{"uid":"cap_fTsSEVndtqLqoxt4_O4J6","slug":"mcp-tool-surface-digest-attestation-aae653a4","name":"MCP Tool Surface Digest & Attestation","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/mcp-digest","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"mcp-digest","evidence":{"tools":{"search":"3ac1…"},"digest_alg":"sha256","tool_count":1,"surface_digest":"9f2b…"}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_lY_Z1SbBHR8jvx2NLupQN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Computes a stable, signed digest over an MCP server's tools/list (tool names, descriptions, and inputSchemas) and returns a cryptographically signed attestation as a baseline for future integrity comparisons.","exampleAgentPrompt":"Take the tools/list from my MCP server and compute a signed digest of the whole tool surface — names, descriptions, and schemas — so I have a pinned attestation I can compare against later if I suspect something changed.","exampleUseCases":[{"title":"Pin MCP server before deployment","prompt":"Before I deploy this MCP server to production, compute a signed attestation of its full tools/list — all the tool names, descriptions, and inputSchemas — so I have a trusted baseline I can verify against later."},{"title":"Detect tool description rug pull","prompt":"I want to make sure nobody has silently rewritten any of my MCP tool descriptions since I last checked. Pin the current tools/list now so I can diff it against the signed digest I stored last week."},{"title":"Compliance audit of agent tool surface","prompt":"For our security audit, I need a cryptographically signed record of exactly what tools our MCP server exposes right now — every tool name, description, and schema — with an ed25519 attestation I can hand to the auditors."}],"resultDescription":"Returns a JSON object containing an ed25519-signed attestation with a verdict ('pass'), the overall surface_digest (sha256 over all tools), per-tool digests keyed by tool name, the tool count, and a key_id identifying the signing key. This signed attestation can be stored as a trusted baseline and compared against future snapshots to detect drift or tampering.","failureModes":["Empty or malformed tools array returns an error or digest with tool_count 0","Missing required 'name' field on any tool item causes a validation error","Network/payment failure (x402 micropayment not completed) blocks the response","Malformed inputSchema objects may be excluded or cause serialization errors","If the signing key is rotated, old attestations will reference a deprecated key_id"],"whenToPreferThis":"Use this endpoint when you need a cryptographically signed, tamper-evident snapshot of an MCP server's tool surface at a point in time — especially before deployment, before and after updates, or when establishing a baseline for ongoing drift detection. Prefer this over the companion drift-detection endpoint when you want to CREATE the baseline rather than compare against one. Choose this over ad-hoc hashing because the ed25519 attestation is independently verifiable and externally signed.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T23:25:27.063Z","isFirstParty":false}