mcp
Verifiable provenance for AI agents — ZK proofs over confidential documents, no plaintext exposure.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (1)
- LOWin lemma_query_verified_attributes
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"@lemmaoracle/mcp"
]
}
}
}Ausführbare Pakete
0.0.17stdioRemote-Endpunkte
https://mcp.lemma.workers.dev/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (5)
🟢lemma_query_verified_attributes(attributes, schemas, chainIds, limit, offset)
Query cryptographically verified attributes from Lemma. Use this as the primary tool for finding documents whose attributes match given conditions (e.g., "subject's birthYear lt 2008"). Returns { results: Array<{ docHash, schema, issuerId, subjectId, attributes, isVerified, proof?: { status, circuitId, chainId }, disclosure? }>, hasMore }. The MCP layer enriches each item with an `isVerified` flag derived from `proof.status` (true when status is 'verified' or 'onchain-verified'). Use lemma_get_proof_status to monitor a specific proof; use lemma_get_schema to interpret the keys returned in `attributes`.
Eingabe-Schema
{
"type": "object",
"properties": {
"attributes": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Attribute key as defined by the schema."
},
"operator": {
"type": "string",
"enum": [
"eq",
"neq",
"gt",
"gte",
"lt",
"lte",
"in",
"contains"
],
"description": "Comparison operator. Defaults to eq when omitted. 'in' takes an array value; 'contains' is substring/array-element match."
},
"value": {
"description": "Comparison target value. Type depends on the schema's attribute definition. For 'in', pass an array."
}
},
"required": [
"name"
],
"additionalProperties": false
},
"description": "Attribute predicates to AND-combine."
},
"schemas": {
"type": "array",
"items": {
"type": "string"
},
"description": "Restrict results to documents conforming to these schema IDs."
},
"chainIds": {
"type": "array",
"items": {
"type": "number"
},
"description": "Restrict results to attributes verified on these chain IDs (EVM)."
},
"limit": {
"type": "number",
"minimum": 1,
"maximum": 200,
"description": "Max results per page (1–200). Defaults to API server default (50)."
},
"offset": {
"type": "number",
"minimum": 0,
"description": "Pagination offset. Pair with `hasMore` in the response to walk pages."
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Ausgabe-Schema
{
"type": "object",
"properties": {
"results": {
"type": "array",
"items": {
"type": "object",
"properties": {
"docHash": {
"type": "string",
"description": "Document hash (commitment root)."
},
"schema": {
"type": "string",
"description": "Schema ID this document conforms to."
},
"issuerId": {
"type": "string",
"description": "Issuer DID/identifier."
},
"subjectId": {
"type": "string",
"description": "Subject DID/identifier."
},
"chainId": {
"type": "number",
"description": "EVM chain ID, if anchored on-chain."
},
"attributes": {
"type": "object",
"additionalProperties": {},
"description": "Attribute key/value pairs as defined by the schema."
},
"isVerified": {
"type": "boolean",
"description": "MCP-layer flag — true when proof.status is 'verified' or 'onchain-verified'. Prefer this over raw status for boolean checks."
},
"proof": {
"type": "object",
"properties": {
"status": {
"type": "string"
},
"circuitId": {
"type": "string"
},
"chainId": {
"type": "number"
}
},
"additionalProperties": false,
"description": "Proof envelope (status, circuit, chain)."
},
"disclosure": {
"description": "Selective-disclosure payload, if present."
}
},
"required": [
"docHash",
"schema",
"issuerId",
"subjectId",
"attributes",
"isVerified"
],
"additionalProperties": false
},
"description": "Result set; each item has been MCP-enriched with `isVerified`."
},
"hasMore": {
"type": "boolean",
"description": "True when more results exist beyond this page; pair with `offset` to walk pages."
}
},
"required": [
"results",
"hasMore"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢lemma_get_schema(id)
Retrieve a Lemma schema by its ID via GET /v1/schemas/{id}. A schema declares how documents of a given type are interpreted and normalized. Returns SchemaMeta { id, description? } with additionalProperties open — implementations commonly include a `normalize` artifact (WASM that maps raw documents to canonical form) and its content hash. Use this when you need to interpret attribute keys returned by lemma_query_verified_attributes.
Eingabe-Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Schema ID. Returned in the `schema` field of VerifiedAttributesQueryResponseItem from lemma_query_verified_attributes, or registered via POST /v1/schemas."
}
},
"required": [
"id"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Ausgabe-Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Schema ID, echoing the request."
},
"description": {
"type": "string",
"description": "Human-readable description of the schema."
},
"normalize": {
"type": "object",
"properties": {
"artifact": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"ipfs",
"https"
],
"description": "URI scheme for fetching the WASM artifact."
},
"wasm": {
"type": "string",
"description": "URL or CID of the WASM module."
},
"js": {
"type": "string",
"description": "URL or CID of the wasm-bindgen JS shim required for instantiation."
}
},
"required": [
"type",
"wasm",
"js"
],
"additionalProperties": false
},
"hash": {
"type": "string",
"description": "Content hash of the WASM module (verifies integrity)."
},
"abi": {
"type": "object",
"properties": {
"raw": {
"type": "object",
"additionalProperties": {
"type": "string"
}
},
"norm": {
"type": "object",
"additionalProperties": {
"type": "string"
}
}
},
"required": [
"raw",
"norm"
],
"additionalProperties": false,
"description": "Optional ABI mapping between raw input keys and normalized attribute names."
}
},
"required": [
"artifact",
"hash"
],
"additionalProperties": false,
"description": "Normalize artifact — WASM that maps raw documents to canonical form."
}
},
"required": [
"id",
"normalize"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢lemma_get_circuit(circuitId)
Retrieve a zero-knowledge proof circuit by its circuitId via GET /v1/circuits/{circuitId}. A circuit defines the constraints that proofs must satisfy and binds to a single schema. Returns CircuitMeta { circuitId, schema, description?, inputs?, verifier?: { type: 'onchain'|'offchain', address?, chainId? }, artifact?: { location: { type: 'ipfs'|'https', wasm, zkey } } }. Use this before lemma_submit_proof to confirm the circuit's schema, public inputs, and verifier configuration. Circuits are immutable; new variants get new circuitIds.
Eingabe-Schema
{
"type": "object",
"properties": {
"circuitId": {
"type": "string",
"description": "Circuit ID. Returned in the `proof.circuitId` field of VerifiedAttributesQueryResponseItem from lemma_query_verified_attributes, or registered via POST /v1/circuits. NOTE: this matches the OpenAPI field name `circuitId`, not a generic `id`."
}
},
"required": [
"circuitId"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Ausgabe-Schema
{
"type": "object",
"properties": {
"circuitId": {
"type": "string",
"description": "Circuit ID, echoing the request."
},
"schema": {
"type": "string",
"description": "Schema ID this circuit is bound to."
},
"description": {
"type": "string"
},
"inputs": {
"type": "array",
"items": {
"type": "string"
},
"description": "Ordered names of the circuit's public/private inputs."
},
"verifiers": {
"type": "array",
"items": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"onchain",
"offchain"
],
"description": "Verifier location."
},
"address": {
"type": "string",
"description": "Verifier contract address (onchain only)."
},
"chainId": {
"type": "number",
"description": "EVM chain ID (onchain only)."
},
"alg": {
"type": "string",
"description": "Proof algorithm identifier (e.g. 'groth16-bn254-snarkjs')."
}
},
"required": [
"type"
],
"additionalProperties": false
},
"description": "Available verifier configurations for this circuit."
},
"artifact": {
"type": "object",
"properties": {
"location": {
"type": "object",
"properties": {
"type": {
"type": "string",
"enum": [
"ipfs",
"https"
]
},
"wasm": {
"type": "string",
"description": "Circuit WASM artifact URL/CID."
},
"zkey": {
"type": "string",
"description": "Circuit proving key URL/CID."
}
},
"required": [
"type",
"wasm",
"zkey"
],
"additionalProperties": false
}
},
"required": [
"location"
],
"additionalProperties": false,
"description": "Circuit artifact location (WASM + zkey)."
}
},
"required": [
"circuitId",
"schema"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢lemma_get_generator(generatorId)
Retrieve a Lemma document generator by generatorId via GET /v1/doc-generators/{generatorId}. A generator describes how a class of source documents is produced (e.g., what fields a 'KYC-v2' issuer must populate). Returns GeneratorMeta { generatorId, schema, description?, language?, source?: { type: 'url', uri }, inputsSpec?, outputsSpec? }. Each generator is bound to one schema. Use this when onboarding a new issuer or auditing how an existing schema is being populated.
Eingabe-Schema
{
"type": "object",
"properties": {
"generatorId": {
"type": "string",
"description": "Generator ID. Each generator is bound to a single schema and describes how source documents are produced. Registered via POST /v1/doc-generators. NOTE: this matches the OpenAPI field name `generatorId`, not a generic `id`."
}
},
"required": [
"generatorId"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Ausgabe-Schema
{
"type": "object",
"properties": {
"generatorId": {
"type": "string",
"description": "Generator ID, echoing the request."
},
"schema": {
"type": "string",
"description": "Schema ID this generator is bound to (1:1 binding)."
},
"description": {
"type": "string"
},
"language": {
"type": "string",
"description": "Implementation language (e.g. 'rust', 'typescript')."
},
"source": {
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "url"
},
"uri": {
"type": "string",
"description": "Source URL (git, IPFS, etc.)."
}
},
"required": [
"type",
"uri"
],
"additionalProperties": false,
"description": "Reference to the generator's source code."
},
"inputsSpec": {
"type": "object",
"additionalProperties": {},
"description": "Specification of fields the issuer must populate."
},
"outputsSpec": {
"type": "object",
"additionalProperties": {},
"description": "Specification of fields the generator produces."
}
},
"required": [
"generatorId",
"schema"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢lemma_get_proof_status(verificationId)
Get the verification status of a proof. NOTE: the v2 API does not yet expose a dedicated GET /v1/proofs/{id} endpoint, so this tool internally calls POST /v1/verified-attributes/query filtered by docHash (treating the verificationId returned from lemma_submit_proof as a docHash filter). Returns { status, circuitId, chainId, docHash } extracted from the matched item, or undefined if the verificationId is unknown. Status enum: received | verified | onchain-verified | rejected. Use the SDK's isVerified() helper (or check status === 'verified' || status === 'onchain-verified') to determine cryptographic validity.
Eingabe-Schema
{
"type": "object",
"properties": {
"verificationId": {
"type": "string",
"description": "verificationId returned by lemma_submit_proof. Internally treated as a docHash filter on POST /v1/verified-attributes/query (no dedicated GET /v1/proofs/{id} endpoint in v2 API)."
}
},
"required": [
"verificationId"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Ausgabe-Schema
{
"type": "object",
"properties": {
"status": {
"type": "string",
"description": "Verification status enum: 'received' | 'verified' | 'onchain-verified' | 'rejected'. Use the SDK's isVerified() helper (or check status === 'verified' || status === 'onchain-verified') for cryptographic validity."
},
"circuitId": {
"type": "string",
"description": "Circuit ID this proof was generated against."
},
"chainId": {
"type": "number",
"description": "EVM chain ID where the proof was verified, if applicable."
},
"docHash": {
"type": "string",
"description": "Document hash this proof attests to."
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Nachweis