenant_id', 'service_id', 'key_id', 'jwk'], 'properties': {'jwk': {'type': 'object', 'additionalProperties': True}, 'key_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'tenant_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'service_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}}}, 'maxItems': 128}, 'require_chain': {'type': 'boolean'}, 'require_signature': {'type': 'boolean'}}}
Output schema
{'type': 'object', 'title': 'verify_submitted_bundleDictOutput', 'additionalProperties': True}
proofrelay.verify_signed_attestation
Verify signed ProofRelay attestation
Verify a legacy Ed25519 or V2 ES256 ProofRelay artifact using public key material and optional issuer/purpose pins. The tool never accepts private keys and does not sign caller claims.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['verification'], 'properties': {'verification': {'type': 'object', 'required': ['signed_artifact'], 'properties': {'now': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'now_ms': {'anyOf': [{'type': 'integer', 'minimum': 0}, {'type': 'null'}]}, 'public_jwk': {'anyOf': [{'type': 'object', 'additionalProperties': True}, {'type': 'null'}]}, 'public_key_hex': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'expected_issuer': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'signed_artifact': {'type': 'object', 'additionalProperties': True}, 'expected_purpose': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}}}}
Output schema
{'type': 'object', 'title': 'verify_signed_attestationDictOutput', 'additionalProperties': True}
proofrelay.wrap_mcp_tool_evidence
Wrap MCP tool evidence
Convert hash-only MCP tool request, response, schema, authority, and payment context references into a portable ProofRelay evidence wrapper without ingesting raw prompts, outputs, credentials, or logs.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['tool_evidence'], 'properties': {'tool_evidence': {'type': 'object', 'required': ['tool_name', 'request_hash', 'response_hash'], 'properties': {'tool_name': {'type': 'string'}, 'request_hash': {'type': 'string'}, 'tool_call_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'response_hash': {'type': 'string'}, 'authority_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'non_secret_refs': {'type': 'array', 'items': {'type': 'string'}}, 'tool_schema_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'payment_context_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'verifier_response_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}, 'identity_reference_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}]}}, 'additionalProperties': False}}, 'additionalProperties': False}
Output schema
{'type': 'object', 'title': 'wrap_mcp_tool_evidenceDictOutput', 'additionalProperties': True}
Changed
proofrelay.scan_mcp_risk
Sept. 23, 2026, 2:42 a.m.
Changed
proofrelay.wrap_mcp_tool_evidence
Sept. 23, 2026, 2:42 a.m.
Added
proofrelay.verify_signed_attestation
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.issue_conformance_badge
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_registry_entry
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.adapt_agent_identity_evidence
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.compute_readiness_signal
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.map_lender_condition_evidence
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.review_wire_payoff_change
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_closing_proof_pack
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_title_production_evidence
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.review_vendor_risk_profile
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.summarize_agent_action_log
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_audit_pack_manifest
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_human_approval_receipt
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.describe_cli_sdk_helper
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.scan_mcp_risk
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.generate_paid_tool_receipt
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.map_openapi_operation_evidence
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.wrap_mcp_tool_evidence
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.plan_replay_rejection_test
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.adapt_x402_payment_proof
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.describe_stripe_entitlement_flow
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.build_bundle_draft
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.normalize_payment_proof
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.verify_bundle
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.recommend_checkpoint
Sept. 17, 2026, 12:40 p.m.
Added
proofrelay.get_verifier_status
Sept. 17, 2026, 12:40 p.m.