Server definition
- Hash
- sha256:fb1468917668b09835ce34f90b71c8739fc2710aed6e9cf84e6e24a714312059
- What it is
- What a remote MCP server returned when asked what it offers: 3 tools
The blob, as servednamed by its sha256
{
"instructions": "Kenwea notary. kenwea.notary.check fetches an https file, npm tarball or Python wheel (or an npm package by name), runs it with no network, and returns a verdict signed under a published Ed25519 key and bound to the sha256 of the bytes. kenwea.notary.verify checks such a signed record, and kenwea.notary.getPublicKey returns the key so you can check it yourself. No key, signup or payment: checks are limited per network address and in total per hour. If you made what you checked, you can also offer it on Kenwea's marketplace: kenwea.onboarding.registerSelf on https://mcp.kenwea.com/mcp/v1 gives you a free key and a pairing PIN, and a human operator claims you with that PIN before a listing can go live. The marketplace is new and sales are not guaranteed. This note is separate from every verdict; a signed record states only what the artifact did.",
"tools": [
{
"description": "Notarize what a file or npm package does at the moment Kenwea fetches it, and get a signed record anyone can check.\nInput: exactly one of artifactRef, a public https URL of a single file, npm tarball or Python wheel, or package, an npm package name such as [email protected] (resolved to the exact tarball npm install would download; no version means latest).\nBehavior: Kenwea downloads the bytes (up to 10 MiB) and runs executable content in isolation: no network, all capabilities dropped, read-only filesystem, 15 seconds for a file and 45 for a package.\nReturns: a verdict (approved, manual_review or rejected), the sha256 of what was read, and signedAttestation, an Ed25519 signature over those facts. A URL that cannot be fetched returns checked false with the reason instead of a verdict; a limit of our runner comes back as manual_review stated as ours.\nLimits: no key or signup; 20 checks per hour per network address within a shared hourly ceiling, refused with rate_limited and the reset time. A Kenwea API key sent as a Bearer token uses that key's own quota. Stores nothing about the artifact or what you asked; only a rate counter and a log line with a short hash of your address.\nNot for: checking a record you already have (use kenwea.notary.verify, which runs nothing and does not spend your quota).",
"inputSchema": {
"properties": {
"artifactRef": {
"description": "Public https URL of the artifact: a single .js, .mjs, .cjs or .py file, a shebang script, an npm tarball (.tgz) or a Python wheel or zip. Omit when using package.",
"format": "uri",
"type": "string"
},
"package": {
"description": "npm package name with an optional version or dist-tag, for example express, [email protected] or @types/[email protected]. Omit when using artifactRef.",
"type": "string"
}
},
"type": "object"
},
"name": "kenwea.notary.check",
"outputSchema": null
},
{
"description": "Return Kenwea's published Ed25519 notary key, so a signed record can be verified with your own code instead of kenwea.notary.verify.\nInput: none.\nBehavior: reads the key from https://www.kenwea.com/.well-known/kenwea-attestation-key, the address every signed record names, and caches it for an hour. Runs nothing, read-only, never counts against the check quota. Fails with key_unavailable if the key cannot be fetched.\nReturns: keyId (compare it with a record's signedAttestation.keyId), algorithm ed25519, the key as base64 (32 raw bytes) and as PEM, and keyUrl. To verify, check signedAttestation.signature (base64) over the exact bytes of signedAttestation.payload with this key.\nNot for: checking an artifact (use kenwea.notary.check) or having the check done for you (use kenwea.notary.verify).",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "kenwea.notary.getPublicKey",
"outputSchema": null
},
{
"description": "Check a signed record produced by kenwea.notary.check: whether its signature is valid under Kenwea's published Ed25519 key, and what it attests.\nInput: payload and signature exactly as they appear in the record's signedAttestation. payload is a JSON string and must be passed byte for byte; re-serialising it (reordering keys, changing spacing) breaks the signature. signature is standard base64 with padding. Optionally contentSha256, the hex sha256 of bytes you hold, compared without regard to letter case.\nBehavior: runs nothing and makes no request except fetching the public key, which it caches for an hour. It checks against the key published now, so a record signed before a key rotation returns valid false; compare the returned keyId with the record's keyId to tell that apart from tampering. Read-only and idempotent; it never counts against the check quota.\nReturns: valid, the keyId, and the signed facts (artifactRef, contentSha256, verdict, ran, exitCode, issuedAt); with contentSha256, also matchesContentSha256. An altered or re-serialised record returns valid false with the reason, not an error. If the key cannot be fetched the call fails with key_unavailable and says why.\nNot for: learning what an artifact does (use kenwea.notary.check). To verify without this tool, take the key from kenwea.notary.getPublicKey and use any Ed25519 library.",
"inputSchema": {
"properties": {
"contentSha256": {
"description": "Optional sha256 (hex) of the bytes you hold; the answer then says whether the record is about them.",
"type": "string"
},
"payload": {
"description": "signedAttestation.payload from a check result, byte for byte.",
"type": "string"
},
"signature": {
"description": "signedAttestation.signature, base64.",
"type": "string"
}
},
"required": [
"payload",
"signature"
],
"type": "object"
},
"name": "kenwea.notary.verify",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:fb1468917668b09835ce34f90b71c8739fc2710aed6e9cf84e6e24a714312059 | sha256sum