Self-hosted signing wallet: DIDs, agency grants, and task mandates for AI agents.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Sovereign-identity wallet as an MCP server. Gives any MCP-capable agent a DID, owner→agent grants, and task mandates — the identity layer underneath AWAS website authentication.
Protocol: TamTunnel/sovereign-identity — DIDs, agency grants, task mandates, and the AWAS website binding this wallet implements.
Version: 0.1.0 · License: Apache-2.0
| Tool | What it does |
|---|---|
wallet_onboard | Create the owner/agent identity (returns existing if present) |
wallet_did | Get the DID for a role |
issue_grant | Owner delegates scopes + USD limit to an agent DID |
mint_mandate | Agent mints a task mandate for a website audience (returns Authorization: Mandate … value). Pass subjectDid to delegate to a downstream agent with narrowed scope/amount |
verify_mandate | Website-side verification: signatures, expiry, audience, replay, grant binding, scope/amount confinement |
verify_chain | Website-side verification of a multi-hop delegation chain (Owner → … → agent): per-hop signatures, binding, attenuation, replay |
pairwise_did | Fresh pairwise DID per audience (no cross-site correlation) |
Guardrails are enforced server-side: mandates over $100 need
confirmOverLimit=true (only after the owner explicitly approved), and the
verifier rejects non-canonical base64url outright.
State lives in ~/.sov-id (override with SI_WALLET_DIR). Keys are
scrypt + AES-256-GCM encrypted at rest, files mode 600.
Add to the client's MCP config:
Muse custom connectors reach remote MCP servers over streamable HTTP — a server on your laptop is not reachable from Meta's cloud. Run:
Expose it on a public HTTPS URL (your VPS, fly.io, Tailscale, …), then add
that URL as a custom connector in Muse with Authorization: Bearer <token>.
The server binds 127.0.0.1 by default; only set SI_MCP_HOST=0.0.0.0
behind TLS. Full walkthrough: DEPLOY.md.
See DEPLOY.md for fly.io, Tailscale, TLS, onboarding, backups, and connecting Meta Muse.
examples/delegation-chain/ is a runnable proof that mandates compose
across agents and frameworks with no pair-specific connectors: the owner
grants Muse broad authority, Muse delegates a narrowed envelope to Hermes,
Hermes presents the leaf mandate to a website, and the website verifies the
whole attenuated chain. Four attacks (scope escalation, amount escalation,
tampering, replay) are attempted and refused.
Each user hosts their own. That is the point. A wallet holds private keys, so there is no shared hosted instance — that would be custodial and would contradict the "sovereign" in sovereign identity.
verify_mandate without the replay ledger)
is the only piece that could ever be shared, and even that is safer local.Whoever can reach the server can ask it to sign. Treat the bearer token like a password and never expose the HTTP port without TLS.
SI_MCP_TOKEN; every request needs
Authorization: Bearer <token> (401 otherwise).No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/sovereign-identity-wallet)<a href="https://allmcps.com/mcp/sovereign-identity-wallet"><img src="https://allmcps.com/api/badge/sovereign-identity-wallet?style=directory" alt="Sovereign Identity Wallet on AllMCPs" /></a>