🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@peac/mcp-server

Package Overview
Dependencies
Maintainers
1
Versions
39
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@peac/mcp-server

PEAC record operations as MCP tools (verify, inspect, decode, issue, bundle)

next
latest
Source
npmnpm
Version
0.16.3
Version published
Weekly downloads
78
-57.14%
Maintainers
1
Weekly downloads
 
Created
Source

@peac/mcp-server

Local MCP server for PEAC signed interaction records. It exposes tools to verify, inspect, decode, issue, and bundle PEAC records through stdio or the local Streamable HTTP transport.

Installation

pnpm add @peac/mcp-server

Or run directly:

npx @peac/mcp-server

What It Does

@peac/mcp-server exposes PEAC signed interaction record operations as Model Context Protocol (MCP) tools that AI agents and LLM-based applications can call. It supports both stdio and Streamable HTTP transports, with static policy checks, concurrency limits, input size guards, and structured error responses with recovery hints.

How Do I Use It?

Add to Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "peac": {
      "command": "npx",
      "args": ["-y", "@peac/mcp-server"]
    }
  }
}

Add to Cursor or Windsurf

Add to .mcp.json at your project root:

{
  "mcpServers": {
    "peac": {
      "command": "npx",
      "args": ["-y", "@peac/mcp-server"]
    }
  }
}

Streamable HTTP transport

npx @peac/mcp-server --transport http --port 3000

HTTP transport provides per-session isolation, rate limiting, and RFC 9728 PRM discovery. Binds to 127.0.0.1 by default. See examples/mcp-http-quickstart/ for an end-to-end demo.

Enable receipt issuance

npx @peac/mcp-server \
  --issuer-key env:PEAC_ISSUER_KEY \
  --issuer-id https://example.com

Start with HTTP transport

npx @peac/mcp-server --transport http --port 3000

CLI options

FlagDescriptionDefault
--transport <type>Transport: stdio or httpstdio
--port <number>HTTP port3000
--host <address>HTTP bind address127.0.0.1
--issuer-key <ref>Issuer key reference (env:VAR or file:/path)None
--issuer-id <uri>Issuer identifier URINone
--policy <path>Policy configuration file pathBuilt-in default
--jwks-file <path>JWKS file for verifier key resolutionNone
--bundle-dir <path>Directory for evidence bundle outputNone
--cors-origins <list>Allowed CORS origins (comma-separated, HTTP only)None
--trust-proxy <value>Trust X-Forwarded-For (off, loopback, private)off

Programmatic usage

Handlers can be used directly without the MCP server binding:

import { createPeacMcpServer, handleVerify } from '@peac/mcp-server';
import { getDefaultPolicy, computePolicyHash } from '@peac/mcp-server';

const policy = getDefaultPolicy();
const policyHash = await computePolicyHash(JSON.stringify(policy));

const result = await handleVerify({
  input: { jws: 'eyJ...', public_key_base64url: '...' },
  policy,
  context: {
    version: '0.15.0',
    policyHash,
    protocolVersion: '2025-11-25',
  },
});

Available tools

ToolDescriptionAvailability
peac_verifyVerify a PEAC signed interaction record.Always
peac_inspectInspect a PEAC signed interaction record without verification.Always
peac_decodeDecode a PEAC receipt JWS header and payload for diagnostics.Always
peac_issueIssue a PEAC signed interaction record from provided claims.Requires --issuer-key and --issuer-id
peac_create_bundleCreate a PEAC bundle from signed records and related artifacts.Requires --issuer-key, --issuer-id, and --bundle-dir

All structured tool outputs include a schema-declared _meta audit block with serverVersion, policyHash, protocolVersion, and registeredTools. This is separate from the top-level MCP _meta carrier used by @peac/mappings-mcp to attach PEAC receipt references.

Integrates With

  • @peac/protocol (Layer 3): signed-record issuance and verification
  • @peac/crypto (Layer 2): JWS signing and decoding
  • @peac/schema (Layer 1): Receipt schema validation
  • @peac/kernel (Layer 0): Error codes and constants
  • @modelcontextprotocol/sdk: MCP server and transport bindings

For Agent Developers

Connect your agent to this server over stdio or HTTP to gain signed-record verification, receipt decoding, and issuance capabilities. The tools use structured outputs with error codes and next_action recovery hints so your agent can handle failures programmatically. Every response includes _meta for audit and traceability.

Read-only tools (peac_verify, peac_inspect, peac_decode) are available with no configuration. To enable issuance, provide an Ed25519 signing key via --issuer-key and --issuer-id.

For Operators

The server applies static policy checks with configurable concurrency limits, input size bounds, JWS size caps, and tool timeouts. HTTP transport binds to localhost by default with CORS deny-all. The stdout fence prevents non-JSON-RPC output from corrupting the stdio transport.

Security properties: no ambient key discovery (keys must be explicitly provided), no implicit network fetches from tool handlers, path traversal prevention on bundle output, and session isolation on HTTP transport.

License

Apache-2.0

PEAC Protocol is an open source project stewarded by Originary and community contributors.

Docs | GitHub | Originary

Keywords

peac

FAQs

Package last updated on 21 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts