Back to Browse

Agenttrust MCP Server

by Bch1212
Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Trust scores & reputation for the agent-to-agent economy. Verify A2A counterparties.

About

Trust scores & reputation for the agent-to-agent economy. Verify A2A counterparties.

Security Report

4.2
Use Caution4.2High Risk

AgentTrust MCP is a well-structured reputation system for agent-to-agent transactions with proper authentication boundaries (read tools public, write tools require API keys, admin operations require admin keys). The codebase demonstrates good security hygiene with input validation, parameterized queries, and transaction management. However, there are moderate concerns around API key management practices, insufficient logging of security events, and a dependency on environment variable-based credential handling that could be more robust. Supply chain analysis found 8 known vulnerabilities in dependencies (1 critical, 5 high severity). Package verification found 1 issue.

7 files analyzed · 18 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

database

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

API key for write operations. Reads are public. Free tier: 100 writes/day.Required

Environment variable: AGENTTRUST_API_KEY

Override the API base URL for self-hosted deployments.Optional

Environment variable: AGENTTRUST_API_BASE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-bch1212-agenttrust": {
      "env": {
        "AGENTTRUST_API_KEY": "your-agenttrust-api-key-here",
        "AGENTTRUST_API_BASE": "your-agenttrust-api-base-here"
      },
      "args": [
        "-y",
        "agenttrust-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

AgentTrust MCP

The trust layer for the A2A economy. A first-mover credit-bureau-style reputation infrastructure for AI agents.

As agent-to-agent commerce scales toward $450B by 2028, agents need a way to verify counterparties before transacting — payments, data brokerage, scraping, research, anything paid. AgentTrust gives every agent a portable identity, a 0–1000 trust score, an immutable transaction history, and peer endorsements. Other agents query it; humans verify it; disputes erode it.

Twelve MCP tools, one SQLite store, zero external dependencies. Drop-in compatible with the Anthropic MCP protocol.


Install

claude mcp add agenttrust-mcp --url https://mcp-agenttrust.up.railway.app/mcp

Or run locally:

git clone <this repo> && cd mcp-agenttrust
pip install -r requirements.txt
python -m uvicorn server:app --reload

Open http://localhost:8000/ for the service banner, /health for liveness, /docs for the OpenAPI explorer.


MCPize Listing Copy

AgentTrust — Reputation infrastructure for the A2A economy.

Before your agent wires money, hands over data, or accepts a job from another agent, ask AgentTrust who they're dealing with. Every counterparty gets a 0–1000 trust score that combines transaction history, success rate, account age, peer endorsements, and dispute record — recomputed live. Free for read calls; $9/mo unlimited writes.

First-mover infrastructure for a $450B market: as A2A commerce scales, every agent needs a counterparty-check tool. Twelve MCP tools cover the full lifecycle — register, transact, dispute, endorse, verify, search, and rank. SQLite-backed, async, deployable in one click on Railway. Built for agents that need to know before they trust.


Pricing

TierLimitPrice
Free100 write calls/day$0
ProUnlimited writes$9/mo
Pay-per-call$0.001 / write callmetered

All read tools (get_*, search_*, get_leaderboard) are public — no API key required.


Trust Tiers

TierScore rangePlain English
PLATINUM800–1000Long history, near-perfect success rate, verified, endorsed
GOLD550–799Established, mostly clean, decent volume
SILVER300–549Mid-pack, modest volume, no major disputes
BRONZE100–299Junior, small footprint, untested at scale
NEW0–99Fresh registration — transact at your own risk

Trust Score Algorithm (plain English)

Every score is recomputed live on read — no stale cache. Six independent signals combine into a number between 0 and 1000:

Volume (0–200, log scale). A first transaction is worth ~12 points; ten transactions ~40; a hundred ~80; a thousand caps at 200. We use a log curve so high-volume agents don't dwarf legitimate small ones — being active matters, but not exponentially.

Success rate (0–400, the heaviest signal). The percentage of transactions marked successful, multiplied by 400. A 99% success rate is worth 396 points; a 50% rate is only 200. This is the single most important factor — agents that ship reliably climb fastest.

Age (0–100, capped at one year). Each day since registration adds about a quarter of a point, maxing out at 365 days. Not a huge factor, but real: a one-day-old agent with five great transactions is still less trustworthy than a one-year-old agent with the same record.

Endorsements (0–200). Every peer endorsement (quality / reliability / speed / domain expertise) is worth 10 points, capped at 200. This is the social signal — other agents and operators vouching for this one.

Disputes (unbounded penalty). Each upheld dispute against the agent removes 30 points, with no floor below zero. A bad actor can score 1000 from the other categories and still bottom out at 0 from disputes alone.

Verification bonus (+100). A one-time bump when an operator verifies the agent (DNS proof, KYC, or platform-specific check). It's worth roughly the same as 10 endorsements — meaningful, not decisive.

The score then clamps to [0, 1000] and maps to a tier. Recompute happens on every transaction, endorsement, dispute resolution, and verification — so the score is never more than one event behind reality.


MCP Tools

ToolAuthWhat it does
register_agentAPI keyMints an agent_id + agent_token. NEW tier, score 0.
get_agent_profilepublicFull profile + live trust score, tier, stats.
get_trust_scorepublicScore, tier, and per-category breakdown.
record_transactionAPI keyLogs a transaction (success or failure); recomputes both sides.
dispute_transactionAPI keyFile a dispute. Reporter must be a counterparty.
resolve_disputeadmin keyResolve in favor of reporter / respondent / invalid.
endorse_agentAPI keyEndorse another agent (quality / reliability / speed / domain).
get_transaction_historypublicPaginated transaction list, most recent first.
search_agentspublicFilter by capability, min score, verified flag.
verify_agentadmin keyOperator verification → +100 score bonus.
get_leaderboardpublicTop-N agents, optionally filtered by capability.
report_agentAPI keyFile an out-of-band abuse report (separate from a tx dispute).

Demo Data

On startup, five seed agents land in the DB at different tiers — demo-platinum-001 (AlphaAgent), demo-gold-001 (BetaAgent), demo-silver-001 (GammaAgent), demo-bronze-001 (DeltaAgent), demo-new-001 (EpsilonAgent). Use them for quickstart demos.


Quickstart Calls

# Public read — no key needed
curl -s http://localhost:8000/tools/get_leaderboard \
  -H 'content-type: application/json' \
  -d '{"limit": 5}' | jq .

# Register a new agent
curl -s http://localhost:8000/tools/register_agent \
  -H 'content-type: application/json' \
  -H 'x-api-key: agenttrust-dev-key-001' \
  -d '{"agent_id":"my-agent","name":"My Agent","capabilities":["search","rag"]}' | jq .

# Record a successful transaction
curl -s http://localhost:8000/tools/record_transaction \
  -H 'content-type: application/json' \
  -H 'x-api-key: agenttrust-dev-key-001' \
  -d '{"from_agent":"my-agent","to_agent":"demo-platinum-001","amount_usd":42.0,"success":true,"description":"data lookup"}' | jq .

JSON-RPC MCP Transport

POST /mcp speaks the standard MCP JSON-RPC dialect:

{"jsonrpc":"2.0","id":1,"method":"tools/list"}
{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_trust_score","arguments":{"agent_id":"demo-gold-001"}}}

tools/call results return as {"content":[{"type":"text","text":"<JSON>"}],"isError":<bool>}.


Tests

pytest -v

34 tests covering: HTTP surface (16), trust-score edge cases (18). Specific edge cases included: zero-transaction agents, 100% dispute rate, max-endorsement cap, failure rates that erode score, score-bounded between 0 and 1000.


Deploying to Railway

./deploy.sh

Reads the project's RAILWAY_TOKEN from ~/Projects/agentic-builds/Build Prompts from OpenClaw/.deploy-secrets.env, provisions the service via nixpacks, sets env vars, and prints the public URL.


License

MIT.

Reviews

No reviews yet

Be the first to review this server!

Agenttrust MCP Server - Trust scores & reputation for the agent-to-agent economy. | MCP Marketplace