mcp server
Emilia Protocol
Trust & human sign-off for AI agents: approval required before irreversible agent actions
Description as published by the maintainer. Source
- version 1.0.4
- active
active — Most recent push to the repository was 2026-08-08.
What this server can do
17 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
ep_add_presentation(claims, issuer_ref, party_role, handshake_id, disclosure_mode, presentation_type)- Add an identity presentation (proof) to an active handshake. WRITE: appends the party's identity claims to the handshake for evaluation against its policy; supports full, selective, or zero-knowledge disclosure. Requires auth. Returns the updated presentation count and handshake state. Call after ep_initiate_handshake and before ep_verify_handshake. Required: handshake_id, party_role, presentation_type, claims.
ep_bind_receipt_to_commit(commit_id, receipt_id)- Bind a post-action receipt to a commit, completing the commit-execute-receipt cycle. Links the behavioral outcome back to the signed authorization token. Required: commit_id, receipt_id.
ep_check_signoff(receipt_id)- Poll a pending authorization after ep_guard_action returns BLOCKED. Pass the receipt_id. Returns PENDING, APPROVED (the action may now proceed), or DENIED (with reason). Safe to call repeatedly until a decision is reached. Required: receipt_id.
ep_create_delegation(scope, expires_at, constraints, principal_id, max_value_usd, agent_entity_id)- Create a delegation record. WRITE: persists to the EP ledger that a human or principal authorizes an agent to act on their behalf, with scope, expiry, and optional constraints. Requires auth. Returns a delegation_id that later actions reference (via ep_verify_delegation) to prove authorization. Use when a principal grants an agent standing authority for a bounded set of actions. Required: principal_id, agent_entity_id, scope.
ep_get_commit_status(commit_id)- Get the current state of a pre-action commit by id. Read-only. Returns one of active, revoked, expired, or fulfilled, plus the bound action hash and expiry — poll this to learn whether a commit may still be consumed. Required: commit_id.
ep_get_handshake(handshake_id)- Get the full state of a handshake including parties, presentations, binding, and result. Use this to check handshake progress or review completed exchanges. Required: handshake_id.
ep_guard_action(amount, summary, currency, risk_flags, action_type, destination, organization_id, target_resource_id)- REQUIRED before any irreversible action: payments, wire transfers, fund releases, deletions, record or account changes, or sending messages with real-world effect. Submits the exact action for policy evaluation and human authorization. Returns APPROVED with a receipt the action may proceed under, or BLOCKED with a receipt_id + signoff_id while a named human reviews. Do NOT execute the action without an APPROVED result — if BLOCKED, poll ep_check_signoff with the receipt_id. Required: organization_id, action_type, target_resource_id.
ep_initiate_handshake(mode, binding, parties, policy_id, interaction_id)- Initiate an EP Handshake — a structured identity exchange between parties. The handshake coordinates mutual presentation of identity proofs before a trust decision. Requires at least 2 parties and a governing trust policy. Required: mode, policy_id, parties.
ep_install_preflight(policy, context, entity_id)- BEFORE installing or enabling third-party software an agent depends on — an npm package, GitHub app, browser extension, or MCP server — check it here. Evaluates the software against a fit-for-purpose trust policy and returns allow / review / deny with reasons covering publisher, requested permissions, provenance, and trust history. Required: entity_id.
ep_issue_commit(scope, policy, context, entity_id, action_type, principal_id, delegation_id, max_value_usd, counterparty_entity_id)- Issue a signed EP Commit before a high-stakes action. Returns a commit_id, decision (allow/deny/review), expiry, scope, and appeal path. The commit binds the agent to a specific action type, entity, and policy before execution. Required: action_type, entity_id.
ep_list_policies- List all available trust policies with their requirements and families. Use to discover which policy to evaluate against.
ep_revoke_commit(reason, commit_id)- Revoke an active pre-action commit before it is fulfilled or expires. SIDE EFFECT: terminally cancels the commit — it can never be consumed after this, and the change is irreversible. Requires auth. Returns the revoked status; use when a pending action should be called off. Required: commit_id, reason.
ep_revoke_handshake(reason, handshake_id)- Revoke an active handshake. Only parties to the handshake may revoke it. Revocation is terminal — the handshake cannot be reopened. Required: handshake_id, reason.
ep_verify_commit(commit_id)- Verify a pre-action commit — read-only, no side effects. Checks its signature, status, and validity and returns valid/invalid plus the current status, decision, and expiry. Use before relying on or consuming a commit to confirm it is genuine and still active. Required: commit_id.
ep_verify_delegation(action_type, delegation_id)- Verify that an agent currently holds a valid delegation from a principal for a specific action. Use this before accepting a task from an agent claiming to act on behalf of a human. Returns: valid/expired/not_found with scope details. Required: delegation_id.
ep_verify_handshake(handshake_id)- Evaluate all presentations in a handshake against its governing policy — read-only, no mutation. Returns accepted (all requirements met), rejected (policy violations), or partial (awaiting presentations), each with reason_codes explaining the outcome. Call after the parties have added their presentations to decide whether the handshake clears. Required: handshake_id.
ep_verify_receipt(receipt_id)- Verify a trust receipt — its signature and Merkle inclusion against the anchored root. Read-only. Returns valid/invalid plus the verified claim (action, approver, outcome) and anchor status; use it to independently confirm a receipt was issued by EP and has not been tampered with. Required: receipt_id.
Last successful function declaration observed on
.
Source: pkg:npm/@emilia-protocol/mcp-server. We list what the server declared;
we do not call any of these functions.
Endpoint status observed on
.
Source: pkg:npm/@emilia-protocol/mcp-server.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 664 | Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. | cumulative, all time | GitHub | |
| Last commit | 2026-08-08 | Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. | point in time | GitHub | |
| Open issues | 6 | Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. | as of fetch | GitHub | |
| Latest published version | 1.0.4 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-06-16 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| License | Apache-2.0 | Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. | as of fetch | GitHub | |
| First listed in the MCP Registry | 2026-06-16 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | active | The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. | as of fetch | GitHub | |
| mcp tools declared | 17 tools | Number of functions the server declared when started and asked to list them. It says what the server offers an agent, not how well any of it works. | as of probe | npm |
|
| mcp endpoint status | ok | The server listed 17 functions when asked. | as of probe | npm |
|
| package install scripts | none | This package declares no install-time scripts, so installing it does not execute any of its code. | as of probe | npm |
Where to get it
Related, by what their authors tagged them
-
com.scopeblind/protect-mcp
— last commit 2026-07-09, shares ai-security, ed25519, ietf
Fail-closed Cedar policy gate + Ed25519 signed receipts for agent tool calls. Denies on any error.
-
io.github.Delego-Dev/delego
— last commit 2026-06-11, shares authorization, security
Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.
-
Sounio Compiler
— last commit 2026-08-06, shares formal-verification
Check, compile, run, and test Sounio programs locally.
-
Aperion Shield
— last commit 2026-08-04, shares zero-trust
Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
-
io.github.Archerkattri/mathlas
— last commit 2026-07-25, shares formal-verification
Airtight math for AI agents: 3.68M-doc theorem search + numeric/Lean verification. No LLM, no key.
-
io.github.authzx/mcp-gateway
— last commit 2026-07-13, shares authorization
AuthzX MCP Gateway — policy-enforcing proxy between AI agents and MCP servers
-
io.github.dns-aid/dns-aid
— last commit 2026-08-06, shares ietf
Discover and publish AI agents via DNS using SVCB records (RFC 9460)
-
ActionProof
— last commit 2026-07-01, shares agentic-ai, cryptography, ed25519
Tamper-proof audit trail for AI agents. Signed receipts, offline-verifiable, zero backend.
-
io.github.forcedreamai/mcp-server
— last commit 2026-07-30, shares cryptography, ed25519
A paid, growing marketplace of real AI agents -- Ed25519-proven, verifiable in your own process.
-
verify-proof
— last commit 2026-07-19, shares cryptography
Verify blockchain-anchored timestamp proofs offline. No network calls, account, or API key.
These share tags the maintainers applied themselves, such as ai-security, ed25519, ietf, zero-trust. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
How the author describes it
Topics the maintainer set on GitHub: agent-security, agentic-ai, ai-agents, ai-security, audit-evidence, authorization, authorization-receipts, consequence-firewall, cryptography, ed25519, exact-action, formal-verification, human-authorization, ietf, mcp, mcp-security, model-context-protocol, policy-enforcement, security, zero-trust.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json