io.github.Chriscorp/tracea

MCPcommunitylive
v0.1.0io.github.ChriscorpUnknownUpdated 2mo ago

Tracea — legal identity (Know Your Agent) for AI agents, on-chain. ERC-8004 compatible.

Endpoint healthlive
checked 9 days ago · 388ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
2mo agoLast update
Package
Authorio.github.Chriscorp
LicenseUnknown
Version0.1.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface15 tools · none privileged
Security scan✓ Cleanvlive · 9d agoHow well does this scan work?
EvalsNone
IndexedAug 11, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

15 tools · none privileged
Observed live from the vendor's endpoint9d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://mcp.tracea.online/mcp15 tools · 388ms
verify_agentVerify an AI agent's on-chain legal identity on Tracea (Base Sepolia). Returns registration status, financial cap, permission scope, revocation status, and KYA legal identity (mandant) when available. Use this BEFORE trusting or delegating work to an agent.

Verify an AI agent's on-chain legal identity on Tracea (Base Sepolia). Returns registration status, financial cap, permission scope, revocation status, and KYA legal identity (mandant) when available. Use this BEFORE trusting or delegating work to an agent.

ParameterTypeDescription
agent_address*stringEthereum address of the agent (0x...)
get_agent_infoGet the raw Tracea registry record for an agent: owner, permission scope, financial cap, active status, timestamps.

Get the raw Tracea registry record for an agent: owner, permission scope, financial cap, active status, timestamps.

ParameterTypeDescription
agent_address*stringEthereum address of the agent
is_agent_revokedCheck whether an agent's mandate has been revoked on Tracea (immediate, scheduled or partial revocation).

Check whether an agent's mandate has been revoked on Tracea (immediate, scheduled or partial revocation).

ParameterTypeDescription
agent_address*stringEthereum address of the agent
get_owner_agentsList all agent addresses registered on Tracea by a given owner address.

List all agent addresses registered on Tracea by a given owner address.

ParameterTypeDescription
owner_address*stringEthereum address of the owner
get_actionRead a single logged agent action from the Tracea ActionLog contract by its numeric ID. Returns agent, action type, payload and timestamp.

Read a single logged agent action from the Tracea ActionLog contract by its numeric ID. Returns agent, action type, payload and timestamp.

ParameterTypeDescription
action_id*integerNumeric action ID
get_agent_actionsList all on-chain action IDs logged for a given agent on Tracea.

List all on-chain action IDs logged for a given agent on Tracea.

ParameterTypeDescription
agent_address*stringEthereum address of the agent
log_actionLog an agent action on-chain via Tracea (immutable audit trail, court-ready). Requires TRACEA_API_KEY env var. The action is signed by the account's wallet.

Log an agent action on-chain via Tracea (immutable audit trail, court-ready). Requires TRACEA_API_KEY env var. The action is signed by the account's wallet.

ParameterTypeDescription
agent_address*stringEthereum address of the acting agent
action_type*stringShort action type, e.g. 'email_sent', 'payment_initiated'
datastringOptional human-readable payload (JSON string recommended)
get_registration_fileFetch the ERC-8004 compatible registration file for a Tracea-registered agent, including the KYA legal principal block.

Fetch the ERC-8004 compatible registration file for a Tracea-registered agent, including the KYA legal principal block.

ParameterTypeDescription
agent_address*stringEthereum address of the agent
report_activityReport an action the agent just performed to its owner's Tracea activity feed (off-chain, free, instant). Call this AFTER every significant action (email sent, message posted, file modified, payment, purchase, booking...). Auth via the Tracea MCP URL (?key=...) from the agent's identity page, OR se…

Report an action the agent just performed to its owner's Tracea activity feed (off-chain, free, instant). Call this AFTER every significant action (email sent, message posted, file modified, payment, purchase, booking...). Auth via the Tracea MCP URL (?key=...) from the agent's identity page, OR se…

ParameterTypeDescription
agent_address*stringEthereum address of this agent
category*stringAction category
summary*stringShort human-readable summary of what was done
permission_labelstringWhich owner-granted permission this action falls under
in_permissionbooleanfalse if this action is OUTSIDE the granted permissions (flagged red)
detailsstringOptional JSON string with extra context
get_my_identityGet this agent's full Tracea identity (activity apiKey +, for v2 agents, its EOA private key and ERC-4337 smart account address) using a one-time activation code from the owner. The private key is returned ONLY ONCE — save it securely.

Get this agent's full Tracea identity (activity apiKey +, for v2 agents, its EOA private key and ERC-4337 smart account address) using a one-time activation code from the owner. The private key is returned ONLY ONCE — save it securely.

ParameterTypeDescription
agent_address*stringEthereum address of this agent
activation_codestringOne-time activation code (or use ?code= / x-activation-code)
get_payment_whitelistGet the list of owner-approved payment destination addresses for an agent (anti-injection guardrail). Non-empty list = the agent's smart account can ONLY pay these addresses. Empty = all allowed.

Get the list of owner-approved payment destination addresses for an agent (anti-injection guardrail). Non-empty list = the agent's smart account can ONLY pay these addresses. Empty = all allowed.

ParameterTypeDescription
agent_address*stringEthereum address of the agent
check_payment_allowedDry-run a payment BEFORE executing it: checks on-chain whether the agent's smart account would allow it (permission granted, within financial cap, destination approved if a whitelist exists). Returns { allowed, reason }.

Dry-run a payment BEFORE executing it: checks on-chain whether the agent's smart account would allow it (permission granted, within financial cap, destination approved if a whitelist exists). Returns { allowed, reason }.

ParameterTypeDescription
agent_address*stringEthereum address of the agent (its smart account address)
destination*stringDestination address to pay
amount_eth*stringAmount in ETH, e.g. '0.001'
payment_requiredCreate a x402 payment request (HTTP 402) for a resource you sell to another agent. Returns a paymentId, the USDC amount in units, the destination address and the TraceaPayments contract to call. The paying agent must then call TraceaPayments.payX402(destination, amount, paymentId) on-chain — the co…

Create a x402 payment request (HTTP 402) for a resource you sell to another agent. Returns a paymentId, the USDC amount in units, the destination address and the TraceaPayments contract to call. The paying agent must then call TraceaPayments.payX402(destination, amount, paymentId) on-chain — the co…

ParameterTypeDescription
destination*stringAddress that receives the USDC payment (yours)
amount_usdc*stringAmount in USDC, e.g. '0.50' or '2'
resourcestringIdentifier/URL of the resource to unlock after payment
agentstringAddress of the paying agent, if known
ttl_secondsnumberValidity of the payment session (30-3600s, default 300)
payment_incomingVerify a x402 payment ON-CHAIN (the USDC transfer to your address, exact amount) and mark the session fulfilled. The blockchain is the ONLY source of truth — the payment_sessions table is never trusted alone. Returns { status: 'fulfilled', resource } if verified, or an error if not yet paid/expired.

Verify a x402 payment ON-CHAIN (the USDC transfer to your address, exact amount) and mark the session fulfilled. The blockchain is the ONLY source of truth — the payment_sessions table is never trusted alone. Returns { status: 'fulfilled', resource } if verified, or an error if not yet paid/expired.

ParameterTypeDescription
payment_id*stringThe paymentId returned by payment_required (pay_...)
tx_hash*stringThe on-chain transaction hash of the USDC transfer / payX402 call
payment_statusGet the status of a x402 payment session (pending | paid | fulfilled | expired), with destination, amount and tx hash. Useful to poll while waiting for the paying agent's on-chain transaction.

Get the status of a x402 payment session (pending | paid | fulfilled | expired), with destination, amount and tx hash. Useful to poll while waiting for the paying agent's on-chain transaction.

ParameterTypeDescription
payment_id*stringThe paymentId returned by payment_required (pay_...)

15 of 15 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Tracea — legal identity (Know Your Agent) for AI agents, on-chain. ERC-8004 compatible.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.