Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. Developer Tools
  3. Verifa
  4. README

Verifa README

The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Verifa listing page.

Back to Verifa View source on GitHub

Verifa MCP Server

Run identity verification from any MCP client — Claude Desktop, Cursor, Claude Code, or your own agent. Create verification sessions, hand the person a capture link, screen against sanctions and PEP lists, read results, and work the review queue, all as tools an agent can call.

config.json
{
  "mcpServers": {
    "verifa": {
      "command": "npx",
      "args": ["-y", "@verifasolutionsinc/mcp-server"],
      "env": { "VERIFA_API_KEY": "vk_sandbox_...", "VERIFA_ENV": "sandbox" }
    }
  }
}

That is the whole install. Get a sandbox key at app.withverifa.com → Developers → API keys (free, no card, no sales call). Sandbox keys never touch real data and can simulate every verification outcome, so you can see the full lifecycle in a few minutes — examples/id-check does exactly that.

How it works

This package is deliberately small. It opens one authenticated connection to Verifa's hosted MCP endpoint (https://api.withverifa.com/mcp, streamable HTTP) and forwards tools/list, tools/call, prompts/list and prompts/get over stdio. Nothing is reimplemented here: tool schemas, PII scrubbing, rate limits and the audit trail all live server-side, so this wrapper never drifts from the product.

If your client already speaks streamable HTTP with OAuth 2.1, you can skip this package and connect to the hosted endpoint directly — same tools, sign-in instead of an API key.

Tools

The server exposes 45 tools, grouped into toolsets. By default you get everything except destructive.

ToolsetWhat an agent can do
sessionscreate_session, get_session, list_sessions, list_session_events, simulate_session (sandbox), reprocess_session
checkslist_checks, get_check, list_check_hits, rerun_check — sanctions, PEP, adverse media, watchlists
identitiessearch_identities, list_identities, get_identity, tag / untag
caseslist_cases, get_case, claim_case, assign_case, add_case_comment, approve_case, reject_case, escalate_case …
findingslist_findings, get_finding, acknowledge_finding, dismiss_finding
listsblocklist and custom list reads and writes
workflowslist_workflows, get_workflow, trigger_workflow, list_verification_policies
orgwhoami, get_usage_stats, list_org_users, list_api_keys
searchsearch / fetch for ChatGPT-style connectors
destructiveredact_session, redact_identity, bulk_redact_sessions, … — off unless you opt in

Every tool is scoped: the API key's scopes cap what the connection can do, whatever toolsets are enabled. Every call — read or write — writes an audit row that records it was made by an agent and by which key or OAuth client, so an agent's decision is never mistaken for a human's.

Narrowing the surface

Fewer tools means less context spent per request and better tool selection. Pick what the job needs:

json
"env": {
  "VERIFA_API_KEY": "vk_sandbox_...",
  "VERIFA_MCP_TOOLSETS": "sessions,checks",
  "VERIFA_MCP_READ_ONLY": "1"
}
VariableEffect
VERIFA_API_KEYRequired. vk_sandbox_… or vk_live_…. Publishable keys (vk_pub_…) are rejected.
VERIFA_ENVsandbox or live. Inferred from the key if omitted; must match it if set.
VERIFA_MCP_TOOLSETSComma-separated toolsets to expose. Default: all except destructive.
VERIFA_MCP_READ_ONLY1 hides every tool that writes.
VERIFA_MCP_ALLOW_DESTRUCTIVE1 adds the redaction tools. Each call also needs the redact:write scope, a written reason, and is capped at 5 per hour per key. Redaction is irreversible by design.
VERIFA_API_URLOverride the API host (e.g. a staging environment).

Check what a given configuration exposes without opening a client:

sh
VERIFA_API_KEY=vk_sandbox_... npx -y @verifasolutionsinc/mcp-server --check

Try it in five minutes

sh
git clone https://github.com/Verifa-Solutions/verifa-mcp-server
cd verifa-mcp-server/examples/id-check
npm install
cp .env.example .env        # paste your sandbox key
npm start                   # approve
npm run review              # the outcome that matters: a human has to decide

The demo creates a session, generates the one-time capture link and QR code an integrator would show, simulates an outcome (no passport needed — sandbox only), and reads the result. It prints the REST calls in one column and the identical flow driven through this MCP server in the other. Add --webhooks with a public URL (cloudflared tunnel --url http://localhost:8787 works) to receive the signed webhook deliveries and see signature verification — the part most integrations get wrong.

Development

Terminal
npm install
npm run build
npm test                                     # unit tests
VERIFA_API_KEY=vk_sandbox_... node dist/index.js --check   # live smoke test

Node 20+. Logs go to stderr; stdout is the MCP transport.

Security

  • Use sandbox keys while evaluating. Live keys should be scoped to the toolsets the agent needs.
  • The server never stores or logs the API key; it is sent only as a Bearer token to VERIFA_API_URL.
  • Responses are PII-free by default — the hosted server strips applicant identifiers from tool results unless the key holds the relevant scope and the session's sensitive-data window is open.
  • Report vulnerabilities via withverifa.com/security/disclosure.

License

MIT — see LICENSE.