HiveAttest
Pre-action attestation perimeter for AI agents — 8 primitives, signed C18 receipt per call.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"hive-mcp-attest": {
"url": "https://hive-mcp-attest.onrender.com/mcp"
}
}
}Puntos de conexión remotos
https://hive-mcp-attest.onrender.com/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (18)
⚪attest_passport_issue(action_id, agent_did, intended_op, target_resource, inputs, ...)
Issue a Pre-Action Attestation Manifest (C15: hive-passport). Signs with Ed25519 over RFC 8785 JCS-canonical body. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"action_id": {
"type": "string",
"description": "Caller-supplied action correlation ID"
},
"agent_did": {
"type": "string",
"description": "DID of the attesting agent"
},
"intended_op": {
"type": "string",
"description": "Operation name, e.g. \"tool_invocation\""
},
"target_resource": {
"type": "string",
"description": "URI or identifier of the target resource"
},
"inputs": {
"type": "object",
"description": "Declared inputs (will be hashed)",
"default": {}
},
"ttl_seconds": {
"type": "integer",
"description": "Validity window in seconds (default 300)",
"default": 300
}
},
"required": [
"action_id",
"agent_did",
"intended_op",
"target_resource"
]
}⚪attest_passport_verify(manifest, observed_inputs)
Verify a Pre-Action Attestation Manifest (C15: hive-passport). Checks Ed25519 signature, temporal validity, and optionally observed inputs hash. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"manifest": {
"type": "object",
"description": "Full passport manifest object (from attest_passport_issue)"
},
"observed_inputs": {
"type": "object",
"description": "Optional observed inputs to check against declared hash"
}
},
"required": [
"manifest"
]
}⚪attest_custody_append(chain_id, transform_id, agent_did, payload, taint_status)
Append a node to a custody chain (C16: hive-custody). Taint propagates: once tainted, always tainted. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"chain_id": {
"type": "string",
"description": "Chain identifier (create new by using a fresh ID)"
},
"transform_id": {
"type": "string",
"description": "Transform identifier for this step"
},
"agent_did": {
"type": "string",
"description": "DID of the agent performing the transform"
},
"payload": {
"type": "object",
"description": "Transform payload (will be hashed)",
"default": {}
},
"taint_status": {
"type": "string",
"enum": [
"clean",
"tainted",
"unknown"
],
"default": "clean",
"description": "Declared taint status"
}
},
"required": [
"chain_id",
"transform_id",
"agent_did"
]
}⚪attest_custody_verify(nodes)
Verify a custody chain: hash linkage, Ed25519 signatures, and taint propagation (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"nodes": {
"type": "array",
"description": "Ordered array of custody chain node objects (from attest_custody_append responses)"
}
},
"required": [
"nodes"
]
}🟢attest_custody_proof(chain_id, index)
Retrieve a Merkle inclusion proof for a specific node in a custody chain (C16). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"chain_id": {
"type": "string",
"description": "Chain identifier"
},
"index": {
"type": "integer",
"description": "0-based node index"
}
},
"required": [
"chain_id",
"index"
]
}⚪attest_cargo_register(id, name, version, sensitivity, schema, ...)
Register a versioned cargo type in the HiveAttest registry (C17: hive-cargo-taxonomy). Pins a definition hash for version-anchoring. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Unique cargo type ID, e.g. \"pii\""
},
"name": {
"type": "string",
"description": "Human-readable cargo type name"
},
"version": {
"type": "string",
"description": "Semver version string, e.g. \"1.0.0\""
},
"sensitivity": {
"type": "string",
"enum": [
"public",
"internal",
"confidential",
"restricted",
"critical"
]
},
"schema": {
"type": "object",
"description": "JSON Schema defining the payload shape"
},
"supersedes": {
"type": "object",
"description": "Optional {id, version} of superseded type"
}
},
"required": [
"id",
"name",
"version",
"sensitivity",
"schema"
]
}⚪attest_cargo_validate(cargo_type_id, version, payload)
Validate a payload against a registered cargo type schema (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"cargo_type_id": {
"type": "string",
"description": "Registered cargo type ID"
},
"version": {
"type": "string",
"description": "Cargo type version"
},
"payload": {
"type": "object",
"description": "Payload to validate against the schema"
}
},
"required": [
"cargo_type_id",
"version",
"payload"
]
}🟢attest_cargo_snapshot
Get a registry snapshot with Merkle root for version pinning (C17). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {}
}⚪attest_warranty_issue(agent_did, action_id, claim, scope, expires_at)
Issue an attestation warranty committing an agent to a claim (C18: hive-attestation-warranty). Signed with Ed25519. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"agent_did": {
"type": "string",
"description": "DID of the warranting agent"
},
"action_id": {
"type": "string",
"description": "Action correlation ID being warranted"
},
"claim": {
"type": "string",
"description": "Human-readable warranty claim"
},
"scope": {
"type": "object",
"description": "Scope constraints",
"default": {}
},
"expires_at": {
"type": "string",
"description": "ISO-8601 expiry UTC (optional)"
}
},
"required": [
"agent_did",
"action_id",
"claim"
]
}⚪attest_warranty_breach(warranty_id, breach_description, evidence)
Report a warranty breach. Marks the warranty as breached and returns a signed breach record (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"warranty_id": {
"type": "string",
"description": "Warranty ID to report breach on"
},
"breach_description": {
"type": "string",
"description": "Description of the breach"
},
"evidence": {
"type": "object",
"description": "Optional evidence dict"
}
},
"required": [
"warranty_id",
"breach_description"
]
}🟢attest_warranty_get(warranty_id)
Retrieve a warranty by ID (C18). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"warranty_id": {
"type": "string",
"description": "Warranty ID"
}
},
"required": [
"warranty_id"
]
}⚪attest_gate_evaluate(passport_manifest, cargo_manifest, custody_root, warranty_ids, context)
THE HEADLINE TOOL. Evaluate whether an agent may proceed through the HiveAttest gate (C19: hive-gate-enforcer). Verifies passport signature + expiry, cargo registry membership, and warranty status. Every response (allow OR deny) includes a signed C18-format receipt of the gate decision. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"passport_manifest": {
"type": "object",
"description": "C15 passport manifest from attest_passport_issue"
},
"cargo_manifest": {
"type": "object",
"description": "C17 cargo manifest (optional)"
},
"custody_root": {
"type": "string",
"description": "Expected custody chain Merkle root (optional)"
},
"warranty_ids": {
"type": "array",
"items": {
"type": "string"
},
"description": "Active warranty IDs to verify",
"default": []
},
"context": {
"type": "object",
"description": "Additional gate evaluation context",
"default": {}
}
},
"required": [
"passport_manifest"
]
}🟢attest_inspect_sample(sample_id, records, sample_rate, seed)
Probabilistic secondary inspection of a record batch (C20: hive-secondary-inspection). Returns a signed inspection record. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"sample_id": {
"type": "string",
"description": "Identifier for the sample batch"
},
"records": {
"type": "array",
"description": "Records to probabilistically inspect"
},
"sample_rate": {
"type": "number",
"minimum": 0,
"maximum": 1,
"default": 0.1,
"description": "Fraction to inspect (0.0 to 1.0)"
},
"seed": {
"type": "integer",
"description": "Optional RNG seed for reproducibility"
}
},
"required": [
"sample_id",
"records"
]
}⚪attest_smsh_verify(receipt, pubkey_b64url, max_age_seconds)
Verify a SMSH-Stamp v1 receipt (C8/C12: smsh-stamp-verifier). Validates schema, version, algorithm, timestamp, and Ed25519 signature. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"receipt": {
"type": "object",
"description": "SMSH-Stamp v1 receipt object"
},
"pubkey_b64url": {
"type": "string",
"description": "Override trust anchor Ed25519 public key (base64url, 32 bytes)"
},
"max_age_seconds": {
"type": "integer",
"description": "Reject receipts older than this many seconds"
}
},
"required": [
"receipt"
]
}⚪attest_absence_build(window_id, events)
Build a sorted Merkle tree for an audit window (enables cryptographic non-membership proofs, C13: prov-absence). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"window_id": {
"type": "string",
"description": "Audit window identifier"
},
"events": {
"type": "array",
"description": "Observed events to commit to the sorted Merkle tree"
}
},
"required": [
"window_id",
"events"
]
}🟢attest_absence_prove(window_id, query)
Prove that a query event is NOT a member of a previously-built audit window (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"window_id": {
"type": "string",
"description": "Audit window identifier (must have been built)"
},
"query": {
"type": "object",
"description": "Event to prove absent"
}
},
"required": [
"window_id",
"query"
]
}⚪attest_absence_verify(proof, root_hex)
Verify a non-membership proof against an expected Merkle root (C13). Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {
"proof": {
"type": "object",
"description": "Non-membership proof from attest_absence_prove"
},
"root_hex": {
"type": "string",
"description": "Expected Merkle root (hex)"
}
},
"required": [
"proof",
"root_hex"
]
}⚪attest_meta
Return HiveAttest layer/spec/patent metadata for all claims. Useful for agent introspection. Reference-grade implementation. Wire format normative; production-grade is Layer B.
Esquema de entrada
{
"type": "object",
"properties": {}
}Comunidad
Evidencia