Agent Passport System — Cryptographic Identity for AI Agents
REMOTE · MCP.AEOESS.COM · 2 COMPONENTS · SCANNED SEP 22
Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify sse. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the Agent Passport System — Cryptographic Identity for AI Agents MCP server?
Agent Passport System — Cryptographic Identity for AI Agents is a hosted endpoint at https://mcp.aeoess.com/sse, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.aeoess.com
claude mcp add --transport http aeoess-agent-passport-mcp 'https://mcp.aeoess.com/sse'
{
"mcpServers": {
"aeoess-agent-passport-mcp": {
"url": "https://mcp.aeoess.com/sse"
}
}
} {
"servers": {
"aeoess-agent-passport-mcp": {
"type": "http",
"url": "https://mcp.aeoess.com/sse"
}
}
} [mcp_servers.aeoess-agent-passport-mcp] url = "https://mcp.aeoess.com/sse"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"aeoess-agent-passport-mcp": {
"type": "remote",
"url": "https://mcp.aeoess.com/sse",
"enabled": true
}
}
} openclaw mcp add aeoess-agent-passport-mcp --url 'https://mcp.aeoess.com/sse' --transport streamable-http
mcp_servers:
aeoess-agent-passport-mcp:
url: "https://mcp.aeoess.com/sse" {
"McpServers": {
"aeoess-agent-passport-mcp": {
"Transport": "http",
"Url": "https://mcp.aeoess.com/sse"
}
}
} assistant mcp add aeoess-agent-passport-mcp -t streamable-http -u 'https://mcp.aeoess.com/sse'
{
"mcpServers": {
"aeoess-agent-passport-mcp": {
"type": "http",
"url": "https://mcp.aeoess.com/sse"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 31 Aug 26 −47
- Endpoint reachability: reachable → behind authorisation ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Stability: 0.93 → unverified ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 100 → unverified ▼ functional
- 29 Aug 26 0
- A breaking change shipped without a version bump: still 3.3.0 ▼ security
- Tool “evaluate_threshold” was removed ▼ security
- New tool “sign_amendment” functional
- New tool “verify_amendment” functional
- New tool “propose_amendment” functional
- 28 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 150 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- Schema quality: unverified → fail ▼ functional
- Schema quality: unverified → 100 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Schema quality: unverified → poor ▲ functional
- Schema quality: unverified → pass ▲ functional
- First check of Tool coverage: 67 functional
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 3 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.aeoess.com/sse
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.aeoess.com | CN=YE2,O=Let's Encrypt,C=US | 25 Jul 2026 | 23 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 573c4f46b597d0d48a2f939c8d6163c4ada |
| SANs: mcp.aeoess.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.aeoess.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| aeoess.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 404 |
| Header | Value |
|---|---|
| content-security-policy | default-src 'none' |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| sse | https://mcp.aeoess.com/sse | Auth required | 401 | |
| http (plaintext) | http://mcp.aeoess.com/sse | HTTPS enforced | 301 | https://mcp.aeoess.com/sse |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
accept_assignment ~36
[ANY ROLE] Accept your task assignment. Confirms you're ready to work.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID to accept |
No output schema declared.
No examples provided.
activate_emergency ~58
Activate a pre-authorized emergency pathway with evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| pathway_id | string | yes | – |
| trigger_evidence | string | yes | Evidence that trigger conditions are met |
| trust_epoch | number | – | – |
| valid_until | string | yes | – |
No output schema declared.
No examples provided.
add_approval_signature ~60
Add a signature to an approval request.
| Name | Type | Req | Description |
|---|---|---|---|
| key_class | string | – | – |
| office_id | string | – | – |
| request_id | string | yes | – |
| signer_private_key | string | yes | – |
| signer_public_key | string | yes | – |
No output schema declared.
No examples provided.
add_principal_report ~58
Add principal's perspective to an outcome record. Enables three-way divergence reporting.
| Name | Type | Req | Description |
|---|---|---|---|
| divergence_score | number | yes | – |
| observed_outcome | string | yes | – |
| outcome_class | string | yes | – |
| outcome_id | string | yes | – |
No output schema declared.
No examples provided.
apply_reputation_downgrade ~95
Apply import policy downgrade to a foreign vouched reputation.
| Name | Type | Req | Description |
|---|---|---|---|
| accept_from | array | yes | Gateway IDs accepted by import policy |
| agent_id | string | yes | – |
| attested_diversity_score | number | yes | – |
| attested_tier | number | yes | – |
| downgrade_ratio | number | – | – |
| foreign_default_tier | number | – | – |
| origin_gateway_id | string | yes | – |
No output schema declared.
No examples provided.
aps_aggregate_settlement ~181
Aggregate a batch of Attribution Primitives over a half-open settlement period [t0, t1) into a signed SettlementRecord. Each axis (D, P, G, C) produces a per-contributor total with a balanced-Merkle commitment. Residual buckets pool sub-threshold contributors per Build A §4.1. Output is a fully signed record ready for third-party verification. Spec: BUILD-C-SETTLEMENT-PIPELINE.md.
| Name | Type | Req | Description |
|---|---|---|---|
| gateway_did | string | yes | Gateway DID that signs the record |
| gateway_private_key | string | yes | Ed25519 gateway private key (hex) |
| issued_at | string | – | Override issued_at (canonical ISO-8601 UTC ms + Z); defaults to now |
| period | object | yes | – |
| receipts | array | yes | Array of AttributionPrimitives to aggregate |
No output schema declared.
No examples provided.
aps_attribution_receipt_id ~52
Representation boundary helper: compute the canonical sha256 id of an AttributionReceipt's unsigned core. Verifiers use this to detect id tampering.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt | – | yes | AttributionReceipt JSON (signatures ignored) |
No output schema declared.
No examples provided.
aps_build_contributor_query ~138
Build a contributor-query response: given a signed SettlementRecord and a contributor DID, return per-axis (total_weight, contribution_count, merkle_path, axis_root) plus the full signed record so a third party can verify the contributor's share end-to-end without trusting the gateway beyond its public key. Returns null if the contributor has no share in the period.
| Name | Type | Req | Description |
|---|---|---|---|
| contributor_did | string | yes | Contributor DID (data source, compute provider, governance signer, or protocol module identifier) |
| gateway_jwks | string | – | Advisory JWKS URL; not part of the signed material |
| record | – | yes | A signed SettlementRecord |
No output schema declared.
No examples provided.
aps_capability_evaluate_authority ~161
v0.1 capability-token authority evaluation request (M2). Subject signs a request carrying the sink's M1, the delegation chain, and a revealed authority-token preimage. The gateway consumes this to decide permit/deny. Search keywords: capability token, authority evaluation, M2.
| Name | Type | Req | Description |
|---|---|---|---|
| authority_token | object | yes | – |
| challenge | – | yes | SinkChallenge object from M1 |
| delegation_chain | array | yes | v2.x delegation envelopes |
| delegation_chain_root | string | – | Override; otherwise computed from chain |
| freshness_beacon | object | yes | – |
| subject_private_key | string | yes | Subject Ed25519 private key (hex) |
| subject_public_key | string | yes | Subject Ed25519 public key (hex) |
No output schema declared.
No examples provided.
aps_capability_issue_challenge ~166
v0.1 capability-token sink challenge (M1). Sink issues a signed canonical action statement. Returns the SinkChallenge and its challenge_hash. Used to bind the gateway's later policy evaluation to a specific action the sink authored. Search keywords: capability token, sink challenge, M1.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | Canonical action statement |
| required_policy_freshness | object | – | – |
| sink_id | string | yes | DID of the sink issuing the challenge |
| sink_private_key | string | yes | Sink Ed25519 private key (hex) |
| sink_public_key | string | yes | Sink Ed25519 public key (hex) |
| subject_id | string | yes | DID of the subject the challenge is addressed to |
| validity_seconds | integer | – | – |
No output schema declared.
No examples provided.
aps_capability_mint_receipt ~140
v0.1 capability-token gateway receipt (M3). Gateway signs a permit or deny over the sink's exact challenge_hash. Echoes the M2 delegation_chain_root so the sink can verify the gateway saw the same chain the subject committed to. Search keywords: capability token, challenge receipt, gateway receipt, M3.
| Name | Type | Req | Description |
|---|---|---|---|
| decision | string | yes | – |
| deny_reason | string | – | – |
| gateway_private_key | string | yes | – |
| gateway_public_key | string | yes | – |
| policy_digest | string | yes | SHA-256 of the policy bundle used in evaluation |
| request | – | yes | AuthorityEvaluationRequest from M2 |
No output schema declared.
No examples provided.
aps_capability_sign_effect ~189
v0.1 capability-token sink effect receipt (M4). Sink consumes the token preimage from the gateway's M3 (rejecting on nullifier replay), executes the action, and signs an EffectReceipt binding the consumed token to the result. The (M1, M3, M4) tuple is the full attestation record. Search keywords: capability token, effect receipt, M4, sink attestation.
| Name | Type | Req | Description |
|---|---|---|---|
| challenge | – | yes | Original SinkChallenge from M1 (for binding verification) |
| challenge_receipt | – | yes | ChallengeReceipt from M3 |
| effect | object | yes | – |
| expected_delegation_chain_root | string | – | If omitted, falls back to the receipt's own root |
| gateway_public_key | string | yes | Used to verify M3 before consuming the token |
| sink_private_key | string | yes | – |
| sink_public_key | string | yes | – |
No output schema declared.
No examples provided.
aps_check_artifact_citations ~91
Representation boundary: gate a binding artifact's citations. Each citation must resolve to a provided, signed, unexpired receipt whose content + principal match, with per-artifact replay protection.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact | – | yes | CitingArtifact with optional citations[] array |
| binding_context | string | – | Require receipts to be scoped to this binding context |
| receipts | array | yes | AttributionReceipts backing each citation |
No output schema declared.
No examples provided.
aps_check_escalation_required ~122
Escalation boundary: check whether an action on a v2 delegation requires owner confirmation before execution. Returns {required, requirement?, reason?}. Use aps_record_owner_confirmation to clear the flag when required.
| Name | Type | Req | Description |
|---|---|---|---|
| action_class | string | yes | Action class (e.g. 'org_creation', 'spend_above_threshold') |
| action_details | – | – | Structured details; hashed for audit |
| delegation | – | yes | V2Delegation with optional scope.escalation_requirements |
| session_id | string | – | Session id (required for per_session scope) |
No output schema declared.
No examples provided.
aps_check_projection_consistency ~100
Cross-projection consistency check (§2.4): given two projections, confirm they originate from the same signed receipt. Returns {same_receipt: true} or {same_receipt: false, reason: 'DIFFERENT_ACTIONS'|'DIFFERENT_RECEIPTS'|'DIFFERENT_SIGNATURES'|'METADATA_MISMATCH'}.
| Name | Type | Req | Description |
|---|---|---|---|
| projection_a | – | yes | First AttributionProjection |
| projection_b | – | yes | Second AttributionProjection |
No output schema declared.
No examples provided.
aps_compute_attribution_action_ref ~85
Derive the action_ref (hex sha256) for an action tuple. action_ref is the content-addressed anchor that all four axis projections bind to. Useful for indexing primitives by action without constructing the full primitive.
| Name | Type | Req | Description |
|---|---|---|---|
| actionType | string | yes | – |
| agentId | string | yes | – |
| nonce | string | yes | – |
| params | object | yes | – |
No output schema declared.
No examples provided.
aps_compute_compute_axis_weights ~137
Compute the C-axis fractional weight vector from a list of inference billing records (prompt_tokens, completion_tokens). Returns canonical ComputeAxisEntry[] with 6-digit decimal compute_share strings that sum to ~1.0 and feed directly into aps_construct_attribution_primitive. Weights = prompt_tokens + completion_tokens × COMPLETION_MULTIPLIER (default 3.0), normalized per spec BUILD-B §'The C-axis formula'. Parameter names match the SDK: `providers`, optional `profile`.
| Name | Type | Req | Description |
|---|---|---|---|
| profile | – | – | Optional WeightProfile override; defaults to DEFAULT_WEIGHT_PROFILE |
| providers | array | yes | Per-provider billing records |
No output schema declared.
No examples provided.
aps_compute_data_axis_weights ~169
Compute the D-axis fractional weight vector from a list of AccessReceipt records with role, timestamp, and content length. Returns canonical DataAxisEntry[] with 6-digit decimal contribution_weight strings that sum to ~1.0 and feed directly into aps_construct_attribution_primitive. Empty input → empty array; all-zero raw weights → error. Weights = role × recency_decay × length_weight, normalized per spec BUILD-B §'The D-axis formula'. Parameter names match the SDK: `sources`, `action_timestamp`, optional `profile`.
| Name | Type | Req | Description |
|---|---|---|---|
| action_timestamp | string | yes | ISO-8601 UTC ms when the action ran (t_action) |
| profile | – | – | Optional WeightProfile override; defaults to DEFAULT_WEIGHT_PROFILE |
| sources | array | yes | Per-source records with retrieval metadata |
No output schema declared.
No examples provided.
aps_construct_attribution_primitive ~159
Build and sign a four-axis AttributionPrimitive for an action. Axes: D (data sources), P (protocol modules), G (delegation chain), C (compute providers). Returns the complete signed object.
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | Action identity tuple; the action_ref is derived as sha256(canonical(this)) |
| axes | object | yes | Four-axis content. See spec §1.2 for entry shapes per axis. |
| issuer | string | yes | Issuer DID (gateway or agent producing the receipt) |
| issuer_private_key | string | yes | Ed25519 private key hex that signs the envelope |
| timestamp | string | – | ISO-8601 UTC with ms precision + Z (§2.5). Defaults to now(). |
No output schema declared.
No examples provided.
aps_create_attribution_receipt ~205
Representation boundary: build a citer-signed AttributionReceipt attributing a claim to a third-party principal. The receipt is not yet valid — the cited principal must sign consent via aps_sign_attribution_consent before checkArtifactCitations accepts it.
| Name | Type | Req | Description |
|---|---|---|---|
| binding_context | string | yes | ID of the binding artifact this citation is scoped to |
| citation_content | string | yes | The quoted or paraphrased claim |
| cited_principal | string | yes | DID/public key of the cited principal |
| cited_principal_public_key | string | yes | Hex public key of cited principal |
| citer | string | yes | DID/public key of the citing agent |
| citer_private_key | string | yes | Hex private key of citer |
| citer_public_key | string | yes | Hex public key of citer |
| gateway_id | string | – | Gateway id for timestamping (default: 'mcp') |
| ttl_ms | number | – | Receipt TTL in ms (default: 24h) |
No output schema declared.
No examples provided.
aps_create_provisional ~156
Commitment boundary: emit a provisional statement for agent-to-agent negotiation. Default is non-binding until a PromotionEvent satisfies a PromotionPolicy. Dead-man expiry auto-withdraws.
| Name | Type | Req | Description |
|---|---|---|---|
| author | string | yes | AgentDID/public key of the emitting agent |
| author_principal | string | yes | PrincipalDID behind the author |
| author_private_key | string | yes | Hex private key of author for signing |
| content | string | yes | Statement content (offer, position, claim) |
| dead_man_ms | number | – | Dead-man expiry relative to now (ms). If elapsed without promotion/withdrawal, statement auto-withdraws. |
| gateway_id | string | – | Gateway id for timestamping (default: 'mcp') |
No output schema declared.
No examples provided.
aps_project_attribution ~92
Extract a single-axis projection from an AttributionPrimitive. The projection carries the axis content plus a two-hop Merkle path that lets a downstream verifier reconstruct the signed root without seeing the other three axes. axis: 'D' | 'P' | 'G' | 'C'.
| Name | Type | Req | Description |
|---|---|---|---|
| axis | string | yes | Axis to project |
| primitive | – | yes | An AttributionPrimitive (from aps_construct_attribution_primitive) |
No output schema declared.
No examples provided.
aps_promote_statement ~108
Commitment boundary: promote a provisional statement to binding by attaching a PromotionEvent that satisfies the PromotionPolicy (m-of-n principal signatures). dead_man_elapsed cannot promote — it auto-withdraws via the dead-man path.
| Name | Type | Req | Description |
|---|---|---|---|
| policy | – | yes | PromotionPolicy {id, required_signers, threshold, max_time_to_promote} |
| promotion_event | – | yes | PromotionEvent with kind, promoted_at, promoter, promoter_signature, policy_reference |
| statement | – | yes | ProvisionalStatement from aps_create_provisional |
No output schema declared.
No examples provided.
aps_record_owner_confirmation ~140
Escalation boundary: owner signs an OwnerConfirmation authorizing a flagged action. Builds the ConfirmationRequest and signs it in a single call. The confirmation is bound to action_details via hash and scoped (per_action / per_session / time_window).
| Name | Type | Req | Description |
|---|---|---|---|
| action_class | string | yes | Action class being confirmed |
| action_details | – | yes | Structured action details — hashed and bound to the confirmation |
| delegation | – | yes | V2Delegation with escalation_requirements for this action class |
| owner_private_key | string | yes | Hex private key of the delegation's owner (delegator) |
| session_id | string | – | Session id (required for per_session scope) |
No output schema declared.
No examples provided.
aps_sign_attribution_consent ~76
Representation boundary: the cited principal adds their consent signature to an AttributionReceipt. Without this signature, verifyAttributionConsent and checkArtifactCitations reject the receipt.
| Name | Type | Req | Description |
|---|---|---|---|
| cited_principal_private_key | string | yes | Hex private key of cited principal |
| receipt | – | yes | AttributionReceipt JSON from aps_create_attribution_receipt |
No output schema declared.
No examples provided.
aps_verify_attribution_consent ~61
Representation boundary: verify an AttributionReceipt end-to-end (id, citer signature, consent signature, expiry). Returns {valid, reason?}.
| Name | Type | Req | Description |
|---|---|---|---|
| now | – | – | Optional HybridTimestamp to pin the evaluation moment |
| receipt | – | yes | AttributionReceipt JSON |
No output schema declared.
No examples provided.
aps_verify_attribution_primitive ~76
End-to-end verify of a full AttributionPrimitive: constructs projections for all four axes and verifies each one. Useful as a post-construction sanity check or for verifying a primitive received from a peer.
| Name | Type | Req | Description |
|---|---|---|---|
| issuer_public_key | string | yes | Issuer Ed25519 public key hex |
| primitive | – | yes | An AttributionPrimitive |
No output schema declared.
No examples provided.
aps_verify_attribution_projection ~107
Verify a single-axis AttributionProjection under the issuer's Ed25519 public key. Returns {valid: true} or {valid: false, reason: 'INVALID_AXIS_TAG'|'MERKLE_MISMATCH'|'SIGNATURE_INVALID'|'MALFORMED'}. Verification is purely local — no other axes required.
| Name | Type | Req | Description |
|---|---|---|---|
| issuer_public_key | string | yes | Issuer Ed25519 public key hex |
| projection | – | yes | An AttributionProjection (from aps_project_attribution) |
No output schema declared.
No examples provided.
aps_verify_promotion ~75
Commitment boundary: verify that a promoted statement's PromotionEvent cryptographically satisfies the PromotionPolicy (policy_reference match, promoter in required_signers, threshold, signature, max_time_to_promote, author-signature tamper check).
| Name | Type | Req | Description |
|---|---|---|---|
| policy | – | yes | PromotionPolicy to check against |
| statement | – | yes | Promoted ProvisionalStatement |
No output schema declared.
No examples provided.
aps_verify_settlement ~154
Verify a signed SettlementRecord under S1-S5 (signature, Merkle roots, conservation, residual shape, optional input-receipts cross-check). S3 conservation is the strongest invariant: a gateway cannot inflate or suppress any contributor's share without breaking it. Returns {valid: true} or {valid: false, reason, detail}. Pass inputReceipts to also recompute input_receipts_hash.
| Name | Type | Req | Description |
|---|---|---|---|
| gateway_public_key | string | yes | Gateway Ed25519 public key hex |
| input_receipts | array | – | Optional — the input Attribution Primitives that fed the settlement. When supplied, S5 cross-checks input_receipts_hash and verifies each receipt individually. |
| record | – | yes | A signed SettlementRecord |
No output schema declared.
No examples provided.
aps_withdraw_provisional ~110
Commitment boundary: author withdraws their own provisional statement. Already-promoted statements cannot be withdrawn. Caller must supply the author's signature over the withdrawal payload (canonicalize({action:'withdraw', statement_id})).
| Name | Type | Req | Description |
|---|---|---|---|
| author_private_key | string | – | If provided, tool signs the withdrawal payload with this key. |
| author_signature | string | – | Hex Ed25519 signature. If omitted, provide author_private_key and the tool will sign for you. |
| statement | – | yes | ProvisionalStatement to withdraw |
No output schema declared.
No examples provided.
assign_agent ~93
[OPERATOR] Assign an agent to a role in a task. Creates a delegation automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | Agent ID |
| agent_public_key | string | yes | Agent's Ed25519 public key |
| role | string | yes | Role to assign |
| scope | array | yes | Delegation scopes |
| spend_limit | number | – | Max spend |
| task_id | string | yes | Task ID |
No output schema declared.
No examples provided.
attest_to_floor ~48
Attest that your agent agrees to abide by the loaded Values Floor.
| Name | Type | Req | Description |
|---|---|---|---|
| extensions | array | – | Optional additional extensions |
| floor_version | string | yes | Version of the floor to attest to |
No output schema declared.
No examples provided.
broadcast ~79
Send a signed message to all agents via comms/broadcast.json.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | – | Structured data payload |
| message | string | yes | Message body |
| priority | string | – | Priority: low, normal, high, critical |
| subject | string | yes | Message subject |
| type | string | – | Message type (default: 'broadcast') |
No output schema declared.
No examples provided.
check_aggregate_constraints ~100
Check if a data access would violate aggregate rate limits.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | yes | – |
| burstLimit | number | – | – |
| currentAccessCount | number | yes | – |
| currentRecordCount | number | yes | – |
| lastAccessMs | number | yes | – |
| maxAccessesPerWindow | number | – | – |
| sourceId | string | yes | – |
| windowMs | number | – | – |
| windowStartMs | number | yes | – |
No output schema declared.
No examples provided.
check_combination_permitted ~89
Check if combining data from two sources is permitted. Prevents prohibited inferences (HIPAA, COPPA, GDPR Art 9).
| Name | Type | Req | Description |
|---|---|---|---|
| forbiddenSourceClasses | array | – | – |
| forbiddenSourceIds | array | – | – |
| otherSourceClasses | array | – | – |
| otherSourceId | string | yes | – |
| reason | string | yes | – |
| regulatoryBasis | string | – | – |
No output schema declared.
No examples provided.
check_jurisdiction_transfer ~98
Check if a data transfer is permitted under jurisdiction constraints (EU_ONLY, GDPR_ADEQUATE_ONLY, NO_CROSS_BORDER).
| Name | Type | Req | Description |
|---|---|---|---|
| processingRestrictions | array | – | – |
| purpose | string | yes | – |
| sourceJurisdiction | string | yes | ISO 3166-1 alpha-2 code |
| targetJurisdiction | string | yes | ISO 3166-1 alpha-2 code |
| transferConstraints | array | – | – |
No output schema declared.
No examples provided.
check_messages ~61
Check messages addressed to you. Reads from comms/to-{your-agent-name}.json.
| Name | Type | Req | Description |
|---|---|---|---|
| mark_read | boolean | – | Mark returned messages as processed (default: false) |
| unprocessed_only | boolean | – | Only show unprocessed messages (default: true) |
No output schema declared.
No examples provided.
check_purpose_permitted ~68
Check if a purpose is permitted under source terms. Supports wildcards (research:*) and hierarchical matching.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedPurposes | array | yes | Purposes allowed by the source terms |
| purpose | string | yes | Purpose to check (e.g. research:academic, training:model) |
No output schema declared.
No examples provided.
check_retention_expired ~61
Check if data retention has expired based on TTL policy.
| Name | Type | Req | Description |
|---|---|---|---|
| accessType | string | – | – |
| accessedAt | string | yes | ISO timestamp of when data was accessed |
| maxRetentionMs | – | yes | Max retention in ms (null = no limit) |
No output schema declared.
No examples provided.
check_tier ~110
Check if an agent's earned tier permits an action at a given autonomy level and spend amount. Returns null if permitted, or escalation details if tier is insufficient.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | yes | Agent ID |
| principalId | string | yes | Principal ID |
| requestedAutonomy | number | – | Requested autonomy level (1-5) |
| requestedDepth | number | – | Requested delegation depth |
| requestedSpend | number | – | Requested spend amount in dollars |
| scope | string | yes | Reputation scope |
No output schema declared.
No examples provided.
check_usage_permitted ~43
Check if a specific usage type is permitted under a governance block's terms.
| Name | Type | Req | Description |
|---|---|---|---|
| block | string | yes | Governance block JSON string |
| usage | string | yes | – |
No output schema declared.
No examples provided.
classify_evidence_quality ~90
Classify attestation evidence quality (none / issuer_vouched / infrastructure / principal_bound) and return the corresponding grade (0-3).
| Name | Type | Req | Description |
|---|---|---|---|
| evidence | object | – | Evidence object (checked for known infrastructure keys) |
| has_issuer_signature | boolean | – | – |
| has_principal_binding | boolean | – | – |
| method | string | – | Attestation method (e.g. 'spiffe') |
No output schema declared.
No examples provided.
commerce_preflight ~139
[moved to gateway in SDK 3.3.0] The 6-gate commerce preflight orchestration moved out of the SDK and MCP into the AEOESS gateway. This tool no longer runs the pipeline locally; it returns a machine-readable deprecation notice pointing to the gateway commerce endpoint. Compose the pure gate predicates from the SDK yourself, or call the gateway.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | Agent making the purchase |
| amount | number | yes | Purchase amount |
| currency | string | – | Currency code |
| delegation_id | string | yes | Commerce delegation ID |
| merchant_name | string | yes | Merchant to purchase from |
No output schema declared.
No examples provided.
compare_timestamps ~31
Compare two hybrid timestamps to determine ordering.
| Name | Type | Req | Description |
|---|---|---|---|
| a | object | yes | – |
| b | object | yes | – |
No output schema declared.
No examples provided.
complete_action ~81
[deprecated in v3.0.0 — use gateway.aeoess.com REST API] Complete a permitted action and get the full 3-signature proof chain.
| Name | Type | Req | Description |
|---|---|---|---|
| intent_id | string | yes | Intent ID from execute_with_context result |
| status | string | yes | Outcome of the action |
| summary | string | yes | Brief description of what was accomplished |
No output schema declared.
No examples provided.
complete_task ~54
[OPERATOR] Close the task unit with final status and retrospective.
| Name | Type | Req | Description |
|---|---|---|---|
| retrospective | string | – | What went well, what didn't |
| status | string | yes | Final status |
| task_id | string | yes | Task ID |
No output schema declared.
No examples provided.
compute_action_ref ~83
Compute content-addressed request identity (SHA-256 of agentId + actionType + scope + normalized timestamp). Two receipts with the same action_ref describe the same request.
| Name | Type | Req | Description |
|---|---|---|---|
| action_type | string | yes | – |
| agent_id | string | yes | – |
| scope_required | array | yes | – |
| timestamp | string | – | ISO 8601 timestamp; defaults to now |
No output schema declared.
No examples provided.
compute_governance_taint ~52
Compute governance taint level for an artifact based on its derivation chain and revoked sources.
| Name | Type | Req | Description |
|---|---|---|---|
| artifactId | string | yes | – |
| revokedSources | array | – | Source IDs that have been revoked |
No output schema declared.
No examples provided.
create_access_receipt ~117
Create a signed access receipt — cryptographic proof that your agent consumed content under specific terms. The receipt captures terms and revocation policy at access time.
| Name | Type | Req | Description |
|---|---|---|---|
| agentPrivateKey | string | yes | Your agent's Ed25519 private key (hex) |
| agentPublicKey | string | yes | Your agent's Ed25519 public key (hex) |
| block | string | yes | Governance block JSON string |
| intendedUsage | string | yes | How you intend to use this content |
| sourceUrl | string | yes | URL where content was accessed |
No output schema declared.
No examples provided.
What is the Agent Passport System — Cryptographic Identity for AI Agents MCP server?
Agent Passport System — Cryptographic Identity for AI Agents is an MCP server listed in the public MCP registry as io.github.aeoess/agent-passport-mcp. Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools. This page covers its hosted endpoint (https://mcp.aeoess.com/sse).
Is the Agent Passport System — Cryptographic Identity for AI Agents MCP server safe to use?
Agent Passport System — Cryptographic Identity for AI Agents scores 23 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Agent Passport System — Cryptographic Identity for AI Agents MCP server expose?
Agent Passport System — Cryptographic Identity for AI Agents exposes 152 tools: list_profiles, list_tools_for_scope, identify, generate_keys, issue_passport, and 147 more. Their descriptions and schemas cost roughly 13,504 tokens of context every time the server is loaded.
Does the Agent Passport System — Cryptographic Identity for AI Agents MCP server require authentication?
No. We connected to Agent Passport System — Cryptographic Identity for AI Agents without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Agent Passport System — Cryptographic Identity for AI Agents MCP server still maintained?
Agent Passport System — Cryptographic Identity for AI Agents is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.