Skip to content
Official MCP RegistryListed

io.github.sipyourdrink-ltd/bernstein-mcp

Verifies Bernstein run receipts and hash chains; lists the shipped presets and adapters. Read-only.

First seen 2 Oct 2026. Evidence as of 3 Oct 2026.

11
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
explain_receiptVerify a run receipt and narrate the result in plain language: what the run recorded, which chains recomputed, where the first divergence is, and what an auditor can and cannot conclude without the producing install's keys.Not declared
explain_trace_mappingHow a bernstein run maps onto a TRACE v0.2 Trust Record: one row per claim with the journal field it is sourced from and the rule that derives it. Pass a run receipt to fill in the rows its embedded journal can answer (subject, iat, model, data_class, policy digest, tool transcript) alongside the receipt's own verdict.Not declared
get_presetEvery field of one compliance preset as bernstein v3.19.2 resolves it.Not declared
list_adaptersThe agent adapters bundled with bernstein v3.19.2: adapter name, the binary it drives, the module that implements it.Not declared
list_presetsThe compliance presets bernstein v3.19.2 ships, with the switches each one turns on.Not declared
server_infoIdentity, version, and request limits for this MCP server.Not declared
verify_agent_manifestAgent Manifest v0.2 conformance checks on one manifest, stateless, no account: schema (vendored agent-manifest.schema.json), profile context, version, canonicalization, COSE envelope signature (Ed25519, key identified by kid in the protected header; ML-DSA-65 is reported unverifiable). Optionally checks that a TRACE Trust Record cites this manifest by digest. Nothing is fetched; resolvers are checked as URIs only. The manifest hash is sha256 over the COSE payload bytes (or RFC 8785 canonical JSON for object input).Not declared
verify_chainWalk bernstein chain rows and recompute every link: journal rows (event_hash), lineage spine entries (entry_hash) or audit events (prev_hmac linkage). The row kind is detected from the fields, or pass `kind` explicitly. Reports the first divergent index. Pass `entries` as the file text (a JSON array or one row per line, as journal.jsonl is written) for byte-exact hashing; a parsed array also works, but then a float spelled 1.0 or -0.0 in the file cannot be told apart from an integer.Not declared
verify_delegation_chainTRACE v0.2 delegation-chain conformance, stateless, no account: index every Trust Record by the RFC 8785 digest of its complete form, start at the leaf, follow delegation.parent_record_hash to the root, and check each hop's signature, the root key against `trusted_root_keys`, the depth bound, the link's digest algorithm, the credential (registered, issuer = parent subject, holder = record subject, window at the hop's own iat) and data_class narrowing under `data_class_lattice`. Classification: provenance-invalid outranks authorization-invalid; an unread link is unverifiable, not broken. Pass `records` as a JSON array or as file text (one record per line or a JSON array).Not declared
verify_receiptRecompute every hash chain a bernstein run receipt embeds (journal, lineage spine, optional audit range), rebuild the signed subject from the recomputed heads, and check the Ed25519 signature with the key the receipt carries. Needs no secret and reads nothing but the receipt. Returns the verdict, the first failing check, one line per check, and the same verdict as a DSSE envelope signed by this verifier's Ed25519 key (public key at keys_url) so the outcome can be kept and re-checked offline.Not declared
verify_trace_recordTRACE v0.2 conformance checks on one Trust Record, stateless, no account: schema (vendored trace-claim.json), profile, subject URI, software-only runtime rule, policy digest, public-only confirmation key, the embedded signature (EdDSA, ES256 or ES384 with the key in cnf.jwk), appraisal, delegation link shape and references. Nothing is fetched: resolvers are checked as URIs only. `record_sha256` is the RFC 8785 digest of the complete record, signature included — the value a child hop puts in delegation.parent_record_hash.Not declared

Change history

No changes since the first observation. The first snapshot is the baseline.

Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryio.github.sipyourdrink-ltd/bernstein-mcp2 Oct 20263 Oct 20261