MCP server
Let AI agents and assistants look up domains, resolve SPIFFE trust domains and check signed assertions in the workload trust directory.
Endpoint (Streamable HTTP):
https://mcp.svid.io/mcp
Connect
Claude Code
claude mcp add --transport http art https://mcp.svid.io/mcp
Claude Desktop and claude.ai: Settings → Connectors → Add custom connector, and paste the endpoint above.
Other clients that speak Streamable HTTP take the URL directly. Clients that only speak stdio can bridge with mcp-remote:
{
"mcpServers": {
"art": { "command": "npx", "args": ["-y", "mcp-remote", "https://mcp.svid.io/mcp"] }
}
}
Organization tools (optional): send a directory service token as Authorization: Bearer art_st_…. For example:
claude mcp add --transport http art https://mcp.svid.io/mcp --header "Authorization: Bearer art_st_…"
Tools
| Tool | What it does |
|---|---|
| search_domains | Browse or prefix-search the domain directory. |
| get_domain | One domain: separate evidence indicators, the historical TLS observation, claims, delegations and issuer bindings. No trust score. |
| resolve_trust_domain | Resolve a SPIFFE trust domain: the raw signed assertion plus an unverified decoded view. |
| verify_spiffe_id | Is spiffe://td/path authorized for an expected organization ID? Verifies the JWS, the bundle digest and the scope. |
| get_changes | Read the public lifecycle change feed. |
| get_jwks | The directory's assertion-signing keys. |
| get_openapi | The API description, as a route summary or the full YAML. |
| explain | Short docs: the three checks, evidence types, the assertion, verification steps, rotation, the change feed. |
With a service token, these read-only tools are added:
| Tool | What it does |
|---|---|
| list_my_claims | Your organization's claims. |
| get_claim | One claim with its checks and next actions. |
| list_my_bindings | Your organization's issuer bindings. |
| get_binding | One issuer binding with its versions. |
Resources: art://openapi, art://docs/verification, art://jwks.
Good to know
- Everything is read-only. Trust-changing actions need a passkey step-up in the console, which a service token cannot do.
verify_spiffe_idfetches the JWKS live for convenience. A real relying party pins it out of band. It also does not validate an SVID certificate chain or key possession; mTLS does that.- Tool results mark directory data (domain names, organization names, certificate subjects) as untrusted data, not instructions.
- Limit: 60 requests per minute per client (IPv4 address or IPv6 /64). One JSON-RPC message per request; batches are not accepted.