# paceproof [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/RudrenduPaul/PaceProof  
**GitHub Stars:** 0  
**npm Downloads (last month):** 306  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/paceproof

## Description
Verifies Ed25519-signed attestation records and builds audit reports via MCP tools.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `uvx` (confidence: high):

```json
"mcpServers": {
  "paceproof": {
    "command": "uvx",
    "args": ["paceproof-cli"]
  }
}
```

## Documentation

## What paceproof MCP server does

The paceproof MCP server gives an orchestrating agent access to three operations: `verify`, `ingest`, and `report`. These operations use the same underlying functions as the PaceProof command-line interface rather than a separate MCP-only implementation.

PaceProof works with compute-attestation records that were signed elsewhere. It validates each record against the expected schema and checks its Ed25519 signature. Records that are missing signatures, contain malformed signatures, fail schema validation, or no longer match their signed contents remain in an unverified set. They are not combined with verified records when totals are calculated.

The paceproof MCP server is therefore suited to workflows that need evidence-oriented handling of compute records. It can distinguish successful verification from failure reasons and preserve that distinction in reporting. It does not generate attestations, sign records, or act as a provider of compute services.

## How it works

The `ingest` operation runs a named adapter and converts input into PaceProof's canonical record format as JSONL. The shipped `jsonl` adapter reads newline-delimited JSON that is already in canonical form. The CLI also documents path-or-URL input for ingestion, with network requests limited by a 30-second timeout and a 50 MiB streamed-response cap.

After ingestion, `verify` checks schema validity and Ed25519 signatures for each record. `report` performs ingestion and verification, then aggregates the results. Reports separate verified and unverified counts and compute totals, and can group verified results by provider and workload type. Failure reasons are retained for individual records.

PaceProof has separate TypeScript and Python implementations. The TypeScript and Python command-line outputs are tested for parity on shared fixtures, while the MCP path in the TypeScript package calls the same aggregation and reporting functions used by its CLI.

## Setup and configuration

Install the published CLI with either npm or PyPI:

```bash
npm install -g paceproof-cli
# or
pip install paceproof-cli
```

The repository's TypeScript package includes the MCP server. To build it from source, clone the repository, enter `packages/cli-ts`, install dependencies, and run the build:

```bash
git clone https://github.com/RudrenduPaul/PaceProof.git
cd PaceProof/packages/cli-ts
npm install
npm run build
```

Start the MCP entry point with `paceproof mcp` after installing the CLI. The provided material does not specify environment variables or client-specific configuration. Input adapters and output options are selected through tool or CLI arguments, including the adapter name and, for CLI commands, JSON or output-file options.

## Tools and capabilities

The paceproof MCP server exposes:

- `verify`: checks every record and reports verified and unverified results.
- `ingest`: normalizes adapter-readable input into canonical JSONL.
- `report`: combines ingestion, verification, and aggregation into a summary.

The corresponding CLI also provides `init` for creating example records and `dashboard` for rendering a self-contained HTML file. Those commands are documented as CLI features; the README specifically identifies `verify`, `ingest`, and `report` as MCP tools.

The dashboard output uses inline CSS and contains no JavaScript, external scripts, remote requests, or CDN assets. Aggregation uses null-prototype buckets to prevent attacker-controlled grouping values from modifying `Object.prototype`, and schema fields have explicit maximum lengths.

## Limitations and notes

PaceProof only verifies records that already exist; it does not sign or produce attestations. The default JSONL adapter expects canonical-schema records, so provider-specific formats require an adapter implementing the documented adapter interface. A failed signature or schema check is never treated as verified.

The dashboard currently has one light theme and no dark-mode toggle. The README does not document authentication, persistent storage, or environment-variable settings for the MCP server. Network access is relevant to URL ingestion, not to the core verification of local records.

_Full upstream README: https://allmcps.com/mcp/paceproof/readme_

