MCP Server

H/M Content Credentials Evidence Verifier

net.hogarmas/content-credentials
Legal & Compliance Security Public & reachable MCP 2025-11-25

What this MCP does

Validates C2PA status codes and verifies content-credentials evidence, policy decisions, checksums, and audit chains.

create_content_credentials_policy_profile
Create a checksum-bound evidence policy profile
Creates one versioned policy profile from a fixed preset and optional rule overrides. It accepts no source media or evidence and does not authenticate the policy author.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'name': {'type': 'string', 'maxLength': 120}, 'preset': {'enum': ['editorial-review', 'trusted-distribution', 'archive-preservation', 'open-research'], 'type': 'string'}, 'actions': {'type': 'object', 'description': 'Optional allow, review or hold overrides keyed by a published policy rule ID', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'enum': ['allow', 'review', 'hold'], 'type': 'string'}}, 'purpose': {'type': 'string', 'maxLength': 400}}}
get_content_credentials_capabilities
Read Content Credentials verification boundaries
Returns the free tools, byte limits, privacy behavior and interpretation boundaries before any evidence JSON is submitted.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
run_content_credentials_self_check
Run the Content Credentials evidence self-check
Runs a deterministic, zero-input check of valid evidence, tamper detection and audit-chain verification using a synthetic fixture. No source media or caller data is used.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
triage_c2pa_validation_statuses
Interpret C2PA 2.4 validation status codes
Classifies up to 200 C2PA validation status observations against the complete 2.4 standard catalog, flags class mismatches, separates custom codes and returns bounded remediation. Accepts codes or crJSON-style status groups; no media, URL fetching, authentication or payment.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'codes': {'type': 'array', 'items': {'type': 'string', 'maxLength': 160, 'minLength': 1}, 'maxItems': 200, 'description': 'Unclassified C2PA status code strings'}, 'statusCodes': {'type': 'object', 'properties': {'failure': {'type': 'array', 'items': {'anyOf': [{'type': 'string', 'maxLength': 160, 'minLength': 1}, {'type': 'object', 'required': ['code'], 'properties': {'url': {'type': 'string', 'maxLength': 2048}, 'code': {'type': 'string', 'maxLength': 160, 'minLength': 1}, 'explanation': {'type': 'string', 'maxLength': 2000}}}]}, 'maxItems': 200}, 'success': {'type': 'array', 'items': {'anyOf': [{'type': 'string', 'maxLength': 160, 'minLength': 1}, {'type': 'object', 'required': ['code'], 'properties': {'url': {'type': 'string', 'maxLength': 2048}, 'code': {'type': 'string', 'maxLength': 160, 'minLength': 1}, 'explanation': {'type': 'string', 'maxLength': 2000}}}]}, 'maxItems': 200}, 'informational': {'type': 'array', 'items': {'anyOf': [{'type': 'string', 'maxLength': 160, 'minLength': 1}, {'type': 'object', 'required': ['code'], 'properties': {'url': {'type': 'string', 'maxLength': 2048}, 'code': {'type': 'string', 'maxLength': 160, 'minLength': 1}, 'explanation': {'type': 'string', 'maxLength': 2000}}}]}, 'maxItems': 200}}, 'description': 'crJSON-style success, informational and failure arrays'}}}
Output schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['schema', 'ruleset', 'state', 'summary', 'counts', 'affectedDomains', 'items', 'source', 'privacy', 'limitations'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'classification', 'effectiveClass', 'standardClass', 'observedClasses', 'classMismatch', 'occurrences', 'domain', 'scope', 'meaning', 'nextAction', 'submittedContext'], 'properties': {'code': {'type': 'string'}, 'scope': {'type': 'string'}, 'domain': {'type': 'string'}, 'meaning': {'type': 'string'}, 'nextAction': {'type': 'string'}, 'occurrences': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}, 'classMismatch': {'type': 'boolean'}, 'standardClass': {'anyOf': [{'enum': ['success', 'informational', 'failure'], 'type': 'string'}, {'type': 'null'}]}, 'classification': {'enum': ['standard', 'custom-or-unknown', 'invalid-format'], 'type': 'string'}, 'effectiveClass': {'enum': ['success', 'informational', 'failure', 'unclassified'], 'type': 'string'}, 'observedClasses': {'type': 'array', 'items': {'enum': ['success', 'informational', 'failure'], 'type': 'string'}}, 'submittedContext': {'type': 'object', 'required': ['urlPresent', 'explanationPresent', 'returned'], 'properties': {'returned': {'type': 'boolean', 'const': False}, 'urlPresent': {'type': 'boolean'}, 'explanationPresent': {'type': 'boolean'}}, 'additionalProperties': False}}, 'additionalProperties': False}}, 'state': {'enum': ['no-status-codes', 'failure-observed', 'review-required', 'vendor-review-required', 'informational-review', 'no-standard-failure-observed'], 'type': 'string'}, 'counts': {'type': 'object', 'required': ['observations', 'uniqueCodes', 'success', 'informational', 'failure', 'unclassified', 'standard', 'customOrUnknown', 'invalidFormat', 'classMismatches'], 'properties': {'failure': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'success': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'standard': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'uniqueCodes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'observations': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'unclassified': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'informational': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'invalidFormat': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'classMismatches': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'customOrUnknown': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'schema': {'type': 'string', 'const': 'hm.c2pa-status-triage.v1'}, 'source': {'type': 'object', 'required': ['specification', 'specificationVersion', 'statusCodeReference', 'crJsonReference', 'catalogEntries', 'license'], 'properties': {'license': {'type': 'string'}, 'specification': {'type': 'string'}, 'catalogEntries': {'type': 'number', 'const': 115}, 'crJsonReference': {'type': 'string'}, 'statusCodeReference': {'type': 'string'}, 'specificationVersion': {'type': 'string', 'const': '2.4'}}, 'additionalProperties': False}, 'privacy': {'type': 'object', 'required': ['sourceMediaAccepted', 'urlsReturned', 'submittedExplanationsReturned', 'inputPersistedByCore'], 'properties': {'urlsReturned': {'type': 'boolean', 'const': False}, 'sourceMediaAccepted': {'type': 'boolean', 'const': False}, 'inputPersistedByCore': {'type': 'boolean', 'const': False}, 'submittedExplanationsReturned': {'type': 'boolean', 'const': False}}, 'additionalProperties': False}, 'ruleset': {'type': 'string'}, 'summary': {'type': 'string'}, 'limitations': {'type': 'object', 'required': ['validatesAsset', 'validatesManifest', 'verifiesSignature', 'establishesSignerTrust', 'determinesTruth', 'infersCustomCodeMeaning', 'absenceOfFailureProvesValidity'], 'properties': {'validatesAsset': {'type': 'boolean', 'const': False}, 'determinesTruth': {'type': 'boolean', 'const': False}, 'validatesManifest': {'type': 'boolean', 'const': False}, 'verifiesSignature': {'type': 'boolean', 'const': False}, 'establishesSignerTrust': {'type': 'boolean', 'const': False}, 'infersCustomCodeMeaning': {'type': 'boolean', 'const': False}, 'absenceOfFailureProvesValidity': {'type': 'boolean', 'const': False}}, 'additionalProperties': False}, 'affectedDomains': {'type': 'array', 'items': {'type': 'object', 'required': ['domain', 'codes', 'failures'], 'properties': {'codes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}, 'domain': {'type': 'string'}, 'failures': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}}}, 'additionalProperties': False}
verify_content_credentials_audit
Verify an H/M audit evidence envelope
Checks report identity, source-report digest and the local custody hash chain. It does not prove operator identity, authorship or factual truth.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['envelope'], 'properties': {'envelope': {'type': 'object', 'description': 'Privacy-minimized H/M evidence JSON envelope. Source media is not accepted.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
verify_content_credentials_envelope
Verify an H/M evidence envelope checksum
Checks the schema, privacy boundaries and canonical SHA-256 digest of an H/M evidence envelope. It does not inspect source media or authenticate an issuer.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['envelope'], 'properties': {'envelope': {'type': 'object', 'description': 'Privacy-minimized H/M evidence JSON envelope. Source media is not accepted.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
verify_content_credentials_policy_decision
Verify an H/M evidence policy decision
Checks the policy checksum, decision checksum, every per-item rule outcome and aggregate counts. It does not inspect source media, authenticate the sender or certify compliance.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['decision'], 'properties': {'decision': {'type': 'object', 'description': 'H/M policy decision JSON exported by the browser-local Evidence Policy Lab', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}}}
Added
verify_content_credentials_policy_decision
Sept. 17, 2026, 12:54 p.m.
Added
create_content_credentials_policy_profile
Sept. 17, 2026, 12:54 p.m.
Added
verify_content_credentials_audit
Sept. 17, 2026, 12:54 p.m.
Added
verify_content_credentials_envelope
Sept. 17, 2026, 12:54 p.m.
Added
run_content_credentials_self_check
Sept. 17, 2026, 12:54 p.m.
Added
triage_c2pa_validation_statuses
Sept. 17, 2026, 12:54 p.m.
Added
get_content_credentials_capabilities
Sept. 17, 2026, 12:54 p.m.