touchstone-mcp
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@touchstone-mcprecord that I deployed version 1.2.3"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
touchstone-mcp
Local MCP server for Touchstone — record what your agent did into a tamper-evident, externally-anchored log.
This server runs on your machine and holds your Ed25519 signing key. It signs each
event locally and appends it to your recorder, so an agent only has to call
touchstone_record({ event_type, payload }). The key never leaves this process.
Canonicalization (JCS / RFC 8785) is done locally too, so a malicious or compromised server
can't trick you into signing a different commitment than you intended.
Zero dependencies — Node 18+ built-ins only. It's a single file: read it before you trust it.
The remote MCP at
https://touchstone.cv/mcpcan't sign for you (Touchstone never holds your key), so itstouchstone_recordexpects a signature you computed yourself. Run this server when you want frictionless local signing.
Install
# one-off, no install:
npx -y @touchstone-cv/mcp
# or vendor the single file:
curl -O https://touchstone.cv/touchstone-mcp.mjs
# or clone:
git clone https://github.com/Touchstone-CV/touchstone-mcp && cd touchstone-mcpRelated MCP server: signet
Configure
Point your MCP client at it over stdio:
{
"mcpServers": {
"touchstone": {
"command": "npx",
"args": ["-y", "@touchstone-cv/mcp"],
"env": {
"TOUCHSTONE_RECORDER": "rec_...",
"TOUCHSTONE_SUBJECT": "<your-colony-sub>",
"TOUCHSTONE_API_KEY": "tsk_...",
"TOUCHSTONE_SIGNING_KEY": "<base64 Ed25519 32-byte seed>"
}
}
}
}Env var | Required | Meaning |
| yes | Your recorder public id ( |
| to record | Your Colony |
| yes | API key minted on the recorder ( |
| to record | base64 Ed25519 32-byte seed — kept by you, never sent |
| alt | Path to JSON |
| no | Defaults to |
To get a recorder + key, see touchstone.cv/developers — agents can self-provision one with their own Colony token (OAuth Token Exchange, RFC 8693), no browser required.
Tools
Tool | What it does |
| JCS-canonicalizes |
| Create a shareable |
| Verify a disclosure bundle (proxies to the service) |
| Fetch your recorder's public info / checkpoint state |
Only touchstone_record uses your signing key; the rest proxy to the remote service over your API key.
Selective field disclosure
Call touchstone_record({ event_type, payload, selective_disclosure: true }) to commit each
payload field separately — the client computes a salted-field Merkle root locally and signs
that as payload_hash, storing the per-field salts. Later you can reveal only a subset:
touchstone_disclose({ seqs: [n], reveal: { n: ["field_a", "field_b"] } })Revealed fields ship with Merkle proofs against payload_hash (which your signature already
covers); withheld fields are salt-bound and their values never appear in the disclosure. The
root computation matches the server and the verifiers byte-for-byte.
Verifying the log
A disclosure can be checked by anyone, with no trust in Touchstone — in the
browser verifier, the standalone
verify.php, or the
gossip_check.py split-view checker. Those tools are served
from the site (and are each a single auditable file); this repo is just the recording client.
License
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceMCP server for AI agent identity — verify agents with Ed25519 signatures, check trust scores, sign and verify content, exchange encrypted messages. Built on the Agent Identity Protocol (AIP).Last updated8MIT
- AlicenseAqualityAmaintenanceOpen-source MCP server that exposes Signet cryptographic tools over stdio. It provides tools to generate Ed25519 keypairs, sign MCP actions, verify Signet receipts, and compute canonical content hashes for AI agent audit and accountability workflows.Last updated437Apache 2.0
- AlicenseAqualityCmaintenanceLocal-first MCP server for per-agent key management, generating and using signing keys without external KMS.Last updated8161MIT
- Alicense-qualityAmaintenanceTamper-evident audit logging for AI agents. Append-only, hash-chained, optionally Ed25519-signed log. The MCP server lets an agent keep and verify a record of what it actually did.Last updated5MIT
Related MCP Connectors
Hosted AgentLux MCP server for marketplace, identity, creator, services, and social flows.
Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...
Post-quantum, tamper-evident receipts for agent actions. Ed25519 + ML-DSA-65, offline verify.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Touchstone-CV/touchstone-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server