Server data from the Official MCP Registry
Verify a photo's capture time and provenance: C2PA validation, EXIF/XMP, and pixel forensics.
About
Verify a photo's capture time and provenance: C2PA validation, EXIF/XMP, and pixel forensics.
Security Report
This is a well-structured MCP server for image provenance verification with proper authentication design and secure credential handling. The code uses environment variables for API key storage, validates input parameters correctly, and makes appropriate external API calls. No malicious patterns, code execution vulnerabilities, or credential leaks were found. Permissions align well with the server's stated purpose of verifying images via the ChronoVerify API. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
3 files analyzed · 5 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: CHRONOVERIFY_API_KEY
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-beeswaxpat-chronoverify": {
"env": {
"CHRONOVERIFY_API_KEY": "your-chronoverify-api-key-here"
},
"args": [
"-y",
"chronoverify-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
chronoverify-mcp
An MCP server for ChronoVerify. It gives any MCP-compatible AI agent (Claude Desktop, Cursor, Cline, VS Code, and others) the tools to check a photo's capture time and provenance: C2PA Content Credentials, EXIF and XMP metadata, and classical pixel forensics, fused into one verdict (provenance_confirmed, consistent, inconclusive, metadata_anomaly, or manipulation_indicated) with a 0 to 100 confidence.
Provenance-first, not a deepfake or AI-generation detector. Results are investigative triage to support human review, not proof.
ChronoVerify is a C2PA Conformant Validator, listed on the C2PA Conforming Products List (record 019f8a20-6452-7a43-b11b-59d0b0e4a84a; validation of JPEG, PNG, WebP, and AVIF). Details: https://chronoverify.com/compliance#conformance
Source and issues: github.com/beeswaxpat/chronoverify-mcp
Listed on Smithery: https://smithery.ai/servers/beeswaxpat/chronoverify-mcp
Get an API key (the first 100 verifications each month are included): https://chronoverify.com/pricing . Without a key,
verify_imageuses the free, rate-limited public path. A signed report requires a key.
Install
Add it to your MCP client config. For Claude Desktop (claude_desktop_config.json) or any MCP client:
{
"mcpServers": {
"chronoverify": {
"command": "npx",
"args": ["-y", "chronoverify-mcp"],
"env": { "CHRONOVERIFY_API_KEY": "cv_live_..." }
}
}
}
Omit the env block to use the free public path (verification only; signed reports always need a key).
Tools
verify_image
Verify a photo's capture time and provenance. Takes exactly one of:
url: a publicly reachable image URL (the server fetches it),file_path: an absolute path to a local image, orimage_base64: base64-encoded image bytes.
Optionally set permalink: true to also store the verdict (never the image) and get back an unlisted, shareable link to it in the permalink field, for citing the result to people or in reports. Keyless links expire after 90 days; links minted with an API key do not expire.
It returns a human-readable summary and a typed structured object so an agent can branch on the result without parsing prose:
{
"schema_version": "v1",
"verdict": "consistent",
"confidence": 58,
"headline": "Metadata is internally consistent. No manipulation signals fired.",
"summary": "...",
"capture_time": { "value": "2026-03-14T09:21:30", "source": "exif", "consistent": null },
"capture_device": { "make": "Canon", "model": "EOS R6", "software": "Firmware 1.8.1" },
"capture_location": { "present": false, "place": null },
"c2pa": {
"present": false,
"validated": null,
"validation_state": null,
"signature_valid": null,
"trust_list_match": null,
"signer": null
},
"integrity": {
"sha256": "1313339a...",
"sha512": "93a81e4a...",
"format": "JPEG",
"width": 1200,
"height": 800,
"c2pa_validator_enabled": true
},
"permalink": null,
"limits": "ChronoVerify returns investigative triage, not proof.",
"source": "ChronoVerify (https://chronoverify.com)"
}
The verdict enum:
provenance_confirmed: a trusted C2PA Content Credential validated against the official trust list.consistent: metadata holds up and no manipulation signal fired (consistent with an unedited capture, not proof).inconclusive: not enough signal to decide.metadata_anomaly: the metadata contradicts itself.manipulation_indicated: pixel forensics flagged possible editing for human review.
get_signed_report
Generate a signed PDF audit report for one image: the chain-of-custody / compliance record (for example an EU AI Act Article 50 transparency record, an insurance or legal evidence file, or a newsroom audit trail). Takes one of file_path or image_base64 (this endpoint does not fetch URLs) and an optional out_path. Writes the PDF and returns the path. Requires CHRONOVERIFY_API_KEY; metered as a premium report unit. The report carries an Ed25519 signature you can verify against the public key at https://chronoverify.com/v1/key.
Example prompts
- "Verify the provenance of /Users/me/Downloads/photo.jpg"
- "When was the photo at this URL taken, and has it been edited? https://example.com/photo.jpg"
- "Validate the C2PA Content Credentials on this image and tell me the signer."
- "Verify this photo and give me a shareable link to the verdict."
- "Generate a signed provenance report for ./evidence/claim-001.jpg and save it to ./reports/"
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
