Server data from the Official MCP Registry
Signed attestations for agents, $0.01/call via x402: URL witness, AI permission, tx finality, JWKS.
About
Signed attestations for agents, $0.01/call via x402: URL witness, AI permission, tx finality, JWKS.
Remote endpoints: streamable-http: https://witness.holoweave.org/mcp
Security Report
Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.
7 tools verified · Open access · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Connect
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"io-github-ninefiveonefive-auto-witness": {
"url": "https://witness.holoweave.org/mcp"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
web-bot-auth-check
Find out why your web bot auth signature is being rejected.
Signed attestations, paid per call over x402 on Base.
Part of autobus, which is where the rest of these live — one face per product, each carrying everything its buyer needs.
This repository is the buyer's side: how to call the service, and how to verify what it gave you. It carries no dependencies and nothing here phones home.
Live at https://witness.holoweave.org. No account, no key, no signup. Call the
endpoint, get a 402 with a quote, pay, get a signed attestation.
What it answers
POST /v1/wba-thumbprint — $0.01
Does your keyid name a key you actually published? RFC 7638 thumbprint against your key directory
Anchored to RFC 7638 JWK Thumbprint, with RFC 8037 Appendix A.3 for Ed25519 (RFC 7638), read 2026-08-23.
POST /v1/wba-signature — $0.01
Does your signature verify against the key you published? RFC 9421 signature base, Ed25519
Anchored to RFC 9421 HTTP Message Signatures (RFC 9421), read 2026-08-23.
POST /v1/signature-acceptance — $0.01
Signature acceptance check against draft-meunier-web-bot-auth-architecture
Anchored to draft-meunier-web-bot-auth-architecture (-05), read 2026-08-23.
Evidence, never conclusions
An attestation says what is true of the artifact you sent, against a named specification, at a stated time. It never says you are compliant, valid or approved — those are conclusions, and they are yours to draw.
A finding looks like "keyid matches the kid of key 0 but NOT its RFC 7638 thumbprint". It does not look like "your setup is wrong".
Calling it
POST https://witness.holoweave.org/v1/wba-thumbprint
Content-Type: application/json
{
"key_directory": "https://signer.example/.well-known/http-message-signatures-directory",
"keyid": "poqkLGiymh_W0uP6PZFw-dvez3QJT5SolqXBCW38r0U"
}
Unpaid, that returns 402 with a PAYMENT-REQUIRED header carrying the
quote: scheme exact, network eip155:8453 (base-mainnet), the amount
in atomic units, and the asset. Pay with an x402 client and repeat the call with
the PAYMENT-SIGNATURE header. See examples/call.mjs
for the whole flow in one dependency-free file.
A GET returns the same 402, so a crawler can read the price without buying
anything.
Verifying what you were given
Every attestation is signed Ed25519 over the RFC 8785 canonical form of the attestation object alone — the signature block is not part of what is signed.
node verify.mjs attestation.json
verify.mjs has no dependencies and does not call us. The public
key is in key.json and is also served live at
https://witness.holoweave.org/v1/key.
examples/attestation.json is a real one, bought
on mainnet for a cent. Verify it before you trust anything else here.
Fixtures
fixtures.json is the published fixture suite: inputs and the
exact findings they must produce. If a fixture stops matching, our judgment
moved, and you can tell without asking us.
Idempotence
The same input digest is served from cache and not charged twice. Asking the same question again is free; asking a different one is a different question.
Operated from Austria as a Kleinunternehmen. Imprint and privacy notice at
https://witness.holoweave.org/impressum.html and /datenschutz.html.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
