MCP Server

JIDEC: Bitcoin-anchored public verification ledger (NENRIN)

io.github.ogasurfproject-jpg/jidec
Security Public & reachable MCP 2026-07-28

What this MCP does

Cites, independently verifies, lists, and replays Bitcoin-anchored construction-estimate verification records.

jidec_cite
Cite and independently verify a JIDEC record
Resolve and INDEPENDENTLY verify any JIDEC citation. Accepts 'jidec:path:<sha>', 'jidec:entry:<n>', a bare 64-hex id, or a ledger URL. Fetches the record's exact bytes, recomputes SHA-256 locally, and confirms it equals the cited id. Returns integrity, Bitcoin anchoring status, the parsed record (verification path, claim, or v0 spec entry), and an explicit statement of what the proof does and does not cover. No trust in HORIZON SHIELD is required to accept the result.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['citation'], 'properties': {'citation': {'type': 'string', 'description': 'jidec:path:<sha> | jidec:entry:<n> | 64-hex | ledger URL'}}}
Output schema
{'type': 'object', 'required': ['lookup', 'integrity'], 'properties': {'limits': {'type': 'string'}, 'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'bitcoin': {'type': 'object', 'properties': {'status': {'type': 'string'}}}, 'citation': {'type': 'string'}, 'integrity': {'type': 'object', 'required': ['match'], 'properties': {'match': {'type': 'boolean'}, 'claimed_sha256': {'type': 'string'}, 'recomputed_sha256': {'type': 'string'}}, 'description': 'The whole point: claimed vs recomputed. match:false is an integrity FAILURE, which is a finding, not an error.'}, 'trust_note': {'type': 'string'}, 'record_kind': {'type': 'string'}, 'resolved_entry': {'type': ['number', 'string', 'null']}}, 'additionalProperties': True}
jidec_how_to_verify
Get the executable verification recipe
Return the step-by-step recipe for verifying a JIDEC record WITHOUT trusting HORIZON SHIELD: which bytes to fetch, which hashes to recompute, which OpenTimestamps proof to check, which algorithm commit to check out, and what must match. Use this when you want to confirm the result yourself rather than repeat an assertion.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['citation'], 'properties': {'citation': {'type': 'string', 'description': 'jidec:path:<sha> | jidec:entry:<n> | 64-hex | ledger URL'}}}
Output schema
{'type': 'object', 'required': ['lookup'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'recipe': {'type': ['object', 'string']}, 'path_id': {'type': 'string'}, 'citation': {'type': 'string'}, 'resolved_entry': {'type': ['number', 'string', 'null']}}, 'additionalProperties': True}
jidec_list_paths
List anchored verification paths
List the anchored JIDEC verification paths (most recent first), with purpose, verdict and Bitcoin anchoring status.
Read only Open world Idempotent
Input schema
{'type': 'object', 'properties': {}}
Output schema
{'type': 'object', 'required': ['lookup', 'count'], 'properties': {'count': {'type': 'number', 'description': 'How many anchored paths the ledger returned. 0 means the ledger answered and holds none. It never means the ledger could not be read, that is an error.'}, 'paths': {'type': 'array', 'items': {'type': 'object'}}, 'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}}, 'additionalProperties': True}
jidec_replay
Re-observe an anchored path and report drift
Re-observe an anchored JIDEC verification path against the live system right now and report drift. Returns MATCH (the live system still matches what was anchored) or DRIFT (it changed), node by node. Nodes that cannot be re-observed server-side are reported as deferred, never counted as drift.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['citation'], 'properties': {'citation': {'type': 'string', 'description': 'jidec:path:<sha> | jidec:entry:<n> | ledger URL'}}}
Output schema
{'type': 'object', 'required': ['lookup'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'verdict': {'type': 'string', 'description': 'MATCH or DRIFT. Nodes that could not be re-observed are deferred, never counted as drift.'}}, 'additionalProperties': True}
nenrin_ledger_entry
One ledger entry by number
Return ledger entry n as the ledger serves it: claim_sha256, the canonical record bytes, work description, OpenTimestamps status and Bitcoin block when anchored. Pair with jidec_how_to_verify to recompute it.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['n'], 'properties': {'n': {'type': 'integer', 'minimum': 1, 'description': 'entry number'}}}
Output schema
{'type': 'object', 'required': ['lookup', 'source_url'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'source_url': {'type': 'string', 'description': 'The public ledger URL that returned this body. Fetch it yourself to compare.'}, 'does_not_establish': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': True}
nenrin_ledger_head
Current ledger head and its bound end marker
Return the current head of the JIDEC/NENRIN ledger: entry count n, the head hash, and the end marker bound into the chain (jidec-head-v1) with the recipe to recompute it. Compare it with a head you saw earlier to detect truncation or rewrite.
Read only Open world Idempotent
Input schema
{'type': 'object', 'properties': {}}
Output schema
{'type': 'object', 'required': ['lookup', 'source_url'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'source_url': {'type': 'string', 'description': 'The public ledger URL that returned this body. Fetch it yourself to compare.'}, 'does_not_establish': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': True}
nenrin_resume
Recorded conduct history of an endpoint (NENRIN résumé)
Return the NENRIN résumé of an agent or MCP endpoint: every recorded measurement that touches its origin (by the gate and by outside witnesses, signed or not), which are Bitcoin-anchored, discrepancies, rings, agreements, and the records not counted with the reason. Includes resume_sha256 and a recompute recipe. A history, not a score. Absent means no record, not a negative finding.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['endpoint'], 'properties': {'endpoint': {'type': 'string', 'description': 'https URL of the agent or MCP endpoint, e.g. https://mcp.horizonshield.dev/mcp'}}}
Output schema
{'type': 'object', 'required': ['lookup', 'source_url'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'source_url': {'type': 'string', 'description': 'The public ledger URL that returned this body. Fetch it yourself to compare.'}, 'does_not_establish': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': True}
nenrin_trust_signal
Compact conduct signal of an endpoint
Return the compact NENRIN signal for an endpoint: counts of anchored measurements, witness diversity and freshness, in a shape a trust engine or orderer can read. No score, no allow or deny.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['endpoint'], 'properties': {'endpoint': {'type': 'string', 'description': 'https URL of the agent or MCP endpoint'}}}
Output schema
{'type': 'object', 'required': ['lookup', 'source_url'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'source_url': {'type': 'string', 'description': 'The public ledger URL that returned this body. Fetch it yourself to compare.'}, 'does_not_establish': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': True}
nenrin_witness
One witness record by its SHA-256
Return one NENRIN witness record by its record SHA-256: pending or anchored, and when anchored, the ledger entry and batch that carry it. Use it to check a walk someone says they submitted.
Read only Open world Idempotent
Input schema
{'type': 'object', 'required': ['sha256'], 'properties': {'sha256': {'type': 'string', 'description': '64-hex record SHA-256'}}}
Output schema
{'type': 'object', 'required': ['lookup', 'source_url'], 'properties': {'lookup': {'enum': ['ok', 'absent'], 'type': 'string', 'description': "ok = the ledger was read and the record exists. absent = the ledger was read and there is no such record. A read that FAILED never appears here: it comes back as a tool error (isError: true), so a consumer can never mistake this server's own failure for a statement about the ledger's contents."}, 'source_url': {'type': 'string', 'description': 'The public ledger URL that returned this body. Fetch it yourself to compare.'}, 'does_not_establish': {'type': 'array', 'items': {'type': 'string'}}}, 'additionalProperties': True}
Added
nenrin_ledger_entry
Oct. 1, 2026, 2:47 a.m.
Added
nenrin_ledger_head
Oct. 1, 2026, 2:47 a.m.
Added
nenrin_witness
Oct. 1, 2026, 2:47 a.m.
Added
nenrin_trust_signal
Oct. 1, 2026, 2:47 a.m.
Added
nenrin_resume
Oct. 1, 2026, 2:47 a.m.
Added
jidec_how_to_verify
Sept. 17, 2026, 12:45 p.m.
Added
jidec_list_paths
Sept. 17, 2026, 12:45 p.m.
Added
jidec_replay
Sept. 17, 2026, 12:45 p.m.
Added
jidec_cite
Sept. 17, 2026, 12:45 p.m.