Preview — not for production reliance

MCP server

Let AI agents and assistants look up domains, resolve SPIFFE trust domains and check signed assertions in the workload trust directory.

Endpoint (Streamable HTTP):

https://mcp.svid.io/mcp

Connect

Claude Code

claude mcp add --transport http art https://mcp.svid.io/mcp

Claude Desktop and claude.ai: Settings → Connectors → Add custom connector, and paste the endpoint above.

Other clients that speak Streamable HTTP take the URL directly. Clients that only speak stdio can bridge with mcp-remote:

{
  "mcpServers": {
    "art": { "command": "npx", "args": ["-y", "mcp-remote", "https://mcp.svid.io/mcp"] }
  }
}

Organization tools (optional): send a directory service token as Authorization: Bearer art_st_…. For example:

claude mcp add --transport http art https://mcp.svid.io/mcp --header "Authorization: Bearer art_st_…"

Tools

ToolWhat it does
search_domainsBrowse or prefix-search the domain directory.
get_domainOne domain: separate evidence indicators, the historical TLS observation, claims, delegations and issuer bindings. No trust score.
resolve_trust_domainResolve a SPIFFE trust domain: the raw signed assertion plus an unverified decoded view.
verify_spiffe_idIs spiffe://td/path authorized for an expected organization ID? Verifies the JWS, the bundle digest and the scope.
get_changesRead the public lifecycle change feed.
get_jwksThe directory's assertion-signing keys.
get_openapiThe API description, as a route summary or the full YAML.
explainShort docs: the three checks, evidence types, the assertion, verification steps, rotation, the change feed.

With a service token, these read-only tools are added:

ToolWhat it does
list_my_claimsYour organization's claims.
get_claimOne claim with its checks and next actions.
list_my_bindingsYour organization's issuer bindings.
get_bindingOne issuer binding with its versions.

Resources: art://openapi, art://docs/verification, art://jwks.

Good to know