Dev.to Security 🔐 Cybersecurity 👁 0

Verify any MCP server trust in 1 command (free, Ed25519, no auth)

One command to verify MCP trust curl -s https://marketnow.site/api/atc?action=verify&card_id=ATC-2026-7777670 | jq Returns: { "valid": true, "sentinel_review_score": 10, "decision_authority": "consume

One command to verify MCP trust

curl -s https://marketnow.site/api/atc?action=verify&card_id=ATC-2026-7777670 | jq

Returns:

{
  "valid": true,
  "sentinel_review_score": 10,
  "decision_authority": "consumer",
  "risk_level": "low"
}

What is this?

Agent Trust Cards (ATC) — Ed25519-signed identity cards for MCP servers. RFC 8032 + RFC 8785 JCS. Schema v1.1.0.

The ATC answers 4 questions:

  1. Identity (Ed25519 public key)
  2. Issuer (which CA vouches)
  3. Validity (valid/revoked)
  4. Review evidence (Sentinel score 0-10)

It does NOT answer should you trust it? — that is YOUR decision.

Also: verify Vibe receipts (mutual hop)

curl -s https://marketnow.site/api/atc?action=verify-vibe-receipt | jq .valid
# -> true (bidirectional Ed25519 verification)

Submit your MCP server for free audit

curl -X POST https://marketnow.site/api/submit-skill -H "Content-Type: application/json" -d x27{"repo_url": "https://github.com/you/your-mcp-server"}x27

10-layer audit. Ed25519 ATC. Catalog listing. All free.

Links: https://marketnow.site/submit | https://github.com/edgarfloresguerra2011-a11y/marketnow

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.