Skip to main content

aat-mcp

Signed, tamper-evident audit trail for MCP tool calls, conformant to draft-sharif-agent-audit-trail-06. Every agent tool invocation becomes a signed, hash-chained record that an independent party can verify offline, without trusting the producer.

Containment sandboxes control what an agent may touch. This records who did what, whether it was allowed, and proves it — the governance + evidence layer on top.

What it does (per the spec)

  • 12 mandatory record fields; JCS (RFC 8785) canonicalization.
  • Chain: prev_hash(N) = hex(SHA-256(JCS(record(N-1)))).
  • ES256 signatures (ECDSA P-256 over SHA-256, IEEE-P1363 r‖s, base64url); sig_alg/signer_kid are covered by the signature.
  • Pre-execution recording of enforcement decisions (deny is evidence).
  • Privacy by design: inputs/outputs are digested, never stored raw.

Quickstart

from aat import core
from aat.mcp import MCPRecorder

rec = MCPRecorder(agent_id="urn:agent:bot.example", agent_version="1.0.0",
                  private_key=core.gen_key(), trust_level="L2")
rec.open_session()

# wrap any MCP tool handler; every call is recorded + policy-gated
safe = rec.wrap(handler, policy=lambda name, args: name != "delete_prod_db")
safe("send_payment", {"to": "+100", "amount": 50})

ok, issues = rec.verify()          # chain + every signature

Verify offline (third party, public key only)

from aat import core
ok, issues = core.verify_chain(records, {kid: public_key})

Tests

.venv/bin/python tests/test_aat.py — 23/23 (chain, signatures, tamper on every axis, dropped-record detection, MCP flow, policy-deny, privacy, independent verify).

Apache-2.0. Reference implementation of an open IETF draft.

Metadata

Release files for aat-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aat-mcp 0.1.0
File Size Uploaded
aat_mcp-0.1.0.tar.gz 10.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aat-mcp 0.1.0
File Interpreter ABI Platform
aat_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 19.9 kB

Release files / aat_mcp-0.1.0.tar.gz

Download URL aat_mcp-0.1.0.tar.gz
Size 10.3 kB
Tags Source
SHA-256 checksum
How to use checksums
4a349b15104155ff7ac0cdc49ac5a18172645c74bfa72644fd4247bb5f344ffd
BLAKE2b-256 checksum
How to use checksums
cdaad6367adfd14646b327cde0eb9df3fb27ea9274181d8c76032ef63dbd5e79
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.5

Release files / aat_mcp-0.1.0-py3-none-any.whl

Download URL aat_mcp-0.1.0-py3-none-any.whl
Size 9.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6e38da71accd98317bb3c9ef7da9ae547bd9206d74bf5b7d68d86efde69deb7e
BLAKE2b-256 checksum
How to use checksums
ced62bba03334eff989d729d63872f5c99c1f04bc75f26fa39c468ae319d2097
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.5

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page