Skip to main content

iqa-mcp

The IQA attestation primitives — derived intent addressing and AE-128 envelope verification — exposed as Model Context Protocol tools, so any MCP agent (Claude Desktop, Cline, your own client, an Uber-style MCP Gateway) can verify trust offline, fail-closed.

A thin, stateless wrapper around the published iqa-org 1.3.1 reference implementation. No network. No accounts. No key storage. No state.

Tools

Tool Input Returns Key needed
derive_route_shard authority string SHA-256(authority)[0:16] hex — the derived, action-independent intent address no
parse_envelope AE-128 frame hex structural decode: version, lease, shard, organ, nonce, standing — fails closed on every layout rule no
verify_envelope frame hex + organ key full verification: constant-time HMAC-SHA256 over the whole 128-byte frame (attestation zeroed) + lease check. REJECT is a result, not an error yes (caller-supplied)
published_vector — the published AE128-VECTOR-1 (authority, test key, frame hex) for byte-for-byte self-test —

Run

pip install "iqa-org>=1.3.1" "mcp>=2"
python server.py            # stdio transport

MCP client configuration (Claude Desktop / Cline style):

{
  "mcpServers": {
    "iqa": {
      "command": "python",
      "args": ["/path/to/server.py"]
    }
  }
}

Self-test

python test_mcp.py
# [PASS] 1 · list_tools        -> 4 tools
# [PASS] 2 · derive_route_shard -> 5c378581f92754d0bc88adaed84b7c5a
# [PASS] 3 · published_vector   -> f3b2a1c4.pillar.example
# [PASS] 4 · parse_envelope     -> standing radiant
# [PASS] 5 · verify_envelope    -> [PASS] radiant · nonce 1
# [PASS] 6 · tampered frame     -> REJECT (HMAC mismatch)
# [PASS] 7 · malformed hex      -> REJECT
# ALL 7/7 PASS

Test 6 is the point: flip one byte of the standing field and the frame dies — attestation does not verify. Fail-closed, over the wire.

Why

Agent platforms are converging on MCP as the tool-calling layer (Microsoft's agent OS, Google's Antigravity, Uber's MCP Gateway with 800+ servers and 5000+ tools). The missing layer is trust semantics: what intent is being addressed and whether the counterparty has standing — verifiable without a network call. These four tools make that layer native to any MCP agent.

Design invariants, inherited from the schemes:

  • Zero-parser: fixed offsets, no TLV, no heap-shaped parsing.
  • Fail-closed: malformed input is a REJECT result, never a normalised partial answer.
  • Offline: verification needs the frame, the key, and a hash function. Nothing else.
  • Stateless: the server stores nothing; the organ key is passed per call by the client and never persisted.

Status

Working implementation, protocol-tested (stdio, MCP 2.x SDK). Not yet published to PyPI as its own distribution — packaging/registry placement is a pending decision. The underlying schemes are iqa-org 1.3.1 (four registries) with the merged Internet-Draft draft-li-rttp-iqa-addressing-00 in Independent Submission review.

Public record

Everything this tool wraps is public and checkable — no asking us:

Metadata

Release files for iqa-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iqa-mcp 0.1.0
File Size Uploaded
iqa_mcp-0.1.0.tar.gz 8.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iqa-mcp 0.1.0
File Interpreter ABI Platform
iqa_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 18.3 kB

Release files / iqa_mcp-0.1.0.tar.gz

Download URL iqa_mcp-0.1.0.tar.gz
Size 8.8 kB
Tags Source
SHA-256 checksum
How to use checksums
491f37421cdaa12f6b5e31734fad1c8e3b196c3ecf9c068fce7dd213cd5f30c8
BLAKE2b-256 checksum
How to use checksums
dce8e78d40fbbfeabe0e8b20610d73f3f1daa7b1818631fbfea8ff8bffa7353b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.2

Release files / iqa_mcp-0.1.0-py3-none-any.whl

Download URL iqa_mcp-0.1.0-py3-none-any.whl
Size 9.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
704cbd9f4643a70a468eabe4aeca0c2988fe66fb09a6ce4ceabf4541b95498d8
BLAKE2b-256 checksum
How to use checksums
c2c2ad1f29e0218d248742b0d77d94aab378cb062da8b3e7e3a937296a796f8b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.2

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page