What this MCP does
Creates timestamped observations of public URLs with HTTP metadata and SHA-256 fingerprints, and verifies proof records and policies.
Tools
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url'], 'properties': {'url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTP or HTTPS URL to observe'}, 'max_age': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Maximum acceptable observation age in seconds. Defaults to 300. Set to 0 to force a fresh public-network request.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['proof_id'], 'properties': {'policy': {'type': 'object', 'properties': {'status_in': {'type': 'array', 'items': {'type': 'integer', 'maximum': 599, 'minimum': 100}, 'minItems': 1, 'description': 'Allowed HTTP status codes. The rule passes when the observed status is in this list.'}, 'max_age_seconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Maximum allowed age of the stored observation in seconds at verification time.'}, 'final_host_equals': {'type': 'string', 'minLength': 1, 'description': 'Expected lowercase hostname after redirects, for example example.com. Provide a hostname, not a full URL.'}, 'content_hash_equals': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'Expected SHA-256 response-body fingerprint, including the sha256: prefix. Passes only on exact equality.'}, 'original_host_equals': {'type': 'string', 'minLength': 1, 'description': 'Expected lowercase hostname from the originally requested URL. Provide a hostname, not a full URL.'}, 'changed_since_content_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'Prior SHA-256 response-body fingerprint. Passes when the current proof has a different content hash.'}, 'require_same_origin_redirect': {'type': 'boolean', 'description': 'When true, fails if the final URL origin differs from the original URL origin after redirects.'}}, 'description': 'Optional declarative trust policy. All supplied rules must pass for decision PASS; any failed rule yields FAIL. UNKNOWN is reserved for cases where FreshProof cannot make a reliable policy decision.', 'additionalProperties': False}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['proof_id', 'valid', 'decision', 'checks', 'receipt'], 'properties': {'valid': {'type': 'boolean', 'description': 'True when the stored receipt passes deterministic integrity verification.'}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'pass', 'actual', 'expected'], 'properties': {'pass': {'type': 'boolean', 'description': 'Whether this individual rule passed.'}, 'rule': {'type': 'string', 'description': 'Policy rule that was evaluated.'}, 'actual': {'description': 'Observed value used by the rule.'}, 'expected': {'description': 'Expected value or condition used by the rule.'}}, 'additionalProperties': False}}, 'receipt': {'type': 'object', 'required': ['proof_id', 'receipt_hash', 'payload'], 'properties': {'payload': {'type': 'object', 'required': ['version', 'observation_id', 'normalized_url', 'original_url', 'final_url', 'observed_at', 'method', 'status', 'content_hash', 'content_length', 'etag', 'last_modified', 'fetch_duration_ms'], 'properties': {'etag': {'type': ['string', 'null']}, 'method': {'type': 'string', 'const': 'GET'}, 'status': {'type': 'integer', 'maximum': 599, 'minimum': 100}, 'version': {'type': 'string', 'const': 'freshproof-receipt-v1'}, 'final_url': {'type': 'string', 'format': 'uri'}, 'observed_at': {'type': 'string', 'description': 'ISO-8601 timestamp of the observation.'}, 'content_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'original_url': {'type': 'string', 'format': 'uri'}, 'last_modified': {'type': ['string', 'null']}, 'content_length': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'normalized_url': {'type': 'string', 'format': 'uri'}, 'observation_id': {'type': 'string'}, 'fetch_duration_ms': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}, 'receipt_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'SHA-256 content address of the canonical Proof Receipt payload.'}}, 'additionalProperties': False}, 'decision': {'enum': ['PASS', 'FAIL', 'UNKNOWN'], 'type': 'string', 'description': 'Overall policy decision. PASS means every supplied rule passed; FAIL means at least one supplied rule failed; UNKNOWN means a reliable decision could not be made.'}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url', 'policy'], 'properties': {'url': {'type': 'string', 'format': 'uri', 'description': 'Public HTTP or HTTPS URL to observe and verify.'}, 'policy': {'type': 'object', 'properties': {'status_in': {'type': 'array', 'items': {'type': 'integer', 'maximum': 599, 'minimum': 100}, 'minItems': 1, 'description': 'Allowed HTTP status codes. The rule passes when the observed status is in this list.'}, 'max_age_seconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Maximum allowed age of the stored observation in seconds at verification time.'}, 'final_host_equals': {'type': 'string', 'minLength': 1, 'description': 'Expected lowercase hostname after redirects, for example example.com. Provide a hostname, not a full URL.'}, 'content_hash_equals': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'Expected SHA-256 response-body fingerprint, including the sha256: prefix. Passes only on exact equality.'}, 'original_host_equals': {'type': 'string', 'minLength': 1, 'description': 'Expected lowercase hostname from the originally requested URL. Provide a hostname, not a full URL.'}, 'changed_since_content_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'Prior SHA-256 response-body fingerprint. Passes when the current proof has a different content hash.'}, 'require_same_origin_redirect': {'type': 'boolean', 'description': 'When true, fails if the final URL origin differs from the original URL origin after redirects.'}}, 'description': 'Declarative trust policy evaluated against the resulting Proof Receipt.', 'additionalProperties': False}, 'max_age': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Maximum acceptable observation age in seconds. Defaults to 300. Set to 0 to require a fresh public-network request before policy evaluation.'}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['observation', 'verification'], 'properties': {'observation': {'type': 'object', 'required': ['url', 'final_url', 'observed_at', 'age_seconds', 'status', 'content_hash', 'content_length', 'etag', 'last_modified', 'fetch_duration_ms', 'source', 'proof_id', 'receipt_hash'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'etag': {'type': ['string', 'null']}, 'source': {'enum': ['shared_cache', 'fresh_fetch'], 'type': 'string', 'description': 'fresh_fetch means FreshProof made a new public-network request; shared_cache means a stored observation satisfied max_age.'}, 'status': {'type': 'integer', 'maximum': 599, 'minimum': 100}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}, 'final_url': {'type': 'string', 'format': 'uri'}, 'age_seconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'observed_at': {'type': 'string', 'description': 'ISO-8601 timestamp of the observation.'}, 'content_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'receipt_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'last_modified': {'type': ['string', 'null']}, 'content_length': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'fetch_duration_ms': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'verification': {'type': 'object', 'required': ['proof_id', 'valid', 'decision', 'checks', 'receipt'], 'properties': {'valid': {'type': 'boolean', 'description': 'True when the stored receipt passes deterministic integrity verification.'}, 'checks': {'type': 'array', 'items': {'type': 'object', 'required': ['rule', 'pass', 'actual', 'expected'], 'properties': {'pass': {'type': 'boolean', 'description': 'Whether this individual rule passed.'}, 'rule': {'type': 'string', 'description': 'Policy rule that was evaluated.'}, 'actual': {'description': 'Observed value used by the rule.'}, 'expected': {'description': 'Expected value or condition used by the rule.'}}, 'additionalProperties': False}}, 'receipt': {'type': 'object', 'required': ['proof_id', 'receipt_hash', 'payload'], 'properties': {'payload': {'type': 'object', 'required': ['version', 'observation_id', 'normalized_url', 'original_url', 'final_url', 'observed_at', 'method', 'status', 'content_hash', 'content_length', 'etag', 'last_modified', 'fetch_duration_ms'], 'properties': {'etag': {'type': ['string', 'null']}, 'method': {'type': 'string', 'const': 'GET'}, 'status': {'type': 'integer', 'maximum': 599, 'minimum': 100}, 'version': {'type': 'string', 'const': 'freshproof-receipt-v1'}, 'final_url': {'type': 'string', 'format': 'uri'}, 'observed_at': {'type': 'string', 'description': 'ISO-8601 timestamp of the observation.'}, 'content_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'original_url': {'type': 'string', 'format': 'uri'}, 'last_modified': {'type': ['string', 'null']}, 'content_length': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'normalized_url': {'type': 'string', 'format': 'uri'}, 'observation_id': {'type': 'string'}, 'fetch_duration_ms': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}, 'receipt_hash': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$', 'description': 'SHA-256 content address of the canonical Proof Receipt payload.'}}, 'additionalProperties': False}, 'decision': {'enum': ['PASS', 'FAIL', 'UNKNOWN'], 'type': 'string', 'description': 'Overall policy decision. PASS means every supplied rule passed; FAIL means at least one supplied rule failed; UNKNOWN means a reliable decision could not be made.'}, 'proof_id': {'type': 'string', 'pattern': '^fp1_[a-f0-9]{64}$', 'description': 'FreshProof proof identifier returned by observe_url or verify_url.'}}, 'additionalProperties': False}}, 'additionalProperties': False}
Recent tool changes
Similar MCP servers
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…