Skip to main content

Trust Gate MCP

Post-quantum, tamper-evident receipts for consequential agent actions, as an MCP server.

Seven tools, one shared signing primitive: the open-source OpenAgentOntology mint_receipt.

What actually gets signed depends on what you install -- OAO detects its backend at import time, so this is worth stating plainly rather than advertising the best case:

Install Legs Notes
pip install trust-gate-mcp Ed25519 + ML-DSA-65 (FIPS 204) Default. Pure Python (dilithium-py), no native toolchain. Satisfies PQ-required mode.
pip install "trust-gate-mcp[slh]" Ed25519 + ML-DSA-65 + SLH-DSA (FIPS 205) Adds the hash-based diversity leg via liboqs, which survives a lattice break. Native dependency.

PQ-required verify (the default) demands at least one verified post-quantum leg, so the dual-leg default is a real post-quantum posture, not a downgrade -- but only the [slh] install gives you the hash-based third leg.

Tool What it does
mint_receipt_for_record_change Mints a post-quantum receipt for a CRM record change. Works with any CRM (open-core Relaticle, hosted CRMs via their own MCP, custom). Old/new values are SHA-256 hashes.
audit_my_agent_inventory Ranks a CALLER-PROVIDED list of MCP tools by worst-regret if they act. Read-only. Cannot auto-discover other servers -- MCP protocol does not allow that.
mint_action_receipt Post-quantum receipt for any consequential agent action.
verify_receipt Verify a receipt from the certificate alone -- offline, no DB. Defaults to PQ-required mode.
gate_decision Two-phase decision gate. PREVIEW returns risk assessment + preview_id without acting. COMMIT verifies inputs match and mints a tamper-evident receipt with execution permit.
check_egress Egress classification. Scans data for sensitivity markers and classifies as PUBLIC / INTERNAL / CONFIDENTIAL / RESTRICTED. Blocks RESTRICTED. Returns classification + retention info + receipt.
run_exit_drill Vendor exit readiness drill. Checks local signing key, local model access (Ollama), and local data export. Returns step-by-step results + receipt. Informational, no side effects.

Quantum Hardening (pol.must_do.150 reference implementation)

  • H1 key persistence + bootstrap with FAIL-CLOSED kid-drift check
  • H2 per-IP token-bucket rate limit (DoS-hardened: FIFO eviction + body cap)
  • H3 PQ-required verify (defeats signature-stripping downgrade attacks)
  • H4 128-bit kid on every minted receipt (offline same-notary check)
  • Optional bearer-auth toggle + narrowed CORS via TRUST_GATE_BEARER_TOKEN + TRUST_GATE_ALLOWED_ORIGINS
  • 33/33 tests including adversarial PQ-strip + IP-rotation attack simulations

See PUBLISH.md for the full hardening status table.

Install (stdio)

pip install trust-gate-mcp
trust-gate-mcp

Add [slh] for the hash-based third leg. From a checkout, pip install -e ".[dev]" then python -m trust_gate_mcp.

Container deploy (Smithery / any container host)

docker build -t trust-gate-mcp .
docker run -p 8081:8081 -v trust-gate-data:/data/oao trust-gate-mcp

The volume mount on /data/oao is required for production -- without it the signing key rotates per restart and breaks long-running verification chains. The persistent key_metadata.json holds the notary's kid; the bootstrap step refuses to start if it drifts.

License

Apache-2.0. Built on the open-source OpenAgentOntology primitive.

Release files for trust-gate-mcp 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for trust-gate-mcp 0.2.1
File Size Uploaded
trust_gate_mcp-0.2.1.tar.gz 52.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for trust-gate-mcp 0.2.1
File Interpreter ABI Platform
trust_gate_mcp-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 85.3 kB

Release files / trust_gate_mcp-0.2.1.tar.gz

Download URL trust_gate_mcp-0.2.1.tar.gz
Size 52.4 kB
Tags Source
SHA-256 checksum
How to use checksums
8fc2ff32cc0fb5f12f55f53282abaf4b4a4ec4e46a2a091315cf8dff5aa29fb4
BLAKE2b-256 checksum
How to use checksums
8c631cbfb4983bfbce16ffcaac92d59f50fef9623c056e5ae9c2f252a9ce361a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 29, 2026.

Transparency log

Release files / trust_gate_mcp-0.2.1-py3-none-any.whl

Download URL trust_gate_mcp-0.2.1-py3-none-any.whl
Size 32.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ff8601a674c1068031c1caa2f5a405abbc0b7725c62a90273301352f457c1d7d
BLAKE2b-256 checksum
How to use checksums
e5e563ea66ba54df047dfcd1c71a163e93933f5f1cd89f2245310f737e4ea742
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page