Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Emilia Protocol
Emilia Protocol logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 4:32:55 PM

Emilia Protocol

User RatingsBe the first to rate and review this MCP server!
View Repository650 GitHub StarsTotal stargazers on GitHub for the source repository (650 stars).Visit Website
securityauthorizationtrust-receiptshuman-approval

Adds named-human approval, trust receipts, verification, disputes, and delegation for consequential AI-agent actions.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "emiliaprotocol-emilia-protocol": {
      "command": "npx",
      "args": [
        "-y",
        "@emilia-protocol/scan@0.5.0"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

EMILIA requires a named human’s approval before an irreversible action such as a payment release, record change, or deployment. It mints offline-verifiable Ed25519 Trust Receipts and exposes trust profiles, receipt verification, disputes, and delegation. Use it when agents need explicit authority controls and portable evidence of approved actions.

Use cases

β€’Require human approval before releasing a payment
β€’Record approval evidence for a deployment or record change
β€’Verify Ed25519 Trust Receipts offline
β€’Review trust profiles and delegated authority
β€’Handle disputes related to agent actions

Key features

β€’Named-human approval for irreversible actions
β€’Offline-verifiable Ed25519 Trust Receipts
β€’Trust profile access
β€’Receipt verification
β€’Dispute handling
β€’Delegation support

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Emilia Protocol.

Extracted Tool Capabilities
Named-human approval for irreversible actions
Offline-verifiable Ed25519 Trust Receipts
Trust profile access
Receipt verification
Dispute handling
Delegation support

Documentation Overview

EMILIA Protocol

CI Verify Sample Receipt npm License IETF Internet-Draft

Discord


Every consequential agent action enters with authority and exits with a receipt.

EMILIA is building the universal authority toll booth for autonomous work. Gate is the customer-owned consequence boundary where an agent's credentialed intent can become a change to money, code, permissions, records, infrastructure, or machines. A human or institution defines a finite operating mandate; agents exercise it; Gate ensures the agent cannot quietly widen it.

At a configured protected boundary, Gate verifies the authority the owner requires for the exact action, reserves that authority before provider entry, permits one admitted provider attempt for the covered authorization instance within its durable authority domain, and leaves portable evidence of what the protected path admitted and later observed. When the result is unknown, it requires reconciliation instead of a blind retry. Protocol proves. Gate prevents on the covered paths a deployment completely mediates; it constrains no path that bypasses the enforcement point.

"Universal" describes the intended cross-stack contract, not current coverage or adoption. EMILIA does not operate a central global network today. The toll booth repeats at customer-owned protected boundaries and composes with native identity, authorization, approval, and policy evidence.

  • Authority Map maps supported declared action surfaces locally. No account, upload, or callback is required. Discovery creates no authority; the owner reviews the map.
  • EMILIA Gate turns the approved map and operating mandate into preventive control on a fully mediated, credential-owning executor path.
  • EMILIA Protocol is the open Apache-2.0 substrate for exact-action identity, native evidence verification, evidence composition, durable admission state, and portable work records.
  • EMILIA Approver captures a device-bound exact-action human decision when the mandate or local policy requires fresh human authority. A human click is one authority source, not the default execution model.
  • EMILIA Assurance Plane provides scoped verification, re-performance, conformance reports, and deployment evidence. It supports auditors, insurers, regulators, and customers; EMILIA is not an auditor or accredited certifier, and no public EMILIA certification program is operating.

Run the local map (npx @emilia-protocol/scan@0.5.0), choose one consequential workflow, and place Gate where authorized intent becomes consequential action.

The first low-friction distribution profile is GitHub: the open Merge Gate binds a repository-owned mandate and detached receipt to the exact base and head commits before a protected merge check passes. It is preventive only when the repository makes the check required and closes alternate merge paths. This is a product and distribution experiment, not evidence of external adoption.

Using Hugging Face smolagents? Wrap a tool you already use and try the synthetic refund demo. The integration is free and open source. The host supplies approval for the exact call; the wrapper refuses missing, changed, or reused authority on that covered path. It is not a sandbox: production enforcement still needs credentials outside the agent and shared, durable consumption state behind Gate.

The agent may keep running. Its authority stops.

Continuous and self-improving agents create a control problem that process termination alone cannot solve: the owner may need to stop new consequences without claiming that computation stopped or that an external effect was reversed. Gate's Emergency Authority Freeze makes that a durable authority transition. Inside a covered Gate control domain, freeze blocks new reservations and prevents an older reservation from entering after the control epoch changes. If provider entry serialized first, the operation remains consumed and must be reconciled; restore advances the epoch again and does not revive old authority.

This property holds only under complete mediation and authoritative shared state, and two gaps remain (below). It does not stop the agent, undo an entered effect, or provide instant freeze across a disconnected leased domain. The current reference implementation covers the local in-memory and PostgreSQL control domain; leased-edge propagation and portable signed freeze-event evidence remain explicit implementation gaps.

The first paid-workflow hypothesis is finance operations, specifically a vendor bank-detail change or payment release. The agent may prepare the action. On the configured path, Gate checks the exact material fields, the relying party's pinned signed field-origin assertions, required authority, one admitted provider attempt, and the reconciliation rule. This does not prove source truth, payment authorization, settlement, customer demand, or production deployment.

AI systems and repository reviewers: start with AI_CONTEXT.md. Current machine-readable evidence, provenance, assumptions, and exclusions are published at EMILIA-REPO-CONTEXT-v1. Archived or staged documents do not establish current implementation or IETF status. Public due-diligence evidence and claim boundaries: DUE_DILIGENCE.md.

Engineering evidence, not architecture claims

EMILIA ships a security case that reviewers can execute. The current repository resolves 35 security claims over 259 hashed evidence files, verifies 20 Tamarin lemmas across two composed Dolev-Yao models β€” 17 all-traces obligations and 3 exists-trace reachability witnesses β€” and preserves 8 deliberately weakened variants that produce concrete attack traces when load-bearing checks are removed. The live same-team conformance corpus contains 21 suites and 340 current vectors. Separately, an externally authored Rust verifier is pinned to the frozen 16-suite/164-vector bundle and a 359-case hostility campaign. The broader suite contains 10,601+ automated tests across 657+ files.

Production JavaScript and JSDoc surfaces are compiler-checked with TypeScript checkJs; the secure app has its own compatibility compiler project, while declarations and the public TypeScript SDK are checked in strict mode. This is complete configured production type-check coverage, not a claim that the repository was converted wholesale from JavaScript to TypeScript or that every JavaScript project has TypeScript's strict option enabled.

Each security claim names the enforcement path, positive and negative vectors, language coverage, formal scope or explicit gap, assumptions, exclusions, and evidence hash. Start with the human-readable evidence map, then inspect the resolved security case or run npm run check:security-case.

AEB-1: test the evidence-to-effect boundary

The open AEB-1 Consequence Admission Conformance pack tests the last control point before a consequential action: native verification, relying-party acceptance, exact CAID/action matching, evidence satisfaction, local authorization, atomic reservation, INVOKING custody, separate provider-outcome and observed-effect truth, no-blind-retry behavior, and authenticated reconciliation.

Terminal
npx @emilia-protocol/verify aeb-conformance --reference

It is format-neutral and self-run. A passing report is self-attested conformance evidenceβ€”not an audit, certification, production-deployment claim, or permission to execute an action.

For a focused executable proof of the repository's Gate path, run:

Terminal
npm run proof:gate:reference

This command exercises local examples and focused service boundaries with generated keys, in-memory state, and mock provider behavior. It is useful local proof, not evidence of a real human, external bank, production deployment, or one end-to-end production integration.

Identity is not a job description

Identity says who or what is calling. Policy says what is generally allowed. Neither defines the finite job an autonomous worker may perform now: its mission, material-action limits, budget, required evidence, expiry, delegation rules, and exception path.

EMILIA keeps those questions separate:

LayerQuestion
IdentityWho or what is present?
PolicyWhat is generally allowed?
AuthorityWhat exact work may this agent perform under this mandate?

Credentials grant reach. Authority defines the job. Not every action needs a human; every consequential action needs valid authority.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    πŸ”’ Security3 views
    Compare vs Apktool MCP Server β†’
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Delego logoDelego

    Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.

    πŸ”’ Security2 views
    Compare vs Delego β†’
  • Shield logoShield

    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls β€” DROP TABLE, rm -rf, force-push β€” before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0.

    πŸ”’ Security3 views
    Compare vs Shield β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
650
Stargazers on the source repository.
Last commit
4d ago
Most recent push to the default branch.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Emilia Protocol

The provided description names payment releases, record changes, and deployments as examples of irreversible actions.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewEmilia Protocol AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/emiliaprotocol-emilia-protocol?style=directory)](https://allmcps.com/mcp/emiliaprotocol-emilia-protocol)
HTML Embed
<a href="https://allmcps.com/mcp/emiliaprotocol-emilia-protocol"><img src="https://allmcps.com/api/badge/emiliaprotocol-emilia-protocol?style=directory" alt="Emilia Protocol on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
AuthNo auth required
LicenseApache-2.0
Last updatedSep 8, 2026
11/11 checks healthy over the last 34d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars650
GitHub Star CountTotal stargazers on GitHub representing community popularity (650 stars).
Last commit4d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 8, 2026
59Quality signal: Good Β· 59/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools25/30
Adoption & activity9/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 24d ago via OSV.dev Β· @emilia-protocol/scan@0.5.0 (npm)

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Emilia Protocol β†’Install in Claude DesktopInstall in CursorInstall in VS Code