🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

agent-envelope-mcp

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

agent-envelope-mcp

Neutral MCP server for AgentEnvelope — expose agent authority (sovereign verify + vault-governed verify, lookup, and mint) to any MCP client.

latest
Source
npmnpm
Version
1.0.2
Version published
Weekly downloads
231
Maintainers
1
Weekly downloads
 
Created
Source

agent-envelope-mcp

The neutral authority layer for agent runtimes, as an MCP server.

Any MCP client — Claude, an OpenAI agent, LangChain, CrewAI, a custom runtime — can call these tools to check and issue agent authority without building its own policy engine, audit log, or verification stack. AgentEnvelope is owned by no framework, so every framework can embed it.

Run

npx agent-envelope-mcp

It speaks MCP over stdio. No API key is needed to start, or to use the sovereign verifier — only the vault-governed tools require AE_API_KEY.

Wire it into an MCP client

Point your client at the command and pass the vault-issued key in the environment (only needed for the custody tools):

{
  "mcpServers": {
    "agent-envelope": {
      "command": "npx",
      "args": ["-y", "agent-envelope-mcp"],
      "env": { "AE_API_KEY": "your-vault-issued-key" }
    }
  }
}

Tools

ToolModeCredential
ae_verify_sovereignSovereignnone — offline, always free
ae_get_agentCustodyAE_API_KEY
ae_verify_actionCustodyAE_API_KEY
ae_mintCustodyAE_API_KEY
  • ae_verify_sovereign — verify a signed message against a known agent address. Pure crypto: no vault, no key, no network. Verification is always free.
  • ae_get_agent — fetch the vault-registered public record for an agent id.
  • ae_verify_action — verify a signed action against the vault-held record.
  • ae_mint — mint a capability through the vault from a MintDelegate and a signed MintRequest, returning a mint receipt. This is a governed action.

The sovereign verifier needs no vault and no key. The vault-gated tools are the governed surface a framework offloads rather than rebuilds.

Programmatic use

import { createServer } from 'agent-envelope-mcp';
// mount createServer() on your own MCP transport

Environment

VariableRequired forPurpose
AE_API_KEYae_get_agent, ae_verify_action, ae_mintVault-issued API key

The server is fail-closed: vault-gated tools return an error result when AE_API_KEY is absent rather than exposing an unauthenticated surface.

License

Apache-2.0 — see NOTICE for attribution.

Keywords

mcp

FAQs

Package last updated on 02 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts