ScopeProof
Machine-verifiable authorization checks for autonomous AI agents.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"scopeproof": {
"url": "https://scopeproof.davisvillelabs.com/mcp"
}
}
}遠端端點
https://scopeproof.davisvillelabs.com/mcpstreamable-http它能做什麼
工具清單
工具(3)
🟢preflight(authority, action, context)
Validate whether a structured authority envelope contains enough explicit constraints for ScopeProof to evaluate one action. Free. Returns no substantive authorization verdict and accepts no credentials, raw prompts, arbitrary request bodies, or secrets.
輸入結構描述
{
"type": "object",
"properties": {
"authority": {
"type": "object",
"required": [
"allowedActions",
"allowedResources"
],
"additionalProperties": false,
"properties": {
"schemaVersion": {
"type": "string",
"maxLength": 64
},
"principal": {
"type": "string",
"maxLength": 160
},
"issuedAt": {
"type": "string",
"format": "date-time"
},
"notBefore": {
"type": "string",
"format": "date-time"
},
"expiresAt": {
"type": "string",
"format": "date-time"
},
"allowedActions": {
"type": "array",
"minItems": 1,
"maxItems": 64,
"items": {
"type": "string"
}
},
"deniedActions": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"allowedResources": {
"type": "array",
"minItems": 1,
"maxItems": 64,
"items": {
"type": "string"
}
},
"deniedResources": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"methods": {
"type": "array",
"maxItems": 24,
"items": {
"type": "string"
}
},
"tools": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"environments": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
},
"dataClasses": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
},
"maxSpend": {
"type": "object",
"required": [
"amountMinor",
"currency"
],
"additionalProperties": false,
"properties": {
"amountMinor": {
"type": "integer",
"minimum": 0
},
"currency": {
"type": "string",
"pattern": "^[A-Z]{3}$"
}
}
},
"allowDestructive": {
"type": "boolean"
},
"allowIrreversible": {
"type": "boolean"
},
"approvalRequiredFor": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
}
}
},
"action": {
"type": "object",
"required": [
"type",
"resource"
],
"additionalProperties": false,
"properties": {
"type": {
"type": "string",
"maxLength": 64
},
"resource": {
"type": "string",
"maxLength": 1024
},
"method": {
"type": "string",
"maxLength": 12
},
"tool": {
"type": "string",
"maxLength": 200
},
"environment": {
"type": "string",
"maxLength": 80
},
"dataClass": {
"type": "string",
"maxLength": 80
},
"amount": {
"type": "object",
"required": [
"amountMinor",
"currency"
],
"additionalProperties": false,
"properties": {
"amountMinor": {
"type": "integer",
"minimum": 0
},
"currency": {
"type": "string",
"pattern": "^[A-Z]{3}$"
}
}
},
"destructive": {
"type": "boolean",
"description": "Set true when the proposed action is destructive even if its action type or HTTP method is not intrinsically classified as destructive."
},
"irreversible": {
"type": "boolean"
}
}
},
"context": {
"type": "object",
"additionalProperties": false,
"properties": {
"humanApprovalPresent": {
"type": "boolean",
"description": "Caller assertion that required human approval has already occurred. ScopeProof records this as caller-asserted and does not independently verify the human identity or approval event."
}
}
}
},
"required": [
"authority",
"action"
],
"additionalProperties": false
}🟢check_action(authority, action, context)
Determine whether one proposed action is within explicitly supplied authority. $0.01 stablecoin machine payment. Returns within_scope, outside_scope, or review_required plus deterministic reason codes, policy/action digests, and a tamper-evident receipt. This is scope enforcement against supplied authority, not identity verification, legal authorization, or a safety guarantee.
輸入結構描述
{
"type": "object",
"properties": {
"authority": {
"type": "object",
"required": [
"allowedActions",
"allowedResources"
],
"additionalProperties": false,
"properties": {
"schemaVersion": {
"type": "string",
"maxLength": 64
},
"principal": {
"type": "string",
"maxLength": 160
},
"issuedAt": {
"type": "string",
"format": "date-time"
},
"notBefore": {
"type": "string",
"format": "date-time"
},
"expiresAt": {
"type": "string",
"format": "date-time"
},
"allowedActions": {
"type": "array",
"minItems": 1,
"maxItems": 64,
"items": {
"type": "string"
}
},
"deniedActions": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"allowedResources": {
"type": "array",
"minItems": 1,
"maxItems": 64,
"items": {
"type": "string"
}
},
"deniedResources": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"methods": {
"type": "array",
"maxItems": 24,
"items": {
"type": "string"
}
},
"tools": {
"type": "array",
"maxItems": 64,
"items": {
"type": "string"
}
},
"environments": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
},
"dataClasses": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
},
"maxSpend": {
"type": "object",
"required": [
"amountMinor",
"currency"
],
"additionalProperties": false,
"properties": {
"amountMinor": {
"type": "integer",
"minimum": 0
},
"currency": {
"type": "string",
"pattern": "^[A-Z]{3}$"
}
}
},
"allowDestructive": {
"type": "boolean"
},
"allowIrreversible": {
"type": "boolean"
},
"approvalRequiredFor": {
"type": "array",
"maxItems": 32,
"items": {
"type": "string"
}
}
}
},
"action": {
"type": "object",
"required": [
"type",
"resource"
],
"additionalProperties": false,
"properties": {
"type": {
"type": "string",
"maxLength": 64
},
"resource": {
"type": "string",
"maxLength": 1024
},
"method": {
"type": "string",
"maxLength": 12
},
"tool": {
"type": "string",
"maxLength": 200
},
"environment": {
"type": "string",
"maxLength": 80
},
"dataClass": {
"type": "string",
"maxLength": 80
},
"amount": {
"type": "object",
"required": [
"amountMinor",
"currency"
],
"additionalProperties": false,
"properties": {
"amountMinor": {
"type": "integer",
"minimum": 0
},
"currency": {
"type": "string",
"pattern": "^[A-Z]{3}$"
}
}
},
"destructive": {
"type": "boolean",
"description": "Set true when the proposed action is destructive even if its action type or HTTP method is not intrinsically classified as destructive."
},
"irreversible": {
"type": "boolean"
}
}
},
"context": {
"type": "object",
"additionalProperties": false,
"properties": {
"humanApprovalPresent": {
"type": "boolean",
"description": "Caller assertion that required human approval has already occurred. ScopeProof records this as caller-asserted and does not independently verify the human identity or approval event."
}
}
}
},
"required": [
"authority",
"action"
],
"additionalProperties": false
}🟢verify_receipt(receipt)
Verify the cryptographic integrity of one ScopeProof receipt without exposing the server signing key. Free and repeatable.
輸入結構描述
{
"type": "object",
"properties": {
"receipt": {
"type": "object"
}
},
"required": [
"receipt"
],
"additionalProperties": false
}社群
證據