aat-mcp
Signed, tamper-evident audit trail for MCP tool calls, conformant to draft-sharif-agent-audit-trail-06. Every agent tool invocation becomes a signed, hash-chained record that an independent party can verify offline, without trusting the producer.
Containment sandboxes control what an agent may touch. This records who did what, whether it was allowed, and proves it — the governance + evidence layer on top.
What it does (per the spec)
- 12 mandatory record fields; JCS (RFC 8785) canonicalization.
- Chain:
prev_hash(N) = hex(SHA-256(JCS(record(N-1)))). - ES256 signatures (ECDSA P-256 over SHA-256, IEEE-P1363 r‖s, base64url);
sig_alg/signer_kidare covered by the signature. - Pre-execution recording of enforcement decisions (deny is evidence).
- Privacy by design: inputs/outputs are digested, never stored raw.
Quickstart
from aat import core
from aat.mcp import MCPRecorder
rec = MCPRecorder(agent_id="urn:agent:bot.example", agent_version="1.0.0",
private_key=core.gen_key(), trust_level="L2")
rec.open_session()
# wrap any MCP tool handler; every call is recorded + policy-gated
safe = rec.wrap(handler, policy=lambda name, args: name != "delete_prod_db")
safe("send_payment", {"to": "+100", "amount": 50})
ok, issues = rec.verify() # chain + every signature
Verify offline (third party, public key only)
from aat import core
ok, issues = core.verify_chain(records, {kid: public_key})
Tests
.venv/bin/python tests/test_aat.py — 23/23 (chain, signatures, tamper on every
axis, dropped-record detection, MCP flow, policy-deny, privacy, independent verify).
Apache-2.0. Reference implementation of an open IETF draft.
Metadata
Release files for aat-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aat_mcp-0.1.0.tar.gz | 10.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aat_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 19.9 kB
Release files / aat_mcp-0.1.0.tar.gz
| Download URL | aat_mcp-0.1.0.tar.gz |
|---|---|
| Size | 10.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4a349b15104155ff7ac0cdc49ac5a18172645c74bfa72644fd4247bb5f344ffd
|
|
BLAKE2b-256 checksum How to use checksums |
cdaad6367adfd14646b327cde0eb9df3fb27ea9274181d8c76032ef63dbd5e79
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.5
|
Release files / aat_mcp-0.1.0-py3-none-any.whl
| Download URL | aat_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 9.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6e38da71accd98317bb3c9ef7da9ae547bd9206d74bf5b7d68d86efde69deb7e
|
|
BLAKE2b-256 checksum How to use checksums |
ced62bba03334eff989d729d63872f5c99c1f04bc75f26fa39c468ae319d2097
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.5
|