Knox Anchor

Bitcoin-anchored, tamper-evident audit-permanence layer for AI agents, FRE 902(13)/(14)-shaped.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
70%
Naming quality
91%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,068Tokens (tool definitions)
~1013 BTypical response size
Moderate attention impact (0.83% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "knox-anchor": {
      "url": "https://bonissystems.com/api/knox/mcp"
    }
  }
}

Remote endpoints

https://bonissystems.com/api/knox/mcpstreamable-http

What it can do

Tool inventory

Tools (7)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢get_descriptor

Return the Knox MCP server self-description: operator, USPTO patent reference, jurisdiction, available tools, and links to the public AAM (Agent Audit and Management) documentation surface.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢get_chain_health

Return Knox service health: process uptime, database latency, total anchors written, latest anchor timestamp, and the Bitcoin anchor SLA target (OpenTimestamps interval, 1-6 hour confirmation window). Mirrors the public /api/knox/health endpoint under the MCP envelope.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
🟢list_event_types

Return the canonical Knox event-type taxonomy. Each event type is a citation token for federal-grade audit; the registry expands monotonically and is itself anchored on every expansion.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪verify_anchor(hash)

Given a SHA-256 anchor hash (64 hex chars), return the anchor record, chain link validity (predecessor present and matched), event type, sequence number, and verify URL. Public — no authentication required.

Input Schema

{
  "type": "object",
  "properties": {
    "hash": {
      "type": "string",
      "description": "SHA-256 anchor hash (64 lowercase hex chars).",
      "pattern": "^[a-fA-F0-9]{64}$"
    }
  },
  "required": [
    "hash"
  ],
  "additionalProperties": false
}
⚪anchor_event(event_type, payload)

Anchor a generic agent action to the Knox chain. Accepts any event_type from the canonical taxonomy plus a payload object. Returns the anchor sequence, payload hash, predecessor hash, timestamp, and verify URL. Requires a Knox Bearer API key on the Authorization header — unauthenticated calls are rejected. Provision a key by contacting Bonis Systems.

Input Schema

{
  "type": "object",
  "properties": {
    "event_type": {
      "type": "string",
      "description": "Canonical event type (call list_event_types to enumerate). Free-form strings are accepted but not federal-citation-grade."
    },
    "payload": {
      "type": "object",
      "description": "JSON-serializable payload describing the agent action. Hashed verbatim into the chain; do not include secrets — the payload is recoverable on verify."
    }
  },
  "required": [
    "event_type",
    "payload"
  ],
  "additionalProperties": false
}
⚪anchor_mcp_tool_call(server_url, tool_name, arguments_digest, response_digest, agent_identity, ...)

Convenience anchor for the AAM Model Context Protocol theater. Records an `agent_mcp_tool_call` event with structured tool-call metadata (server URL, tool name, argument digest, asserted agent identity, response digest). The record is sealed with a commitment to the authenticated principal that made the assertion, so a reader can tell WHO claimed it. Knox does not authenticate the named agent: this makes an assertion about an agent's actions independently checkable, not the agent itself independently identified.

Input Schema

{
  "type": "object",
  "properties": {
    "server_url": {
      "type": "string",
      "description": "MCP server endpoint the agent invoked."
    },
    "tool_name": {
      "type": "string",
      "description": "Name of the tool invoked."
    },
    "arguments_digest": {
      "type": "string",
      "description": "Caller-computed SHA-256 of the JSON-stringified arguments (64 hex chars).",
      "pattern": "^[a-fA-F0-9]{64}$"
    },
    "response_digest": {
      "type": "string",
      "description": "Caller-computed SHA-256 of the JSON-stringified response (64 hex chars).",
      "pattern": "^[a-fA-F0-9]{64}$"
    },
    "agent_identity": {
      "type": "string",
      "maxLength": 256,
      "description": "Stable identifier the CALLER asserts for the agent (e.g., agent ID, principal, did:knox:agent-X). Recorded as an assertion attributed to your API key, never as an authenticated subject; the anchored payload carries agentIdentityVerified:false and a commitment to the asserting principal."
    },
    "outcome": {
      "type": "string",
      "enum": [
        "success",
        "error",
        "timeout",
        "rejected"
      ],
      "description": "Outcome of the tool call."
    }
  },
  "required": [
    "server_url",
    "tool_name",
    "arguments_digest",
    "agent_identity",
    "outcome"
  ],
  "additionalProperties": false
}
⚪anchor_file_hash(hash, filename, size_bytes, mime_type)

Anchor a SHA-256 file digest to Knox and return an affidavit architected for FRE 902(13)/(14) self-authentication. The file itself is not transmitted — the caller computes the hash and only the digest + filename + size + MIME type are anchored. Admissibility in any matter remains a determination of the presiding court. Requires a Knox Bearer API key on the Authorization header — unauthenticated calls are rejected.

Input Schema

{
  "type": "object",
  "properties": {
    "hash": {
      "type": "string",
      "description": "SHA-256 file digest (64 lowercase hex chars).",
      "pattern": "^[a-fA-F0-9]{64}$"
    },
    "filename": {
      "type": "string",
      "description": "Original filename (max 256 chars)."
    },
    "size_bytes": {
      "type": "integer",
      "minimum": 0,
      "description": "File size in bytes."
    },
    "mime_type": {
      "type": "string",
      "description": "MIME type (max 128 chars)."
    }
  },
  "required": [
    "hash"
  ],
  "additionalProperties": false
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded7 tools
verifiedversion not recorded7 tools