Trustcard
Cryptographic trust infrastructure for MCP servers — content-addressed tool identity, signed manifests, TOFU pinning, capability descriptors, a two-gate invocation policy, signed+chained receipts, and publisher key rotation. Also the "npm audit" health-ch
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Work: Logistics and fulfilment · Audit
Who it is for: Operations · Finance / accounting · Legal / compliance
Install (Claude Code):
claude mcp add trustcard -- npx -y mcp-trustcard“45 worked examples; short of deep on per-tool docs; read with 1 linked doc(s)”
This grade is wrong ›- tashan score: 51.0
- Instruction depth: 70.0 (solid — documents the job properly, with examples you could follow)
- Adoption: 177/wk
- Upkeep: 62.0
- Freshness: 82.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- License: MIT
Security audit
scanned 2026-09-12Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.
What changed recently
- 2026-08-17 mcp-trustcard published 3.0.3, was 3.0.2 A new release is available.
- 2026-08-19 mcp-trustcard published 3.1.0, was 3.0.3 A new release is available.
You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
We recorded 2 changes to Trustcard in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
npm ↗ · source ↗ · pkg:mcp-trustcard
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-13 · scorer s5 · how · something wrong here?