Verifiable decision records for AI agents: signed receipts for calls to its own governed tools.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Verifiable decision records for AI agents: each recorded tool-call decision is a signed, hash-chained receipt, exported in evidence bundles a reviewer can verify offline against the published format. Verification establishes the integrity of the receipts present, not that every action was recorded.
Status: published reference implementation, before independent pilot validation. The gateway emits classical Ed25519-SHA256-JCS bundles. The published
@attested-intelligence/aga-verify@2.2.2CLI checks that classical profile; on a v2/hybrid bundle it reports FAILED because it does not implement that profile. The package also exposes an ML-DSA-65 + Ed25519 composite as a library profile, andaga-proxy verifycan check it. Reference verifiers have their own unsupported-profile behavior. These are different components, not one interchangeable verifier. Build provenance concerns the published build; it is not runtime correctness or an external security audit.
Runtime status. Since 3.5.0, a measurement requested after the active artifact's TTL expires moves it to TERMINATE;
delegate_to_subagentalso refuses after expiry. Nothing checks the TTL on a schedule, and the exported bundle does not record that transition. Do not downgrade to deprecated 3.3.3 as the evaluation path. Since 3.6.0,aga-proxyhonorsAGA_GATEWAY_KEY/AGA_GATEWAY_KEY_FILE; the stdio upstream can inherit those variables. Read the known issues andTHREAT_BOUNDARY.mdbefore any runtime evaluation.
Runtime examples below identify the observed 3.6.2 package, not a newly approved production deployment. Review the known issues first; an isolated synthetic evaluation is required before considering a pilot. Prefer the static verifier path for the first check.
A Python companion SDK (aga-governance) is documented in the Python SDK section below.
You do not have to take any of this on faith. The repo ships the reference verifier, the canonical vectors, and sample bundles, so you can check one offline right now, with no network and no callback to us:
The published @attested-intelligence/aga-verify CLI agrees on the tested classical corpus as the harness supplies it. npm run conformance:cross-stack (first: npm run build && npm --prefix independent-verifier run build) proves that six v1 verifier configurations, spanning three independent toolchains (JavaScript, Go, and Python, including a pure-stdlib, no-third-party-crypto path), agree on the 54 object-level cases. The five file-parsing verifiers also agree on the 7 raw-byte/file-parse cases (61 total). The in-server engine is library-only, receiving parsed objects rather than raw file bytes, so it does not run the file-parse cases; six configurations do not agree on all 61 and this no longer claims they do. npm run conformance:cross-stack-v2 proves two genuinely independent-language oracles (@noble/JS and CIRCL/Go) agree on the v2 composite corpus. For a source-and-build reproduction (build the package yourself, reproduce the published tarball byte-for-byte, re-run every gate), see the REVIEWER_GUIDE.md (a command-by-command self-service path), REPRODUCIBILITY.md, and the step-by-step SKEPTICAL_AUDITOR.md. This release carries SLSA build provenance, checkable with npm audit signatures.
This is built for teams shipping agentic-AI products into financial services and insurance, at the moment a customer's vendor-risk, model-risk, or internal-audit review asks what your agent did and how anyone would know.
Covered tool calls routed through aga-proxy are evaluated against its configured policy. Each recorded decision (PERMITTED or DENIED) takes the form of a signed, hash-linked governance receipt; known issue 7 below describes calls refused without a receipt. aga-proxy also signs the SHA-256 of its policy's canonical JSON into every receipt; see KNOWN_LIMITATIONS.md for what that field binds. Receipts are collected into evidence bundles that anyone holding the published format and the public key can verify offline, with no callback to us.
Record. Prove. Verify.
Scope: a verified bundle proves the integrity of the receipts present: each is authentic, correctly ordered, Merkle-included, and (when a key is pinned) provenance-bound. It does not prove non-omission (that every action the agent took was logged); completeness is bounded by the tamper-evidence of the interception point, which is outside the bundle. See KNOWN_LIMITATIONS.md for the full honest boundary, and THREAT_BOUNDARY.md for the per-field detail.
Add to your Claude Desktop MCP config (claude_desktop_config.json):
Claude can then seal artifacts, measure integrity, generate evidence bundles, and verify them offline through natural language.
By default the gateway signs with an ephemeral key that rotates on every restart. That is fine for a first look, but evidence-bundle provenance cannot be pinned across restarts (and the server warns about it on stderr). Set one stable 64-hex Ed25519 seed so provenance stays pinnable:
Since 3.6.0 this applies to both binaries.
aga-proxyreads the same two variables through the same resolver and prints the active public key at startup so you can pin it out of band;--ephemeralmakes a throwaway key a stated choice. In 3.5.0 and earlieraga-proxyignored both variables silently; a key you set had no effect and no warning was printed, so evidence from such a proxy is integrity-verifiable but not provenance-pinnable across restarts. SeeDEPLOYMENT.mdΒ§2.
Provide it via AGA_GATEWAY_KEY, or AGA_GATEWAY_KEY_FILE (a path to the seed). In Claude Desktop, add an env block:
Keep the seed secret and out of version control; see DEPLOYMENT.md for key handling. A seed in an agent client's environment is not a separate trust domain, and the stdio upstream can inherit the key-related variables (known issue 3). Same-key restarts do not preserve the in-memory ledger: export and verify before stopping.
| Category | Tools |
|---|---|
| Identity | get_server_info, get_portal_state |
| Lifecycle | init_chain, attest_subject, revoke_artifact |
| Measurement & decision | measure_integrity, measure_behavior, verify_chain |
| Evidence | generate_evidence_bundle, verify_bundle_offline |
| Privacy | request_claim, list_claims |
| Delegation | delegate_to_subagent |
| Audit | get_receipts, get_chain_events |
measure_behavioris detective-only by default: it observes tool-usage patterns and records a signed, provable drift finding, but does not block. Enforcement (drift β quarantine) is opt-in viaenforce=trueand off by default. Hard governance decisions (PERMITTED/DENIED) are made by the portal/PEP, not the behavioral monitor.
A bundle this package emits (via the generate_evidence_bundle MCP tool) is a canonical SEP bundle. Verify it offline, with no network and no callback to us:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/aga-mcp-server)<a href="https://allmcps.com/mcp/aga-mcp-server"><img src="https://allmcps.com/api/badge/aga-mcp-server?style=directory" alt="Aga MCP Server on AllMCPs" /></a>