{"uid":"cap_miEEx5AhHd-7LwB8SX5E0","slug":"autobus-mcp-server-attestation-f9b44d86","name":"autobus MCP Server Attestation","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/mcp-server-attest","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"mcp-server-attest","evidence":{"card":{"present":false},"diff":{"added":[],"changed":[],"removed":[],"unchanged":true},"live":{"reachable":true,"tool_count":9,"surface_digest":"ba77…"},"registry":{"name":"io.github.ninefiveonefive/autobus","status":"active","version":"0.2.0"}}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_t7vr1yE4IQiBxWGPd1T9m","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Attests the live tool surface of an MCP server against its registry definition, returning a signed Ed25519 verdict on whether the server matches its published version","exampleAgentPrompt":"Can you attest the live tool surface of the MCP server io.github.ninefiveonefive/autobus at version 0.2.0 and give me a signed verdict on whether it matches its registry definition?","exampleUseCases":[{"title":"Pre-task MCP server integrity check","prompt":"Before I let my agent use the autobus MCP server, attest it — check that io.github.ninefiveonefive/autobus is still running version 0.2.0 with the expected tools and give me a signed pass/fail verdict."},{"title":"Drift detection after deployment","prompt":"I pinned the autobus MCP server last week and got a surface digest of ba77… — can you attest io.github.ninefiveonefive/autobus now and tell me if any tools were added, changed, or removed since then?"},{"title":"Supply chain audit for agent pipeline","prompt":"I need a cryptographically signed attestation that the MCP server io.github.ninefiveonefive/autobus is active, reachable, and matches its published registry entry — I want the Ed25519 signature I can log for compliance."}],"resultDescription":"A signed attestation object containing: an Ed25519 signature (algorithm, base64 value, key_id), and an attestation block with a verdict (pass/fail), the endpoint name, and evidence covering live server reachability and tool count, a surface digest, a registry status and version, a diff report showing added/changed/removed/unchanged tools, and a card presence indicator.","failureModes":["Registry server name not found — returns error if namespace/name does not exist in registry","Server unreachable — live reachability check fails, verdict reflects this in evidence","Version mismatch — requested version differs from active registry version","Tool surface drift detected — diff shows added/changed/removed tools, verdict may fail","Invalid baseline digest format — malformed surface_digest in baseline block causes validation error","Payment not received — x402 payment of $0.03 USDC required; unpaid requests are rejected"],"whenToPreferThis":"Choose this endpoint when you need a cryptographically signed, third-party attestation that an MCP server's live tool surface matches its published registry definition — particularly before trusting an MCP server in an automated pipeline, after a deployment, or for compliance logging. Prefer it over simple reachability pings when you need tamper-evident proof (Ed25519 signature) and a structured diff of tool changes.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:27:55.338Z","isFirstParty":false}