Server data from the Official MCP Registry
Issue verifiable credentials from AI agents for $0.10 via x402. On-chain on Celo, IPFS-pinned.
About
Issue verifiable credentials from AI agents for $0.10 via x402. On-chain on Celo, IPFS-pinned.
Security Report
HashProof is a credential issuance service with an MCP server interface. The codebase shows reasonable security practices for authentication (x402 micropayment + API keys) and input validation, but has notable concerns: the frontend accepts and submits user-provided wallet addresses without verification, email domain validation is incomplete, and there is inadequate error handling around payment failures. Permissions are appropriate for the stated purpose (crypto payments, IPFS backup, on-chain registry, DNS verification). Supply chain analysis found 4 known vulnerabilities in dependencies (2 critical, 0 high severity). Package verification found 1 issue (1 critical, 0 high severity).
4 files analyzed · 13 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
What You'll Need
Set these up before or after installing:
Environment variable: HASHPROOF_API_KEY
Environment variable: HASHPROOF_WALLET_PRIVATE_KEY
Environment variable: HASHPROOF_X402_NETWORK
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csacanam-hashproof": {
"env": {
"HASHPROOF_API_KEY": "your-hashproof-api-key-here",
"HASHPROOF_X402_NETWORK": "your-hashproof-x402-network-here",
"HASHPROOF_WALLET_PRIVATE_KEY": "your-hashproof-wallet-private-key-here"
},
"args": [
"-y",
"@hashproof/backend"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
HashProof
Verifiable credentials with IPFS backup, on-chain registry, and pay-per-call API via x402.
What it is
HashProof is a credential issuance API. Organizations and Individuals (entities) issue verifiable credentials to people. Each credential is:
- Stored as a JSON in the database and backed up on IPFS (Pinata)
- Registered on-chain in the
CredentialRegistrycontract on Celo - Verifiable via a public URL:
https://hashproof.dev/verify/:id
Two ways to pay: micropayment in USDC via x402 (Base or Celo) — no API keys, no subscriptions — or a prepaid API key for enterprise clients (no crypto needed). AI agents can call the API directly using a funded wallet.
Project structure
backend/ Express API — credential issuance, verification, payments
frontend/ React app — landing page, credential verification, entity pages
contracts/ CredentialRegistry smart contract (Celo)
mcp/ MCP server (hashproof-mcp on npm) — use HashProof from any AI agent
skills/ Agent skill (npx skills add csacanam/hashproof)
docs/ Architecture and flow documentation
Deployed contracts
| Network | Contract | Address |
|---|---|---|
| Celo mainnet | CredentialRegistry | 0x7a1B759A602Aba72a70f99Dffd0a386d7504ce9B |
Paid API endpoints
| Endpoint | Price | Description |
|---|---|---|
POST /issueCredential | $0.10 USDC | Issue one verifiable credential |
POST /entities/:id/verificationRequests | $49 USDC | Submit a verification request |
Payment is in USDC on Base or Celo via x402. The client signs an off-chain authorization — no gas required.
Free endpoints
| Endpoint | Description |
|---|---|
GET /verify/:id | Full 3-layer verification |
GET /templates/:ref/requirements | Get required fields for a template |
POST /templates/:ref/preview | Generate a preview PDF with watermark (no cost) |
GET /stats | On-chain credential counters |
For AI agents
HashProof is fully agent-usable — no account, no human onboarding. Three ways in:
-
MCP server, local or remote (listed on the official MCP registry as
io.github.csacanam/hashproof):# local (stdio) — pays per credential with your own wallet via x402, or an API key claude mcp add hashproof -- npx -y hashproof-mcp # remote (Streamable HTTP) — nothing to install, API key required to issue claude mcp add --transport http hashproof https://api.hashproof.dev/mcpTools:
preview_template(free — iterate custom layouts),issue_credential($0.10 via x402 or API key),verify_credentialandget_template_requirements(free). The remote server has no wallet, so it can't do x402 — it needsAuthorization: Bearer <api-key>. Seemcp/README.md. -
Agent skill:
npx skills add csacanam/hashproof— or read it at hashproof.dev/skill.md. -
Plain HTTP + x402:
POST /issueCredentialreturns a 402 challenge any x402-v2 client can pay (USDC on Base or Celo). LLM index: hashproof.dev/llms.txt.
Agent identity metadata (ERC-8004 registration-v1): hashproof.dev/metadata.json.
Quick start
See backend/README.md and frontend/README.md for setup instructions.
See docs/README.md for the full documentation index.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
