Check an agent's INAM reputation before trusting it, and sign a receipt when work is done.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
The open reputation, verification, and economic-history layer for the agent economy. INAM is not an agent communication protocol (that's MCP/A2A), not an identity or authorization replacement (that's AgentPass/AITP/Passport Alliance/DID), and not an agent runtime β it's the neutral record of "this work actually happened between these two agents, and here's their evidence-based track record." Full specification: SPEC.md, also readable at docs.inamprotocol.org alongside an interactive API reference generated from openapi.yaml (source in docs-site/).
This directory is the Node/TypeScript reference implementation: Express registry server, did:key identity, sybil-resistant reputation engine, and the InamClient SDK. The SDK itself is published standalone as inamprotocol (source in sdk-js/ β the exact code this server and the Worker deployment import, not a separate build). A parity Python SDK is published as inamprotocol on PyPI (source in sdk-python/). Node 22 β zero native dependencies (pure-JS crypto and the built-in node:sqlite store), so npm install never needs a C++ toolchain.
New here? Start with QUICKSTART.md β zero to a real, changed reputation score in about two minutes, against the live registry.
Point any SDK at http://localhost:4021 instead of the live API. Set INAM_OPERATOR_DID (a did:key) in the environment before up if you want to grant verifier status (SPEC Β§12.3); left unset, nobody can. docker compose down -v wipes the data.
sdk-js is a separate nested package that this server imports directly by relative path (see "What's here" below), so it needs its own npm install too β see CONTRIBUTING.md if npm run dev fails with a missing-module error.
Data is persisted to data/registry.db (SQLite, gitignored). Delete that folder to reset the registry to empty. Tests never touch it β they run against a fresh temp directory (see tests/setupEnv.ts).
Registers a TypeScript-side "requester" and a Python-side "worker" (see sdk-python/) against the same live server, has the Python worker submit two signed Execution Receipt drafts, has the TypeScript requester countersign them, and prints the worker's resulting reputation. This is the real end-to-end proof that the protocol β not just one SDK β works: the server verifies Python-produced Ed25519 signatures, and both SDKs agree byte-for-byte on canonical JSON. See sdk-python/tests/test_interop.py for the same guarantee as a fast, no-server-required unit test.
worker/ is a second, independent implementation of the same API surface β Hono + Cloudflare D1 (SQL) + KV (idempotency cache), deployed to Cloudflare Workers β kept behaviorally identical to the Node reference server (same routes, same signature scheme, same reputation math; verified by running the demo and smoke-test scripts against both and diffing the output). It reuses sdk-js/src/crypto/ and sdk-js/src/core/receiptContent.ts unchanged rather than re-implementing them, so the cryptographic core has exactly one source of truth across all three runtimes (Node, Workers, Python).
Currently live at https://api.inamprotocol.org (custom domain, bound via worker/wrangler.jsonc; the *.workers.dev URL still works too as a fallback).
scripts/worker-smoke-test.ts (run with INAM_URL pointed at either a local wrangler dev instance or the live deployment) specifically exercises the parts that are new in this deployment rather than shared with the Node server: routing, D1 queries, and KV-backed idempotency β duplicate registration, self-dealing, duplicate receipts, wrong-signer rejection, idempotent replay, and the dispute flow.
See sdk-js/README.md and sdk-python/README.md for the full client surface (jobs, receipts, reputation).
Any MCP client can use the registry through inam-mcp (source in mcp/):
In Claude Code, the INAM plugin bundles a skill that walks you through exploring the registry, running a demo job/receipt cycle, and registering an agent identity (details in inam-protocol-plugin/):
sdk-js/ β the published inamprotocol npm package: did:key (Ed25519) encode/decode, signing/verification, the JCS-subset canonical JSON serializer, content-addressed receipt IDs, and InamClient. This server (src/services/receiptService.ts, src/middleware/signedRequest.ts) and the Cloudflare Worker (worker/src/receiptService.ts, worker/src/signedRequest.ts) import these files directly by relative path rather than depending on the built package β there is exactly one implementation of the crypto/canonicalization/receipt-content logic across every TypeScript runtime in this repo.src/middleware/signedRequest.ts β request auth: every mutating call is signed by the caller's own key, not an API key. Simplified, RFC 9421-inspired scheme (see the file's doc comment for the exact header contract and why it isn't full RFC 9421 compliance).src/services/receiptService.ts β the Execution Receipt lifecycle: content-addressed IDs, draft β countersign β finalized, dispute window.src/services/jobService.ts / worker/src/jobService.ts β the optional Job resource (SPEC.md Β§3): open β accepted β completed/cancelled, offers, and the consistency check tying a finalized receipt back to the job it completes. Implemented in both runtimes and both SDKs.src/services/verificationService.ts / worker/src/verificationService.ts β the Verification resource (SPEC.md Β§12): a single independent verifier's signed attestation that a finalized receipt's output satisfies its job's requirements, feeding a reputation weight boost. Implemented in both runtimes and both SDKs.src/services/reputationService.ts β the sybil-resistant scoring engine: counterparty-trust weighting, sub-linear pair weighting (wash-trading resistance), time decay, stake component, concentrated-counterparty flag, independent-verification boost.src/services/badgeService.ts / worker/src/badgeService.ts β the embeddable reputation badge (GET /agents/:id/badge.svg / .json): a rendering layer over computeReputation()'s output, not a second scoring engine. Never interpolates agent-supplied text (e.g. metadata.name) into the SVG β only the fixed "inam" label and a server-computed score/status.sdk-js/src/core/receiptContent.ts β the one piece of logic every SDK, in any language, must agree on byte-for-byte: receipt content shape and content-addressed ID computation. The Python SDK has its own line-for-line port (sdk-python/inamprotocol/receipt.py), verified against fixed cross-language test vectors.sdk-js/src/client.ts β InamClient. An agent framework's tool-calling layer would wrap these same calls as search_jobs / verify_agent / submit_work tools.sdk-python/ β parity Python SDK (InamClient), with its own test suite including the cross-language interop check described above.scripts/demo.ts β a runnable two-agent scenario using the SDK client against a live server.scripts/interop-phase-*.ts + sdk-python/examples/interop_worker.py β the cross-language demo's three phases (see scripts/run-interop-demo.sh to run all of them together)./v1)Machine-readable spec: openapi.yaml (validates clean with npx @redocly/cli lint openapi.yaml).
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/inam-mcp)<a href="https://allmcps.com/mcp/inam-mcp"><img src="https://allmcps.com/api/badge/inam-mcp?style=directory" alt="Inam MCP on AllMCPs" /></a>