Skip to content

Add article: cryptographic receipts for MCP tool calls#76

Open
desiorac wants to merge 1 commit intoPuliczek:mainfrom
desiorac:add-arkforge-mcp-receipts-article
Open

Add article: cryptographic receipts for MCP tool calls#76
desiorac wants to merge 1 commit intoPuliczek:mainfrom
desiorac:add-arkforge-mcp-receipts-article

Conversation

@desiorac
Copy link
Copy Markdown

Adds a practical article on adding Ed25519-signed proof receipts to MCP tool calls.

The article covers:

  • Why MCP tool calls have no built-in auditability mechanism
  • How to route calls through a neutral certifying proxy (one helper function, minimal code change)
  • What each receipt contains: request/response hashes, RFC 3161 timestamp, Ed25519 signature, Sigstore Rekor entry
  • Compliance angle (OWASP Top 10 for Agentic Apps, EU AI Act, DORA)

Fits the Articles section as a practical "how to address the MCP auditability gap" piece.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant