Back to Browse

Identity MCP Server

Developer ToolsModerate5.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

DoI score lookup, vouch event builder, and offline schnorr verify for AI agents.

About

DoI score lookup, vouch event builder, and offline schnorr verify for AI agents.

Security Report

5.8
Moderate5.8Moderate Risk

This is a well-structured MCP server for Nostr identity verification with proper separation of concerns and reasonable security practices. The server intentionally remains stateless and key-free, delegating payment handling to the caller. No critical vulnerabilities or data exfiltration patterns detected. Minor code quality observations exist but do not materially affect security. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

7 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

PowForge Depth-of-Identity oracle base URL. Defaults to public production endpoint when running via npx; override for self-hosted or local dev.Optional

Environment variable: ORACLE_URL

Schnorr pubkey of the DoI oracle, used for offline envelope verification. Defaults to the production PowForge oracle pubkey; override only if pointing at a self-hosted oracle.Optional

Environment variable: ORACLE_PUBKEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-zekebuilds-lab-mcp-identity": {
      "env": {
        "ORACLE_URL": "your-oracle-url-here",
        "ORACLE_PUBKEY": "your-oracle-pubkey-here"
      },
      "args": [
        "-y",
        "@powforge/mcp-identity"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@powforge/mcp-identity

zekebuilds-lab/mcp-identity MCP server

MCP server that scores any Nostr pubkey's depth-of-identity before your handler runs. Chaintip-anchored Schnorr cert, L402 priced, drop-in for AI agents that need Sybil resistance on top of paid APIs.

npm: npm i @powforge/mcp-identity

Homepage: https://powforge.dev/explorer

Whitepaper: https://powforge.dev/whitepaper

What It Does

Three MCP tools that wrap the PowForge Depth-of-Identity Oracle:

  • doi_score_lookup — given a Nostr pubkey (hex or npub), returns multi-dimensional identity score (network, longevity, kinetic-filter cost). L402-priced via the upstream oracle.
  • doi_sign_vouch — builds an unsigned Nostr event for vouching depth-of-identity for another pubkey. Caller signs; oracle counts toward score on observation.
  • doi_score_verify — offline Schnorr verification of a signed DoI cert returned from the oracle. No network.

Why Identity-Anchored Pricing

Most paid-API services charge per-request flat. That fails on agent-to-agent surfaces where:

  1. New agents look identical to scrapers — no signal on intent or risk.
  2. Long-tail abusers extract value cheaper than they impose cost.
  3. Whitelist gating doesn't scale to open agent ecosystems.

DoI gives your server a quantitative number for "how much would it cost to fake this caller's identity at this depth" — anchored to a specific Bitcoin chaintip cert that's non-repudiable. Use it as a multiplier on your L402 macaroon price, a rate-limit input, or a routing key.

Quick Start

npm i @powforge/mcp-identity

Add to your MCP config (Claude Desktop, Cursor, etc):

{
  "mcpServers": {
    "powforge-identity": {
      "command": "npx",
      "args": ["-y", "@powforge/mcp-identity"]
    }
  }
}

Restart the client. Three new tools appear under powforge-identity.

Why Chaintip-Anchored

The score includes a Schnorr signature over (score, dimensions, score_chaintip_height, score_chaintip_blockhash). That binds the claim to Bitcoin's kinetic filter — recomputable PageRank scores can be silently rewritten, but a chaintip-anchored cert is a fixed claim against a known time. Verification is offline.

The oracle's falsifiable claim window is documented in the whitepaper.

L402 Pricing

The MCP server transparently handles the L402 macaroon dance with oracle.powforge.dev. First call returns a 402 with a Lightning invoice; the wrapper pays from a wallet you configure (env: LNBITS_INVOICE_KEY) and retries. No keys, no accounts.

Status

License

MIT.

Source

Source lives in a private development repo. Issues, questions, and bug reports welcome here.

Reviews

No reviews yet

Be the first to review this server!

Identity MCP Server - DoI score lookup, vouch event builder, and offline schnorr | MCP Marketplace