sign-cli
Agent-first e-signature MCP server with **offline PAdES signing** and hash-chained audit. The same 19 tools / 4 prompts / 12 resources are reachable via stdio (`npx @drbaher/sign-cli mcp serve`) for local agents and over HTTP for remote ones. **Architectural claim:** an LLM agent can drive every step of a contract workflow except the actual signing gesture, which stays gated behind a human via per-signer approval tokens (TTL-bounded, scoped to one email, single-use). Pre-sign safety checks (`--require-hash`, `--require-title`, `--require-signer-email`) throw structured errors *before* any state mutation — so an agent that computed a hash earlier can refuse to sign if the document was swapped mid-flight. **Highlights:** - Fully-offline PAdES signer (real PKCS#7, self-issued X.509) - Hash-chained audit log with append-only DB triggers + RFC 3161 timestamping - Read-only mode (`--read-only true`) returns `FORBIDDEN_READ_ONLY` for mutating tools - Multi-provider routing (local / Dropbox Sign / DocuSign / SignWell) - Pre-sign signature visibility (`existingSignatures` on every fetch) - Tool allow-list + capability scoping for sandboxed agents This Smithery deployment runs in **read-only mode** against an ephemeral SQLite that wipes every 4 hours — safe to explore, not for production signing. For local agent use, install via `npm i -g @drbaher/sign-cli`. MIT-licensed. No telemetry. Source: github.com/DrBaher/sign-cli. Showcase: cli.drbaher.com.
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | drbaher/sign-cli | 2 Oct 2026 | 5 Oct 2026 | 1 |