io.github.g-digital-by-Garrigues/gocertius
NPM · @G-DIGITAL/MCP-GOCERTIUS · SCANNED SEP 21
MCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 37 of 111 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Build provenance is cryptographically sound, but it attests a different repository to the one declared in the registry. Most often the declared URL is simply stale. View diagnostics → Unverified
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 12 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability67
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 9650 tokens (~155/item across 62 items; 62 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage72
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 15% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 10 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 62 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.g-digital-by-Garrigues/gocertius MCP server?
io.github.g-digital-by-Garrigues/gocertius runs locally as an npm package, launched with npx -y @g-digital/mcp-gocertius. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @g-digital/mcp-gocertius
claude mcp add g-digital-by-garrigues-gocertius -- npx -y @g-digital/mcp-gocertius
{
"mcpServers": {
"g-digital-by-garrigues-gocertius": {
"command": "npx",
"args": [
"-y",
"@g-digital/mcp-gocertius"
]
}
}
} {
"servers": {
"g-digital-by-garrigues-gocertius": {
"command": "npx",
"args": [
"-y",
"@g-digital/mcp-gocertius"
]
}
}
} codex mcp add g-digital-by-garrigues-gocertius -- npx -y @g-digital/mcp-gocertius
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"g-digital-by-garrigues-gocertius": {
"type": "local",
"command": [
"npx",
"-y",
"@g-digital/mcp-gocertius"
],
"enabled": true
}
}
} openclaw mcp add g-digital-by-garrigues-gocertius --command npx --arg -y --arg @g-digital/mcp-gocertius
mcp_servers:
g-digital-by-garrigues-gocertius:
command: "npx"
args: ["-y", "@g-digital/mcp-gocertius"] {
"McpServers": {
"g-digital-by-garrigues-gocertius": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@g-digital/mcp-gocertius"
]
}
}
} assistant mcp add g-digital-by-garrigues-gocertius -t stdio -c npx -a -y @g-digital/mcp-gocertius
{
"mcpServers": {
"g-digital-by-garrigues-gocertius": {
"command": "npx",
"args": [
"-y",
"@g-digital/mcp-gocertius"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −3
- Stability: pass → 0.77 functional
- 16 Sept 26 0
- Stability: 0.97 → pass security
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed npm/@g-digital/mcp-gocertius@2.0.0
Provenance Repository mismatch
The attestation is cryptographically sound but binds a different repository to the one the registry declares. Most often the declared URL is simply stale.
| Result | Repository mismatch |
|---|---|
| Ecosystem | npm |
| Reason | Repository mismatch |
| Discovered via | Registry attestation endpoint |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/g-digital-by-Garrigues/MCP_Market_Distribution/.github/workflows/publish.yml@refs/heads/main |
| Rekor log index | 2755463524 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:4bdcc75b0fa9101c9ca904f4431d0bdd9adb6422d49160280694c3e8573af13893077a157a0a7e0b5755e452acf0f611a68a29bbd77e632040ec31a92 |
Background: How many MCP packages publish verified provenance →
Dependencies 111 packages
| Packages resolved | 111 |
|---|---|
| Deprecated | 1 |
| Stale | 36 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
notification_request_create ~239
Creates a certified notification request. Requires: case_file_create → caseFileId. Generate a UUID v4 for `id`. Set language to en_GB or es_ES. Returns notificationRequestId. Add at least one receiver with notification_receiver_add before sending. IMPORTANT: The `content` field must be valid HTML — plain text without HTML tags will not render on the recipient landing page. Only the following HTML formats are supported: paragraphs (<p>), bold (<strong>), italic (<em>), unordered lists (<ul><li>), ordered lists (<ol><li>). Do not use other HTML tags or CSS. Avoid special typographic characters (em dashes, smart quotes) in `subject`; use standard ASCII equivalents (hyphen, straight quotes) instead.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | – |
| content | string | yes | – |
| id | string | yes | – |
| language | string | yes | – |
| otpByDefault | boolean | – | – |
| sendSmsUrlByDefault | boolean | – | – |
| sendWaUrlByDefault | boolean | – | – |
| subject | string | yes | – |
| type | string | – | – |
No output schema declared.
No examples provided.
notification_request_delete ~90
Deletes a notification. Requires notificationRequestId and caseFileId. There is no undo. TESTED: once the notification has been sent the API rejects this with 403 Forbidden — a sent notification is delivery evidence and cannot be removed. If you only want it filed elsewhere, use notification_request_case_file_move instead.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | – |
| notificationRequestId | string | yes | – |
No output schema declared.
No examples provided.
notification_request_duplicate ~220
Creates a new DRAFT notification from an existing one, copying its content, its recipients and its attachments. Works whatever state the original is in, so this is how you resend to the same people or reuse a sent notification as a template. Generate a UUID v4 for `id` and supply a new `subject`; pass `caseFileId` in the body to place the copy in a different case file, or omit it to keep it alongside the original. THE COPY IS BUILT ASYNCHRONOUSLY: it starts in CREATING with zero recipients and zero documents, and fills in afterwards, so reading it immediately shows an empty notification that is not empty. Poll notification_request_status until the status is DRAFT before inspecting or sending it. Because recipients ARE copied, review them with notification_receiver_list before calling notification_request_send — otherwise you will send to the original list again.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | – | – |
| id | string | yes | – |
| notificationRequestId | string | yes | – |
| subject | string | yes | – |
No output schema declared.
No examples provided.
notification_request_list ~209
Lists the certified notifications visible to a user. Requires userId (from session_login, session_info or profile_get) — this listing is user-scoped, not case-file-scoped, so it spans every case file unless you filter. Use this to recover a notificationRequestId you no longer have; it is the only way to find one. Returns per notification: id, code, subject, status, type, sentAt, receiverStats and the owning caseFile. Filter by `status` or `statuses` (CREATING, DRAFT, IN_PROCESS, SENT, PARTIALLY_READ, FULLY_READ, PARTIALLY_ANSWERED, FULLY_ANSWERED), by `caseFileIds`, by `search` over the subject, or by `receiversSearch` to find the notification sent to a given recipient. Paginated.
| Name | Type | Req | Description |
|---|---|---|---|
| filter | object | – | – |
| order | object | – | – |
| page | object | – | – |
| userId | string | yes | – |
No output schema declared.
No examples provided.
notification_request_send ~59
Trigger delivery of a certified notification to all added recipients. Returns immediately — delivery is async. Poll notification_request_status until status is DELIVERED before retrieving certificates.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | – |
| notificationRequestId | string | yes | – |
No output schema declared.
No examples provided.
notification_request_status ~111
Checks the delivery status of a certified notification. Requires: notificationRequestId, caseFileId. Returns status (CREATING|DRAFT|IN_PROCESS|SENT|PARTIALLY_READ|FULLY_READ|PARTIALLY_ANSWERED|FULLY_ANSWERED). Poll until status is SENT or beyond. Do not call notification_certificate_get while status is CREATING, DRAFT, or IN_PROCESS.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | – |
| notificationRequestId | string | yes | – |
No output schema declared.
No examples provided.
notification_request_update ~207
Edits a notification that has not been sent: subject, content, type and language. Requires notificationRequestId and caseFileId. `content` must be valid HTML — plain text is accepted by the API but does NOT render on the recipient landing page. Supported tags only: <p>, <strong>, <em>, <ul><li>, <ol><li>; no other tags and no CSS. Keep `subject` to plain ASCII (no em dashes, no smart quotes), 100 characters maximum. TESTED: once the notification has been sent the API rejects this with 403 Forbidden, so editing only works before the send. To change which case file it belongs to use notification_request_case_file_move — this tool does not move it.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | – |
| content | string | – | – |
| language | string | – | – |
| notificationRequestId | string | yes | – |
| subject | string | – | – |
| type | string | – | – |
No output schema declared.
No examples provided.
notification_send ~694
Sends a certified notification to one or more recipients in a single call: creates the notification request, adds every recipient, and sends it. Generates every UUID itself — do not pass any id. Requires case_file_create → caseFileId. `content` MUST be HTML: plain text is accepted by the API and reports SENT but does not render on the recipient's landing page. Supported tags only: <p>, <strong>, <em>, <ul><li>, <ol><li> — no other tags, no CSS. Keep `subject` to plain ASCII, 100 characters maximum. Delivery is always by email; per recipient you can additionally set sendWaUrl (WhatsApp), sendSmsUrl (RCS or SMS depending on the handset) and otpRequired (one-time code), each of which needs phonePrefix with the + and phoneNumber. The maximum number of recipients is a per-subscription setting, not a fixed limit, so none is enforced here — the API rejects an oversized batch. This tool does NOT attach files; use notification_send_with_attachments for that, because attachments must be registered before recipients are added. PARTIAL SUCCESS IS REPORTED, NOT THROWN: if the request was created but a recipient or the send failed, the result still carries notificationRequestId together with recipientsAdded, recipientsFailed and sent:false, so you can finish with notification_receiver_add and notification_request_send instead of abandoning a draft. An INVALID recipient blocks the send, so this tool checks for one before sending and reports invalidRecipients rather than attempting a send that cannot succeed. If the initial create fails the tool raises an error instead: common causes are a caseFileId that does not exist, a subject over 100 characters, and an exhausted contracted notification plan, which no retry will fix. If that error is a timeout rather than a rejection, check notification_request_list before retrying — the request may have been created anyway. Poll notification_request_status for delivery progress, then notification_certificate_get per recipient.
| Name | Type | Req | Description |
|---|---|---|---|
| caseFileId | string | yes | UUID of the case file the notification belongs to |
| content | string | yes | Body of the notification as HTML. Supported tags only: <p>, <strong>, <em>, <ul><li>, <ol><li>. No other tags and no CSS. Plain text is accepted by the API but does NOT render for the recipient. |
| language | string | yes | Language of the notification and its landing page |
| otpByDefault | boolean | – | Require a one-time code for every recipient that does not state its own otpRequired |
| recipients | array | yes | One or more recipients. The maximum is a per-subscription setting that varies by tenant and platform, so no limit is enforced here — if the tenant's cap is exceeded the API says so. |
| sendSmsUrlByDefault | boolean | – | Send the RCS/SMS link to every recipient that does not state its own sendSmsUrl |
| sendWaUrlByDefault | boolean | – | Send the WhatsApp link to every recipient that does not state its own sendWaUrl |
| subject | string | yes | Subject line, 100 characters maximum. Use plain ASCII — avoid em dashes and smart quotes. |
| type | string | – | What the recipient can do: NO_RESPONSE = read only; ACCEPTED_OR_NOT = accept or reject; RECEIVED_AGREE = acknowledge receipt and agree or disagree |
No output schema declared.
No examples provided.
notification_send_with_attachments ~847
Sends a certified notification WITH one or more attached documents to one or more recipients, in a single call. Use notification_send instead when there are no attachments. This tool exists separately because attachments impose an ordering rule the API enforces and does not forgive: documents must be registered and fully uploaded BEFORE any recipient is added, and every document must reach READY_TO_SEND before the notification is sent — otherwise the send fails with 409/404 NOTIFICATION_NOT_FOUND. The tool performs that whole sequence for you: create → register and upload each document → wait for READY_TO_SEND → add recipients → send. Each attachment takes a local file path, base64 content, an HTTPS URL, or an n8n binary reference; the hash and the upload are handled internally. Generates every UUID itself — do not pass any id. Requires case_file_create → caseFileId. `content` MUST be HTML: plain text is accepted by the API and reports SENT but does not render on the recipient's landing page. Supported tags only: <p>, <strong>, <em>, <ul><li>, <ol><li>. Keep `subject` to plain ASCII, 100 characters maximum. Delivery is always by email; per recipient you can additionally set sendWaUrl (WhatsApp), sendSmsUrl (RCS or SMS depending on the handset) and otpRequired (one-time code), each of which needs phonePrefix with the + and phoneNumber. The maximum number of attachments and of recipients are per-subscription settings, not fixed limits, so neither is enforced here. IF AN ATTACHMENT FAILS THE RUN STOPS BEFORE RECIPIENTS ARE ADDED, on purpose: once recipients exist the API will not accept further documents, so continuing would produce a notification that can never carry the missing file. The result reports the draft's notificationRequestId so you can retry or delete it. An INVALID recipient blocks the send, so the tool checks for one before sending and reports invalidRecipients instead of attempting a doomed send. If the initial create fails the tool raises an error ins…
| Name | Type | Req | Description |
|---|---|---|---|
| attachments | array | yes | One or more documents to attach. Each takes a local path, base64 content, an HTTPS URL or an n8n binary reference. The maximum is a per-subscription setting that varies by tenant and platform, so no… |
| caseFileId | string | yes | UUID of the case file the notification belongs to |
| content | string | yes | Body of the notification as HTML. Supported tags only: <p>, <strong>, <em>, <ul><li>, <ol><li>. No other tags and no CSS. Plain text is accepted by the API but does NOT render for the recipient. |
| language | string | yes | Language of the notification and its landing page |
| otpByDefault | boolean | – | Require a one-time code for every recipient that does not state its own otpRequired |
| recipients | array | yes | One or more recipients. The maximum is a per-subscription setting that varies by tenant and platform, so no limit is enforced here — if the tenant's cap is exceeded the API says so. |
| sendSmsUrlByDefault | boolean | – | Send the RCS/SMS link to every recipient that does not state its own sendSmsUrl |
| sendWaUrlByDefault | boolean | – | Send the WhatsApp link to every recipient that does not state its own sendWaUrl |
| subject | string | yes | Subject line, 100 characters maximum. Use plain ASCII — avoid em dashes and smart quotes. |
| type | string | – | What the recipient can do: NO_RESPONSE = read only; ACCEPTED_OR_NOT = accept or reject; RECEIVED_AGREE = acknowledge receipt and agree or disagree |
No output schema declared.
No examples provided.
profile_get ~229
Returns the authenticated user's own profile. It identifies the caller from the session token alone — no email or any other input needed — so it works on every deployment, including a per-request Bearer one. Its `id` field IS your userId (UUID): the value required by case_file_list and every /users/{userId}/... operation. Prefer this over session_info when you need the userId: it is the canonical source. Also returns companyId (needed to subscribe to the notifications SSE stream) and defaultCaseFileId (the personal case file — the one chats must use). Also returns `permit`, a set of booleans — { evidences, idVerifications, notifications, chats, signatures } — that says which tool families this account may use at all: a false entry means every tool in that family returns 403 regardless of inputs, and no retry or different argument will help. Read it before calling into a family for the first time. Note that a family with no tools in this server will read false and that is expected, not a misconfiguration. No parameters.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
session_info ~169
Returns the authenticated user's session info. `type` is how this MCP session authenticated — always 'UserKey', the server's only auth flow. `accountLoginType` is a different fact: how the underlying GoCertius account itself signs in ('Password' or 'OpenId'), reported from GET /profile, null if the API omits it. Use this to retrieve the userId (UUID) required by case_file_list and other user-scoped operations, or to verify who is authenticated. profile_get is the canonical way to obtain the userId and returns more of the profile. Prerequisites: a valid session (call session_login first if needed). Example: session_info() → { userId: '...uuid...', type: 'UserKey', accountLoginType: 'Password' }
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
session_login ~84
Force the GoCertius MCP server to re-authenticate. Takes no parameters and accepts no credentials: the server re-exchanges the user key it was configured with (MCP_AUTH_USER_KEY) for a fresh session token, and this tool reports the resulting userId and expiry. The server manages authentication automatically — call this only to force a re-login or after a 401.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the io.github.g-digital-by-Garrigues/gocertius MCP server?
io.github.g-digital-by-Garrigues/gocertius is an MCP server listed in the public MCP registry as io.github.g-digital-by-Garrigues/gocertius. MCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents. This page covers its npm package (@g-digital/mcp-gocertius).
Is the io.github.g-digital-by-Garrigues/gocertius MCP server safe to use?
io.github.g-digital-by-Garrigues/gocertius scores 79 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.g-digital-by-Garrigues/gocertius MCP server expose?
io.github.g-digital-by-Garrigues/gocertius exposes 62 tools: evidence_create, evidence_list, evidence_seal, evidence_get, evidence_group_create, and 57 more. Their descriptions and schemas cost roughly 9,650 tokens of context every time the server is loaded.
Is the io.github.g-digital-by-Garrigues/gocertius MCP server still maintained?
io.github.g-digital-by-Garrigues/gocertius is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.g-digital-by-Garrigues/gocertius MCP server under?
io.github.g-digital-by-Garrigues/gocertius declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.