Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

LayerOne (DocX + Sign)

NPM · LAYERONE-MCP · SCANNED AUG 3

MCP server for LayerOne DocX (documents & Factur-X) and Sign (e-signature) APIs.

Available components

+34 this week 80 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security87
  • No malware found by supply-chain analysis.Pass
  • Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to GOLayerone/layerone-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 45 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability77
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 1530 tokens (~76/item across 20 items; 20 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · layerone-mcp

# add to Claude Code
claude mcp add golayerone-layerone -- npx -y layerone-mcp
# add to Codex CLI
codex mcp add golayerone-layerone -- npx -y layerone-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "golayerone-layerone": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "layerone-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add golayerone-layerone --command npx --arg -y --arg layerone-mcp
# ~/.hermes/config.yaml
mcp_servers:
  golayerone-layerone:
    command: "npx"
    args: ["-y", "layerone-mcp"]
// mcp.json
{
  "mcpServers": {
    "golayerone-layerone": {
      "command": "npx",
      "args": [
        "-y",
        "layerone-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 +58
    • Known CVEs: unverified → partial security
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • Malware scan: unverified → pass security
    • The attested source repository moved: GOLayerone/layerone-mcp security
    • Schema quality: unverified → excellent functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Maintenance: unverified → pass functional
    • MCP protocol: unverified → pass functional
    • Stability: unverified → 0.23 functional
    • Licence: MIT functional
  • 1 Aug 26 +16
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −23
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −18
    • Malware scan: pass → unverified security
  • 27 Jul 26 46

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
GOLayerone/layerone-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/GOLayerone/layerone-mcp/.github/workflows/publish.yml@refs/heads/main
Rekor log index:
1862722949
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:c6c763699c311b0480555cb02ae1fe2f77c9abc17aa54564352a477bf57c54d93a6ad3166599ed36d1ec390004bdf7db3233af31cc835dcefef1445ba
Discovery method:
attestation_endpoint
Dependencies 95 packages

95 packages in the resolved dependency tree · 95 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 20 exposed · ~1,530 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
docx_delete_template ~39

Supprime définitivement un modèle et tout son historique de versions. Action irréversible.

NameTypeReqDescription
template_idstringyesID du modèle à supprimer.

No output schema declared.

No examples provided.

docx_download_template ~52

Télécharge le fichier .docx d'un modèle déposé. Renvoie un résumé du fichier (taille + aperçu base64 tronqué).

NameTypeReqDescription
template_idstringyesID du modèle à télécharger.

No output schema declared.

No examples provided.

docx_download_template_version ~69

Télécharge le fichier .docx d'une version archivée d'un modèle. Renvoie un résumé du fichier (taille + aperçu base64 tronqué).

NameTypeReqDescription
template_idstringyesID du modèle.
version_idintegeryesID numérique de la version archivée.

No output schema declared.

No examples provided.

docx_get_usage_stats ~39

Retourne le plan, le quota (limite / utilisé / restant) et les statistiques d'usage de la clé API DocX.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

docx_list_template_versions ~35

Liste l'historique des versions archivées d'un modèle.

NameTypeReqDescription
template_idstringyesID du modèle.

No output schema declared.

No examples provided.

docx_list_templates ~69

Liste les modèles Word déposés pour la clé API. Un filtre optionnel par nom (contient le texte) est appliqué côté client à partir de la liste retournée.

NameTypeReqDescription
namestringFiltre optionnel : ne garde que les modèles dont le nom contient ce texte.

No output schema declared.

No examples provided.

docx_render_document ~142

Génère un document (PDF ou DOCX) — devis, contrat, attestation — à partir d'un modèle déposé et de données JSON. Renvoie un résumé du fichier généré.

NameTypeReqDescription
json_datastringyesDonnées du document au format chaîne JSON, ex : {"client":"ACME","date":"2026-01-15","total":1200}.
output_filenamestringNom du fichier généré (défaut : document.pdf).
output_formatstringFormat de sortie (défaut : pdf).
template_idstringyesID d'un modèle déjà déposé sur DocX.

No output schema declared.

No examples provided.

docx_render_facturx ~141

Génère une facture électronique conforme à la réforme 2026 (Factur-X / PDF-A3) à partir d'un modèle déposé et de données JSON. Renvoie un résumé du PDF généré (taille + aperçu base64 tronqué).

NameTypeReqDescription
json_datastringyesDonnées de la facture au format chaîne JSON, ex : {"Npiece":"F2026-001","client":"ACME","total":1200}.
output_filenamestringNom du fichier PDF généré (défaut : facture.pdf).
template_idstringyesID d'un modèle déjà déposé sur DocX.

No output schema declared.

No examples provided.

docx_restore_template_version ~63

Restaure une version archivée comme version active du modèle. La version courante est archivée avant écrasement.

NameTypeReqDescription
template_idstringyesID du modèle.
version_idintegeryesID numérique de la version à restaurer.

No output schema declared.

No examples provided.

docx_update_template ~90

Remplace un modèle existant par une nouvelle version (.docx). L'ancienne version est automatiquement archivée (rollback possible).

NameTypeReqDescription
template_base64stringyesNouveau fichier .docx encodé en base64.
template_idstringyesID du modèle à mettre à jour.
template_namestringNom du fichier (défaut : template.docx).

No output schema declared.

No examples provided.

docx_upload_template ~102

Dépose un modèle Word (.docx) sur le compte pour le réutiliser ensuite par son ID. Retourne l'ID du modèle et les balises {{ ... }} détectées. Le fichier est fourni encodé en base64.

NameTypeReqDescription
template_base64stringyesContenu du fichier .docx encodé en base64.
template_namestringNom du fichier modèle (défaut : template.docx).

No output schema declared.

No examples provided.

sign_cancel_document ~43

Annule une demande de signature encore en cours. Impossible si le document est déjà signé.

NameTypeReqDescription
document_idstringyesID du document de signature à annuler.

No output schema declared.

No examples provided.

sign_detect_fields ~67

Analyse un PDF et retourne les emplacements de signature balisés ([[...]]) détectés, avant de l'envoyer à la signature. Le PDF est fourni encodé en base64.

NameTypeReqDescription
pdf_base64stringyesContenu du document PDF encodé en base64.

No output schema declared.

No examples provided.

sign_download_signed_document ~67

Récupère le PDF final signé (signature PAdES qualifiée + certificat de preuve intégré). Disponible une fois le document complété. Renvoie un résumé (titre, taille, aperçu base64 tronqué).

NameTypeReqDescription
document_idstringyesID du document de signature.

No output schema declared.

No examples provided.

sign_get_audit_certificate ~57

Récupère le certificat de preuve juridique complet : qui a signé, depuis quelle IP, à quelle heure, avec la chaîne de hachage cryptographique.

NameTypeReqDescription
document_idstringyesID du document de signature.

No output schema declared.

No examples provided.

sign_get_document_status ~44

Consulte l'état d'avancement d'une demande de signature (en attente, signé, refusé…).

NameTypeReqDescription
document_idstringyesID du document de signature.

No output schema declared.

No examples provided.

sign_send_for_signature ~215

Envoie un PDF à signer électroniquement (eIDAS / PAdES). Crée la demande et envoie l'email d'invitation au signataire. Le PDF est fourni encodé en base64.

NameTypeReqDescription
company_namestringNom de la société affichée au signataire.
document_namestringyesNom du document.
expiry_daysintegerDélai d'expiration de la demande en jours (défaut : 30).
notestringMessage d'accompagnement adressé au signataire.
pdf_base64stringyesContenu du document PDF encodé en base64.
signer_emailstringyesEmail du signataire.
signer_namestringyesNom du signataire.
signer_phonestringTéléphone du signataire au format international (+33…), requis seulement pour l'OTP SMS.
signer_rolestringRôle du signataire (défaut : Client).

No output schema declared.

No examples provided.

sign_send_otp ~87

Envoie un code OTP par SMS au signataire pour vérifier son identité avant la signature.

NameTypeReqDescription
document_idstringyesID du document.
document_namestringNom du document (affiché dans le SMS).
signer_emailstringyesEmail du signataire.
signer_phonestringyesTéléphone du signataire au format international (+33…).

No output schema declared.

No examples provided.

sign_validate_signature ~41

Vérifie cryptographiquement que la signature PAdES du document est intègre et valide.

NameTypeReqDescription
document_idstringyesID du document de signature.

No output schema declared.

No examples provided.

sign_verify_otp ~68

Valide le code OTP saisi par le signataire et retourne l'URL de signature si le code est correct.

NameTypeReqDescription
codestringyesCode reçu par SMS.
document_idstringyesID du document.
signer_emailstringyesEmail du signataire.

No output schema declared.

No examples provided.