ZBS Index What actually exists in applied AI, with the source next to it

mcp server

Emilia Protocol

Trust & human sign-off for AI agents: approval required before irreversible agent actions

Description as published by the maintainer. Source

  • version 1.0.4
  • active

active — Most recent push to the repository was 2026-08-08.

What this server can do

17 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

ep_add_presentation(claims, issuer_ref, party_role, handshake_id, disclosure_mode, presentation_type)
Add an identity presentation (proof) to an active handshake. WRITE: appends the party's identity claims to the handshake for evaluation against its policy; supports full, selective, or zero-knowledge disclosure. Requires auth. Returns the updated presentation count and handshake state. Call after ep_initiate_handshake and before ep_verify_handshake. Required: handshake_id, party_role, presentation_type, claims.
ep_bind_receipt_to_commit(commit_id, receipt_id)
Bind a post-action receipt to a commit, completing the commit-execute-receipt cycle. Links the behavioral outcome back to the signed authorization token. Required: commit_id, receipt_id.
ep_check_signoff(receipt_id)
Poll a pending authorization after ep_guard_action returns BLOCKED. Pass the receipt_id. Returns PENDING, APPROVED (the action may now proceed), or DENIED (with reason). Safe to call repeatedly until a decision is reached. Required: receipt_id.
ep_create_delegation(scope, expires_at, constraints, principal_id, max_value_usd, agent_entity_id)
Create a delegation record. WRITE: persists to the EP ledger that a human or principal authorizes an agent to act on their behalf, with scope, expiry, and optional constraints. Requires auth. Returns a delegation_id that later actions reference (via ep_verify_delegation) to prove authorization. Use when a principal grants an agent standing authority for a bounded set of actions. Required: principal_id, agent_entity_id, scope.
ep_get_commit_status(commit_id)
Get the current state of a pre-action commit by id. Read-only. Returns one of active, revoked, expired, or fulfilled, plus the bound action hash and expiry — poll this to learn whether a commit may still be consumed. Required: commit_id.
ep_get_handshake(handshake_id)
Get the full state of a handshake including parties, presentations, binding, and result. Use this to check handshake progress or review completed exchanges. Required: handshake_id.
ep_guard_action(amount, summary, currency, risk_flags, action_type, destination, organization_id, target_resource_id)
REQUIRED before any irreversible action: payments, wire transfers, fund releases, deletions, record or account changes, or sending messages with real-world effect. Submits the exact action for policy evaluation and human authorization. Returns APPROVED with a receipt the action may proceed under, or BLOCKED with a receipt_id + signoff_id while a named human reviews. Do NOT execute the action without an APPROVED result — if BLOCKED, poll ep_check_signoff with the receipt_id. Required: organization_id, action_type, target_resource_id.
ep_initiate_handshake(mode, binding, parties, policy_id, interaction_id)
Initiate an EP Handshake — a structured identity exchange between parties. The handshake coordinates mutual presentation of identity proofs before a trust decision. Requires at least 2 parties and a governing trust policy. Required: mode, policy_id, parties.
ep_install_preflight(policy, context, entity_id)
BEFORE installing or enabling third-party software an agent depends on — an npm package, GitHub app, browser extension, or MCP server — check it here. Evaluates the software against a fit-for-purpose trust policy and returns allow / review / deny with reasons covering publisher, requested permissions, provenance, and trust history. Required: entity_id.
ep_issue_commit(scope, policy, context, entity_id, action_type, principal_id, delegation_id, max_value_usd, counterparty_entity_id)
Issue a signed EP Commit before a high-stakes action. Returns a commit_id, decision (allow/deny/review), expiry, scope, and appeal path. The commit binds the agent to a specific action type, entity, and policy before execution. Required: action_type, entity_id.
ep_list_policies
List all available trust policies with their requirements and families. Use to discover which policy to evaluate against.
ep_revoke_commit(reason, commit_id)
Revoke an active pre-action commit before it is fulfilled or expires. SIDE EFFECT: terminally cancels the commit — it can never be consumed after this, and the change is irreversible. Requires auth. Returns the revoked status; use when a pending action should be called off. Required: commit_id, reason.
ep_revoke_handshake(reason, handshake_id)
Revoke an active handshake. Only parties to the handshake may revoke it. Revocation is terminal — the handshake cannot be reopened. Required: handshake_id, reason.
ep_verify_commit(commit_id)
Verify a pre-action commit — read-only, no side effects. Checks its signature, status, and validity and returns valid/invalid plus the current status, decision, and expiry. Use before relying on or consuming a commit to confirm it is genuine and still active. Required: commit_id.
ep_verify_delegation(action_type, delegation_id)
Verify that an agent currently holds a valid delegation from a principal for a specific action. Use this before accepting a task from an agent claiming to act on behalf of a human. Returns: valid/expired/not_found with scope details. Required: delegation_id.
ep_verify_handshake(handshake_id)
Evaluate all presentations in a handshake against its governing policy — read-only, no mutation. Returns accepted (all requirements met), rejected (policy violations), or partial (awaiting presentations), each with reason_codes explaining the outcome. Call after the parties have added their presentations to decide whether the handshake clears. Required: handshake_id.
ep_verify_receipt(receipt_id)
Verify a trust receipt — its signature and Merkle inclusion against the anchored root. Read-only. Returns valid/invalid plus the verified claim (action, approver, outcome) and anchor status; use it to independently confirm a receipt was issued by EP and has not been tampered with. Required: receipt_id.

Last successful function declaration observed on . Source: pkg:npm/@emilia-protocol/mcp-server. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: pkg:npm/@emilia-protocol/mcp-server.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
GitHub stars 664 Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. cumulative, all time GitHub
Last commit 2026-08-08 Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. point in time GitHub
Open issues 6 Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. as of fetch GitHub
Latest published version 1.0.4 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-06-16 When the registry record was last updated by its maintainer. point in time Model Context Protocol
License Apache-2.0 Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. as of fetch GitHub
First listed in the MCP Registry 2026-06-16 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
repository status active The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. as of fetch GitHub
mcp tools declared 17 tools Number of functions the server declared when started and asked to list them. It says what the server offers an agent, not how well any of it works. as of probe npm
mcp endpoint status ok The server listed 17 functions when asked. as of probe npm
package install scripts none This package declares no install-time scripts, so installing it does not execute any of its code. as of probe npm

Where to get it

Related, by what their authors tagged them

  • com.scopeblind/protect-mcp — last commit 2026-07-09, shares ai-security, ed25519, ietf
    Fail-closed Cedar policy gate + Ed25519 signed receipts for agent tool calls. Denies on any error.
  • io.github.Delego-Dev/delego — last commit 2026-06-11, shares authorization, security
    Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.
  • Sounio Compiler — last commit 2026-08-06, shares formal-verification
    Check, compile, run, and test Sounio programs locally.
  • Aperion Shield — last commit 2026-08-04, shares zero-trust
    Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
  • io.github.Archerkattri/mathlas — last commit 2026-07-25, shares formal-verification
    Airtight math for AI agents: 3.68M-doc theorem search + numeric/Lean verification. No LLM, no key.
  • io.github.authzx/mcp-gateway — last commit 2026-07-13, shares authorization
    AuthzX MCP Gateway — policy-enforcing proxy between AI agents and MCP servers
  • io.github.dns-aid/dns-aid — last commit 2026-08-06, shares ietf
    Discover and publish AI agents via DNS using SVCB records (RFC 9460)
  • ActionProof — last commit 2026-07-01, shares agentic-ai, cryptography, ed25519
    Tamper-proof audit trail for AI agents. Signed receipts, offline-verifiable, zero backend.
  • io.github.forcedreamai/mcp-server — last commit 2026-07-30, shares cryptography, ed25519
    A paid, growing marketplace of real AI agents -- Ed25519-proven, verifiable in your own process.
  • verify-proof — last commit 2026-07-19, shares cryptography
    Verify blockchain-anchored timestamp proofs offline. No network calls, account, or API key.

These share tags the maintainers applied themselves, such as ai-security, ed25519, ietf, zero-trust. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.

This is not a recommendation and not a test result. It is a map of what the authors said their work is about.

How the author describes it

Topics the maintainer set on GitHub: agent-security, agentic-ai, ai-agents, ai-security, audit-evidence, authorization, authorization-receipts, consequence-firewall, cryptography, ed25519, exact-action, formal-verification, human-authorization, ietf, mcp, mcp-security, model-context-protocol, policy-enforcement, security, zero-trust.

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. emiliaprotocol/emilia-protocol on GitHub — GitHub, observed , trust tier 3.
  2. Official MCP Registry — Model Context Protocol, observed , trust tier 1.
  3. @emilia-protocol/mcp-server started in an isolated container — npm, observed , trust tier 1.