Attest · attest-mcp
MCP server for Attest — scan agent payment endpoints (x402, MPP, AP2, L402, HTTP 402) and get a trust grade A–F with a safety verdict before your AI agent authorizes a payment.
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Work: Bookkeeping
Who it is for: Finance / accounting
Install (Claude Code):
claude mcp add attest -- npx -y attest-mcp- tashan score: 39.0
- Adoption: 41/wk
- Upkeep: 46.0
- Freshness: 78.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- License: MIT
Security audit
scanned 2026-08-10Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Attest · attest-mcp scores 39 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down — and tells you the day it moves.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
npm ↗ · source ↗ · pkg:attest-mcp
Everything on this page is public evidence and free. What it cannot know is whether you run this — npx tashan-cli doctor reads your own config and names what is wrong in it, also free. tashan Pro tells you the day any of it changes.
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-14 · scorer s5 · how · something wrong here?