mcp
Issue signed receipts for AI agent actions; verify any receipt offline - free, no account.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"@scytalex-llc/pcrzero-mcp"
]
}
}
}Runnable packages
0.2.0streamable-httpRemote endpoints
https://mcp.pcrzero.com/mcpstreamable-httpWhat it can do
Tool inventory
Tools (3)
⚪issue_receipt(document, documents, policy_id, policy, nonce, ...)
Adjudicates an attestation document against a policy and returns the verdict together with a signed receipt pair — the durable, independently checkable proof that this decision was made, by these keys, over this document. **Metered: every call bills one `receipt_verifications` unit against the API key configured for this server, and a `fail` verdict bills exactly like a `pass`. You are paying for the adjudication, not for the answer you wanted.** This is the only tool here that spends. If you already hold a receipt and want to know whether it is genuine, that is `verify_receipt`, which is free and needs no key.
Input Schema
{
"type": "object",
"properties": {
"document": {
"type": "string",
"description": "Base64 attestation document (single-document form)."
},
"documents": {
"type": "array",
"items": {
"type": "string"
},
"description": "Base64 attestation documents (batch form)."
},
"policy_id": {
"type": "string",
"description": "Stored policy id (pol_…)."
},
"policy": {
"type": "object",
"additionalProperties": {},
"description": "Inline policy object (API wire shape)."
},
"nonce": {
"type": "string"
},
"receipt": {
"type": "boolean",
"description": "Request a signed receipt (default true)."
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪verify_receipt(receipt, keyset, conformance)
Checks a PCRZERO receipt pair against the signing keyset: whether the signature holds, and whether the receipt says what it appears to say. **Free, with no API key and no account, and it stays free.** Offline by default — supply `keyset` and this call touches the network not at all; omit it and the server fetches the public keyset from api.pcrzero.com once. The result field `keyset_source` tells you which of the two happened, every time. This tool issues nothing, bills nothing, and cannot spend. It is the half of PCRZERO you never pay for.
Input Schema
{
"type": "object",
"properties": {
"receipt": {
"type": "string",
"description": "Base64url receipt envelope from issue_receipt / the API."
},
"keyset": {
"type": "object",
"properties": {
"keys": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": {}
}
}
},
"required": [
"keys"
],
"additionalProperties": false,
"description": "Optional keyset in GET /v1/keys shape. When supplied, no network is used."
},
"conformance": {
"type": "string",
"enum": [
"full",
"classical-only"
]
}
},
"required": [
"receipt"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_keyset
Returns the current PCRZERO signing keyset — key ids, public halves, and each key's status. Public and unauthenticated: no API key, no cost, no account. This is the same document an outside party fetches to check a PCRZERO receipt without trusting us, and fetching it is how you stop taking our word for anything.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence