iqa-mcp
The IQA attestation primitives — derived intent addressing and AE-128 envelope verification — exposed as Model Context Protocol tools, so any MCP agent (Claude Desktop, Cline, your own client, an Uber-style MCP Gateway) can verify trust offline, fail-closed.
A thin, stateless wrapper around the published
iqa-org 1.3.1 reference
implementation. No network. No accounts. No key storage. No state.
Tools
| Tool | Input | Returns | Key needed |
|---|---|---|---|
derive_route_shard |
authority string | SHA-256(authority)[0:16] hex — the derived, action-independent intent address |
no |
parse_envelope |
AE-128 frame hex | structural decode: version, lease, shard, organ, nonce, standing — fails closed on every layout rule | no |
verify_envelope |
frame hex + organ key | full verification: constant-time HMAC-SHA256 over the whole 128-byte frame (attestation zeroed) + lease check. REJECT is a result, not an error | yes (caller-supplied) |
published_vector |
— | the published AE128-VECTOR-1 (authority, test key, frame hex) for byte-for-byte self-test | — |
Run
pip install "iqa-org>=1.3.1" "mcp>=2"
python server.py # stdio transport
MCP client configuration (Claude Desktop / Cline style):
{
"mcpServers": {
"iqa": {
"command": "python",
"args": ["/path/to/server.py"]
}
}
}
Self-test
python test_mcp.py
# [PASS] 1 · list_tools -> 4 tools
# [PASS] 2 · derive_route_shard -> 5c378581f92754d0bc88adaed84b7c5a
# [PASS] 3 · published_vector -> f3b2a1c4.pillar.example
# [PASS] 4 · parse_envelope -> standing radiant
# [PASS] 5 · verify_envelope -> [PASS] radiant · nonce 1
# [PASS] 6 · tampered frame -> REJECT (HMAC mismatch)
# [PASS] 7 · malformed hex -> REJECT
# ALL 7/7 PASS
Test 6 is the point: flip one byte of the standing field and the frame dies — attestation does not verify. Fail-closed, over the wire.
Why
Agent platforms are converging on MCP as the tool-calling layer (Microsoft's agent OS, Google's Antigravity, Uber's MCP Gateway with 800+ servers and 5000+ tools). The missing layer is trust semantics: what intent is being addressed and whether the counterparty has standing — verifiable without a network call. These four tools make that layer native to any MCP agent.
Design invariants, inherited from the schemes:
- Zero-parser: fixed offsets, no TLV, no heap-shaped parsing.
- Fail-closed: malformed input is a REJECT result, never a normalised partial answer.
- Offline: verification needs the frame, the key, and a hash function. Nothing else.
- Stateless: the server stores nothing; the organ key is passed per call by the client and never persisted.
Status
Working implementation, protocol-tested (stdio, MCP 2.x SDK). Not yet
published to PyPI as its own distribution — packaging/registry
placement is a pending decision. The underlying schemes are
iqa-org 1.3.1 (four registries) with the merged Internet-Draft
draft-li-rttp-iqa-addressing-00 in Independent Submission review.
Public record
Everything this tool wraps is public and checkable — no asking us:
- Public record, dated: https://iqa.org/brief/
- Live demos — the audit chain this tool joins: https://iqa.org/demo/compare/ · https://iqa.org/demo/delegation/
- Whitepaper: https://iqa.org/whitepaper/ (also at rttp.com/whitepaper)
- Internet-Draft: draft-li-rttp-iqa-addressing — Independent Submission, in review
- The library this server wraps: iqa-org 1.3.1 on PyPI — four registries, byte-exact vectors, offline self-test
Metadata
Release files for iqa-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iqa_mcp-0.1.0.tar.gz | 8.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iqa_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.3 kB
Release files / iqa_mcp-0.1.0.tar.gz
| Download URL | iqa_mcp-0.1.0.tar.gz |
|---|---|
| Size | 8.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
491f37421cdaa12f6b5e31734fad1c8e3b196c3ecf9c068fce7dd213cd5f30c8
|
|
BLAKE2b-256 checksum How to use checksums |
dce8e78d40fbbfeabe0e8b20610d73f3f1daa7b1818631fbfea8ff8bffa7353b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.2
|
Release files / iqa_mcp-0.1.0-py3-none-any.whl
| Download URL | iqa_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 9.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
704cbd9f4643a70a468eabe4aeca0c2988fe66fb09a6ce4ceabf4541b95498d8
|
|
BLAKE2b-256 checksum How to use checksums |
c2c2ad1f29e0218d248742b0d77d94aab378cb062da8b3e7e3a937296a796f8b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.2
|