Decide by policy, gate behind a human, verify by read-back, record a hash-chained ledger.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Decide → Gate → Verify → Attest. Your agent sends the email, updates the CRM, moves the money. Attest decides whether it may, gates it behind a human when it matters, reads back from the system of record to check it actually happened, and records tamper-evident evidence either way.
Attest never executes your action. Your tool does. That is why it works with any app and any framework on day one.
Two identical CRM writes, both reported success by the tool, both approved by a human:
The second one read back clean. The first did not, and the ledger says which field disagreed:
A trace would have shown two green steps. That gap is the entire product.
That is the whole change. The first external send now pauses for a human, and the ledger row says
acknowledged, or verified once Attest can read back with the agent's own credentials
(Attest(readers={"gmail": service})). Nothing else in your code moves.
Every row states exactly how much was checked. A check that could not run is never dressed up as a pass.
| level | what it means |
|---|---|
verified | read back from the system of record, and the fields matched |
verified-custom | your own check ran and passed |
acknowledged | the action was accepted, but no read-back could run here |
attested-only | recorded with no verifier available for this action |
unverified | a check ran and contradicted the claim |
Only a contradiction earns unverified. Missing credentials, a read-only scope or an unsupported verb
degrade to acknowledged, because "we could not check" and "it did not happen" are different facts.
| surface | how |
|---|---|
| Decorator / wrapper | @attest.action(...) · at.wrap(...) |
| LangGraph | tool node wrapper, gate as a graph interrupt |
| OpenAI Agents · Claude Agent SDK · CrewAI · DeerFlow | adapters in attest/ |
| MCP | zero-code proxy in front of any server, plus a verify server |
| HTTP gateway | point outbound traffic at it, no SDK at all |
| API only | POST the descriptor yourself |
Human confirmation lands where the team already works: Slack, the web inbox, a webhook, a LangGraph interrupt, or the console. Approvers can edit the parameters before approving, and the edit is recorded.
Hash-chained ledger, SQLite locally and Postgres per organisation in the cloud. Signed checkpoints let
you prune old rows and still verify the chain. Optional Ed25519 signing, and external anchoring to a
file, a git repo or an HTTP endpoint. Exports: JSON, CSV, the IETF draft-sharif-agent-audit-trail
JSONL format, and an EU AI Act event-log pack.
Overhead is roughly a sixth of a millisecond per action, measured in benchmarks/ (published numbers).
The SDK is MIT and works standalone with a local ledger. Attest Cloud adds the shared ledger, the
confirm inbox, versioned org policy, agent keys and compliance exports. Your vendor tokens never reach
it: read-back happens in your process with your own credentials, and only hashes and previews are sent.
Self-host it from deploy/, or read DEPLOY.md.
| where | how |
|---|---|
| PyPI | pip install attestlayer → attest, attest-mcp, attest-mcp-server, attest-gateway |
| npm | npm install attestlayer |
| MCP Registry | io.github.dev-prathap/attest (verify server) · io.github.dev-prathap/attest-proxy (zero-code proxy) |
| Smithery | attestlayer/attest |
| Claude Desktop | attest-<version>.mcpb on the latest release |
| Docker | ghcr.io/dev-prathap/attest-api · ghcr.io/dev-prathap/attest-dashboard |
Full docs at dev-prathap.github.io/ATTEST — quickstart · verification levels · policy · read-back recipes · ledger & exports · hardening
| path | what |
|---|---|
| attest/ | Python SDK — descriptor, policy, ledger, verification ladder, gates, adapters, MCP proxy, CLI |
| packages/attest-ts/ | TypeScript SDK — same canonical hashes, fixture-tested against Python |
| cloud/ | Attest Cloud — FastAPI + Postgres: orgs, keys, policy versions, ledger, confirm inbox, exports |
| dashboard/ | Next.js dashboard — ledger drill-down, confirm inbox, policy and keys |
| examples/ | unknown app, LangGraph, OpenAI Agents, MCP config, API-only, cloud |
| deploy/ | Dockerfiles and compose |
| benchmarks/ | what the layer costs per action |
| docs/ | documentation site source, plus design notes |
Read-back recipes are the easiest place to start: each one teaches Attest how to confirm a write in one more app, and needs nothing but that app's read API. See CONTRIBUTING.md, and SECURITY.md for reporting a vulnerability.
The thinking behind the product, kept in the open: vision · product · universal adapter · architecture · market · build plan · decisions · phase plan
Attest's core mechanisms are extracted from two working codebases: DO (policy engine, read-back
verification pairs, evidence ledger) and DeerFlow (tool receipts, verification patterns, MCP and
chat-channel adapters), which run against real Gmail, Slack, HubSpot, Notion, Linear and Google
Workspace. Attest ships its own live suites for those systems in tests/live/; they
need real credentials and are skipped without them.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/attest-2)<a href="https://allmcps.com/mcp/attest-2"><img src="https://allmcps.com/api/badge/attest-2?style=directory" alt="Attest on AllMCPs" /></a>