iqa-mcp — IQA attestation as MCP tools
The IQA attestation primitives — derived intent addressing and AE-128 envelope verification — exposed as Model Context Protocol tools, so any MCP agent can verify trust offline, fail-closed. A thin, stateless wrapper around the published iqa-org 1.3.1 reference implementation. No network. No accounts. No key storage. No state.
Agent platforms are converging on MCP as the tool-calling layer —
Microsoft's agent OS, Google's Antigravity, Uber's MCP Gateway (800+ servers, 5000+ tools).
The missing layer is trust semantics: what intent is being addressed and
whether the counterparty has standing — verifiable without a network call.
These four tools make that layer native to any MCP agent.
The four tools
| Tool | Returns | Key needed |
|---|---|---|
| derive_route_shard | SHA-256(authority)[0:16] hex — the derived, action-independent intent address (SPEC sec. 3). No lookup, no registry, no network call. | no |
| parse_envelope | structural decode of one AE-128 frame: version, lease, shard, organ, nonce, standing — fails closed on every layout rule of the companion draft. | no |
| verify_envelope | full AE-128 verification: constant-time HMAC-SHA256 over the whole 128-byte frame with the attestation field zeroed, plus the lease check. REJECT is a result, not an error. | yes (caller-supplied) |
| published_vector | the published AE128-VECTOR-1 (authority, test key, frame hex) for byte-for-byte self-test. | — |
Install & run
pip install "iqa-org>=1.3.1" "mcp>=2" git clone https://github.com/Aicent-Stack/iqa-mcp cd iqa-mcp python server.py # stdio transport
MCP client configuration (Claude Desktop / Cline style):
{
"mcpServers": {
"iqa": {
"command": "python",
"args": ["/path/to/iqa-mcp/server.py"]
}
}
}
Self-test
python test_mcp.py [PASS] 1 · list_tools -> 4 tools [PASS] 2 · derive_route_shard -> 5c378581f92754d0bc88adaed84b7c5a [PASS] 3 · published_vector -> f3b2a1c4.pillar.example [PASS] 4 · parse_envelope -> standing radiant [PASS] 5 · verify_envelope -> [PASS] radiant · nonce 1 [PASS] 6 · tampered frame -> REJECT (HMAC mismatch) [PASS] 7 · malformed hex -> REJECT ALL 7/7 PASS
Test 6 is the point: flip one byte of the standing field and the frame dies — attestation does not verify. Fail-closed, over the wire.
Design invariants
- Zero-parser — fixed offsets, no TLV, no heap-shaped parsing.
- Fail-closed — malformed input is a REJECT result, never a normalised partial answer.
- Offline — verification needs the frame, the key, and a hash function. Nothing else.
- Stateless — the server stores nothing; the organ key is passed per call and never persisted.
Links
| What | Where |
|---|---|
| Source | github.com/Aicent-Stack/iqa-mcp |
| PyPI | pypi.org/project/iqa-mcp (0.1.0) |
| The library it wraps | iqa-org 1.3.1 — four registries, byte-exact vectors, offline self-test |
| Public record, dated | iqa.org/brief |
| Live demos | Stack Compare · Delegation Stress Test |
| Whitepaper | iqa.org/whitepaper |
| Internet-Draft | draft-li-rttp-iqa-addressing — Independent Submission, in review |