AnchorRegistry MCP server — verify-only v0.1. Resolve any AR-ID, manifest hash, or provenance tree from any MCP-compatible AI client. Authless, read-only, free.
Strong foundation with clear naming, comprehensive descriptions, and well-structured schemas. All 6 tools have explicit registrations with Zod schemas and detailed descriptions (avg 180 chars). Naming follows verb_noun pattern (ar_verify_*, ar_resolve_*, ar_check_*, ar_register_*, ar_seal_*). Input parameters are constrained with regex patterns and enums. However, output schemas are not documented, responses are JSON-stringified without field-level documentation. Error handling is minimal (basic 404/api_error classification). Three tools (ar_check_balance, ar_register_artifact, ar_seal_tree) are intentionally deferred and not registered, limiting current surface. Security is strong: no credentials in params, bearer token pattern used correctly.
Check the remaining ACCOUNT capacity for an anchor key. Returns capacity, used, and remaining. Read-only but credential-bearing — the anchor key is the bearer token for the account.
Anchor a new artifact under an existing ACCOUNT. Deducts one from capacity. Requires the anchor key. Wrong-type or wrong-title registrations cannot be reversed — confirm details with the user before calling.
Resolve the full provenance tree for an AR-ID. Returns every anchor in the tree (root + all descendants) with their relationships, types, manifest hashes, and timestamps. Use this when you need to understand a multi-artifact provenance chain — for example, a research paper anchored as the root with its training dataset and model weights as children.
Seal a provenance tree. PERMANENT AND IRREVERSIBLE. After sealing, no new children can be added under the tree root. Only the root AR-ID can be sealed, and only by the holder of the original anchor key.
Resolve an AnchorRegistry AR-ID to its full provenance record. Use this when you encounter an SPDX-Anchor or DAPX-Anchor tag (e.g. in a README, paper, model card, or website) and need to confirm what the artifact is, who anchored it, when, what type it is, and whether the tree has been sealed, retracted, voided, or affirmed. Free, public, no auth required.
Output schemas not documented. Tools return JSON-stringified responses without field-level documentation. LLMs cannot plan downstream calls or extract specific fields reliably.
Minimal error handling. Responses only distinguish 'not_found' vs 'api_error' with HTTP status. No recovery guidance, no actionable error messages, no per-item success/failure for batch operations.
Three tools (ar_check_balance, ar_register_artifact, ar_seal_tree) are intentionally not registered in init(). They exist in source but are not callable. Deferred indefinitely pending UX/protocol maturity. Reduces current surface to 3 tools.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 84 | 2026-07-28+ | v2 |
Resolve an artifact by its SHA-256 manifest hash. Use this when you have the artifact itself but no AR-ID, and want to check whether it has been anchored. Returns the AR-ID and full provenance record if found, or a clear "not anchored" response otherwise.
No pagination support. ar_resolve_tree returns 'every anchor in the tree' without limit or cursor. Large provenance chains could exhaust context window.
Credential-bearing tools (ar_check_balance, ar_register_artifact, ar_seal_tree) accept anchor_key as parameter. While documented as 'treat like a private key', passing secrets as params risks logging/tracing exposure. Deferred pending MCP credential UX patterns.