Skip to content
Official MCP RegistryListed

Trooth

Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust.

First seen 2 Oct 2026. Evidence as of 4 Oct 2026.

6
Tools
From an anonymous probe
1
Source listings
Each with its own history
7
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
trooth_ai_data_use_disclosuresRead what one company on the Trooth Network has declared about AI and customer data: whether it trains models on customer data, whether AI is in the product, and which approaches. The company is named by its domain or its Trooth slug, matched exactly. Each row is the company's own declaration and is labeled so. Also says whether Trooth observed a supporting policy clause; not observed means Trooth has not read one, never that the company does not train on customer data. Read only.Read-only
trooth_askAnswer a question about Trooth itself (what the Trooth Network is, what one company record carries, pricing, how witnessing works) from Trooth's fixed, curated knowledge base. Makes no outside request. A question the knowledge base does not cover returns out_of_scope; for a company's record use trooth_public_trust_profile.Read-only
trooth_my_company_recordNeeds an OAuth access token with the records:read scope from the authorization server this server's protected-resource metadata names; every other tool here needs none. Reads the company record of the Trooth workspace the signed-in person belongs to: its name, its slug and the address of its public page. The workspace comes from the token's subject and never from an argument, so this tool takes no arguments. Read only.Read-only
trooth_outside_in_readFetch https://<domain>/ and /.well-known/security.txt once, when called, from Trooth's server and report whether HTTPS answered, which of five response headers (HSTS, CSP, nosniff, frame protection, referrer policy) are present, and whether security.txt is published, absent or unread. IP literals and names resolving to private, loopback or link-local addresses are refused; redirects are reported, not followed; each request stops after 4 seconds. Observations, not witnessed evidence, not a grade.Read-only
trooth_public_trust_profileRead one company's published record on the Trooth Network, given its domain or Trooth slug. The identifier is matched exactly (a URL is reduced to its host), never by a similar name; a name several companies share returns their candidates, not a pick. A record is keyed by its domain and does not by itself say which legal entity, subsidiary or product the domain belongs to. Returns a status and a provenance label; the company's own text is labeled as its own words. Read only.Read-only
trooth_verifyCheck the two signatures on a Trust Ledger Token (tlt2. or tlt. form, or its JTI) against Trooth's own token ledger. Returns valid, invalid (a signature does not check out), expired or revoked, or unclaimed when no token matches. Trooth's signature covers the signing event, not the claim bytes and not the truth of the claims; the issuing company's signature covers the payload.Read-only

Change history

  1. trooth_verify: input schema changed
  2. trooth_public_trust_profile: input schema changed
  3. trooth_outside_in_read: input schema changed
  4. trooth_my_company_record: tool added
  5. trooth_ask: input schema changed
  6. trooth_ai_data_use_disclosures: tool added
  7. server instructions changed (+"grade," +"For 30 days it also keeps a record of each call's policy decision: the tool, whether it was allowed and why, the policy version, the argument names and lengths (never their values) and the outcome. One tool, trooth_my_company_record, needs an OAuth access token and reads only the signed-in caller's own workspace; every other tool needs no account." -"score,")
Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryio.github.troothllc/trooth-network2 Oct 20263 Oct 20261