# attest-mcp-remote MCP server

Zero-install remote MCP server for proof-of-existence file attestation.

## Links
- Registry page: https://www.getdrio.com/mcp/io-github-spazio-genesi-attest-mcp-remote
- Repository: https://github.com/SPAZIO-GENESI/attest-mcp-remote
- Website: https://attestazione.spaziogenesi.org

## Install
- Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- Auth: Not captured

## Setup notes
- Remote endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp

## Tools
- service_status - Health of the Spazio Genesi attestation service components: worker (attestation engine), archive (certificate storage), signer (PDF cryptographic signature), anchor (Bitcoin/OpenTimestamps calendars). Values: ok | degraded | down | n/d. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- check_anchor - Check whether a work's SHA-256 fingerprint has an OpenTimestamps proof anchored in Bitcoin. The proof is created at attestation time and matures (pending → Bitcoin-confirmed) within a few hours. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- verify_attestation - Verify the server HMAC signature of an attestation issued by the Spazio Genesi service. Confirms that the attestation string (fingerprint + timestamp) and any declared metadata are authentic and untampered. Note: this checks the SIGNATURE only. Whether a given file matches the fingerprint must be checked locally by re-hashing the file. If the certificate carried declared metadata (title/author/year/notes), they must be provided EXACTLY as printed for the signature to verify. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- lookup_certificate - Look up whether a work's SHA-256 fingerprint has an attestation certificate in the public archive, and get its permanent links (public certificate page, PDF download, OpenTimestamps proof, browser verification). Trust model: this information is reachable only by whoever knows the fingerprint. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- authorize - Start the device-flow authorization to attest works in this session (up to 20 attestations, 24h). Returns a link the USER must open in a browser and approve (anti-bot check included). After the user approves, call `complete_authorization`. Not needed if the connection already carries an API key header, or for verification tools. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- complete_authorization - Complete the device-flow authorization after the user approved in the browser. Polls the service briefly; if approval hasn't happened yet, just call this tool again. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- attest_hash - Attest a work: the service binds the SHA-256 fingerprint to a server-side timestamp and signs it (HMAC). Requires a credential (device flow via `authorize`, or an API key header). Optional declared metadata (title/author/year/notes) are normalized and BOUND by the signature — immutable after issuance, but they remain self-declared (they don't prove authorship). Compute the SHA-256 locally if you have code execution (`sha256sum <file>` / `shasum -a 256 <file>` / `certutil -hashfile <file> SHA256`). NEVER send file bytes or base64 through tool arguments: this server never receives files. If you cannot compute a hash locally, point the user to the website (https://attestazione.spaziogenesi.org, full privacy: hashing happens in the browser) or the Telegram bot @SGAttestBot. Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp
- create_certificate_pdf - Generate and archive the certificate PDF for a fingerprint attested in this session with `attest_hash`. The PDF is cryptographically signed, anchored in Bitcoin (OpenTimestamps) and archived server-side; this tool returns the permanent links (the PDF itself is downloadable from its URL — it is never inlined here). Endpoint: https://attest-mcp-remote.it-e3f.workers.dev/mcp

## Resources
Not captured

## Prompts
Not captured

## Metadata
- Owner: io.github.SPAZIO-GENESI
- Version: 1.0.0
- Runtime: Streamable Http
- Transports: HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jul 13, 2026
- Source: https://registry.modelcontextprotocol.io
