Back to Browse

Agent Envelope MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Neutral MCP server for AgentEnvelope authority: sovereign verify + vault verify/lookup/mint.

About

Neutral MCP server for AgentEnvelope authority: sovereign verify + vault verify/lookup/mint.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

4 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Vault-issued API key. Required only for the vault-governed tools (ae_get_agent, ae_verify_action, ae_mint). Sovereign verification needs no key.Required

Environment variable: AE_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-blackboxengineering-agent-envelope-mcp": {
      "env": {
        "AE_API_KEY": "your-ae-api-key-here"
      },
      "args": [
        "-y",
        "agent-envelope-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

agent-envelope-mcp

The neutral authority layer for agent runtimes, as an MCP server.

Any MCP client — Claude, an OpenAI agent, LangChain, CrewAI, a custom runtime — can call these tools to check and issue agent authority without building its own policy engine, audit log, or verification stack. AgentEnvelope is owned by no framework, so every framework can embed it.

Run

npx agent-envelope-mcp

It speaks MCP over stdio. No API key is needed to start, or to use the sovereign verifier — only the vault-governed tools require AE_API_KEY.

Wire it into an MCP client

Point your client at the command and pass the vault-issued key in the environment (only needed for the custody tools):

{
  "mcpServers": {
    "agent-envelope": {
      "command": "npx",
      "args": ["-y", "agent-envelope-mcp"],
      "env": { "AE_API_KEY": "your-vault-issued-key" }
    }
  }
}

Tools

ToolModeCredential
ae_verify_sovereignSovereignnone — offline, always free
ae_get_agentCustodyAE_API_KEY
ae_verify_actionCustodyAE_API_KEY
ae_mintCustodyAE_API_KEY
  • ae_verify_sovereign — verify a signed message against a known agent address. Pure crypto: no vault, no key, no network. Verification is always free.
  • ae_get_agent — fetch the vault-registered public record for an agent id.
  • ae_verify_action — verify a signed action against the vault-held record.
  • ae_mint — mint a capability through the vault from a MintDelegate and a signed MintRequest, returning a mint receipt. This is a governed action.

The sovereign verifier needs no vault and no key. The vault-gated tools are the governed surface a framework offloads rather than rebuilds.

Programmatic use

import { createServer } from 'agent-envelope-mcp';
// mount createServer() on your own MCP transport

Environment

VariableRequired forPurpose
AE_API_KEYae_get_agent, ae_verify_action, ae_mintVault-issued API key

The server is fail-closed: vault-gated tools return an error result when AE_API_KEY is absent rather than exposing an unauthenticated surface.

License

MIT

Reviews

No reviews yet

Be the first to review this server!