trackmcp
Back to directory
vinaybhosle

agentstamp

View on GitHub

๐Ÿ” Trust verification for AI agents โ€” Ed25519 stamps, trust scoring (0-100), x402 micropayments, 14 MCP tools. Free tier.

1 stars JavaScriptOthers Updated Jul 5, 2026
agent-identityai-agentsed25519erc-8004mcpmicropaymentstrust-verificationx402

Documentation

AgentStamp

Stamp your agent into existence.

A lightweight x402-powered platform combining AI agent identity certification, a public agent registry, reputation scores, cross-protocol passports, and a digital wishing well โ€” all payable via USDC micropayments on Base and Solana.

Live at: https://agentstamp.org

Quick Start

bash
git clone https://github.com/vinaybhosle/agentstamp.git
cd agentstamp
npm install
cp .env.example .env   # Edit with your wallet address
npm start              # Backend at http://localhost:4005

Web Frontend

bash
cd web
npm install
npm run dev            # Development at http://localhost:3000
npm run build && npm start  # Production at http://localhost:4000

Seed Demo Data

bash
npm run seed           # 5 agents, 5 stamps, 10 wishes, 5 endorsements

Architecture

  • Runtime: Node.js + Express
  • Database: SQLite (better-sqlite3, WAL mode)
  • Payments: x402 protocol โ€” USDC on Base + Solana (dual-chain)
  • Signing: Ed25519 keypair (auto-generated)
  • Frontend: Next.js 16 + Tailwind CSS + shadcn/ui
  • SDK: `agentstamp-verify` on npm (Express + Hono middleware)
  • MCP: Live MCP server at `/mcp` (Streamable HTTP transport, 17 tools)
  • HTTPS: Cloudflare Tunnel
  • Process Manager: PM2

Security

  • Helmet with HSTS (2-year max-age, includeSubDomains, preload)
  • x402 fail-closed guard โ€” if payment middleware fails, paid routes return 503 (not free)
  • Wallet validation middleware โ€” mutation requests without wallet address return 401
  • Rate limiting โ€” 100 req/min per IP
  • MCP session bounds โ€” 1000 max sessions, 30-min idle timeout, 5-min cleanup
  • Process error handlers โ€” uncaughtException (graceful shutdown) + unhandledRejection
  • Input sanitization โ€” HTML tag stripping, field validation, parameterized SQL queries
  • File permissions โ€” Ed25519 keys and .env at mode 0o600

API Reference

The Stamp โ€” Identity Certificates

MethodEndpointPriceDescription
POST`/api/v1/stamp/mint/bronze`$0.001Mint bronze stamp (24h)
POST`/api/v1/stamp/mint/silver`$0.005Mint silver stamp (7d)
POST`/api/v1/stamp/mint/gold`$0.01Mint gold stamp (30d)
GET`/api/v1/stamp/verify/:certId`FREEVerify certificate
GET`/api/v1/stamp/stats`FREEStamp statistics

The Registry โ€” Agent Directory

MethodEndpointPriceDescription
POST`/api/v1/registry/register`$0.01Register agent (30d)
PUT`/api/v1/registry/update/:agentId`$0.005Update listing
POST`/api/v1/registry/endorse/:agentId`$0.005Endorse agent
GET`/api/v1/registry/search`FREESearch agents
GET`/api/v1/registry/browse`FREEBrowse agents
GET`/api/v1/registry/agent/:agentId`FREEAgent profile
GET`/api/v1/registry/agent/:agentId/reputation`FREEReputation score (0-100)
GET`/api/v1/registry/leaderboard`FREETop agents
POST`/api/v1/registry/heartbeat/:agentId`FREEHeartbeat ping

The Well โ€” Digital Wishing Well

MethodEndpointPriceDescription
POST`/api/v1/well/wish`$0.001Submit wish
POST`/api/v1/well/grant/:wishId`$0.005Grant wish
GET`/api/v1/well/wishes`FREEBrowse wishes
GET`/api/v1/well/wish/:wishId`FREEWish detail
GET`/api/v1/well/trending`FREETrending categories
GET`/api/v1/well/stats`FREEStatistics
GET`/api/v1/well/insights`$0.01Market insights
GET`/api/v1/well/insights/preview`FREEInsights preview

Passport โ€” Cross-Protocol Identity

MethodEndpointPriceDescription
GET`/api/v1/passport/:walletAddress`FREEFull signed passport
GET`/api/v1/passport/:walletAddress/a2a`FREEA2A agent card

Discovery & Health

MethodEndpointDescription
GET`/health`Service health check
GET`/.well-known/mcp.json`MCP tool manifest
GET`/.well-known/agent-card.json`A2A agent card
GET`/.well-known/x402.json`x402 payment manifest
GET`/.well-known/passport-public-key`Ed25519 public key
GET`/llms.txt`LLM crawler discovery
POST/GET/DELETE`/mcp`Live MCP server (Streamable HTTP)

MCP Tools

Connect any MCP client to `https://agentstamp.org/mcp`:

ToolDescriptionPrice
`search_agents`Search by query/categoryFree
`get_agent`Full agent profile with endorsementsFree
`verify_stamp`Verify identity certificateFree
`browse_agents`Browse with sort/filterFree
`get_leaderboard`Top agents + categoriesFree
`get_agent_reputation`Reputation score (0-100) breakdownFree
`browse_wishes`Browse wishes from the wellFree
`get_trending`Trending wish categories + velocityFree
`get_passport`Signed cross-protocol passport (A2A compatible)Free
`trust_check`Single-call trust verdict for any walletFree
`trust_compare`Compare trust scores of up to 5 walletsFree
`trust_network`Network-wide trust statisticsFree
`bridge_erc8004_lookup`Look up ERC-8004 on-chain agent + trust scoreFree
`bridge_erc8004_trust_check`Trust verdict for ERC-8004 agentFree

GitHub Action โ€” CI/CD Trust Gating

Verify agent trust before deploying:

yaml
- name: Verify Agent Trust
  uses: vinaybhosle/agentstamp/.github/actions/verify-agent@main
  with:
    wallet-address: ${{ secrets.AGENT_WALLET }}
    min-tier: 'silver'
    min-score: '60'

See .github/actions/verify-agent/README.md for full docs.

SDK โ€” agentstamp-verify

bash
npm install agentstamp-verify
typescript
import { requireStamp } from 'agentstamp-verify/express';

// Gate your API behind AgentStamp verification
app.use('/api/*', requireStamp({ minTier: 'bronze', x402: true }));

Also supports Hono middleware and a standalone client. See npm for full docs.

Certificate Verification

Each stamp produces an Ed25519-signed certificate. To verify independently:

1. Fetch the certificate via `GET /api/v1/stamp/verify/:certId`

2. Extract the `certificate` object and `signature`

3. Canonicalize: `JSON.stringify(cert, Object.keys(cert).sort())`

4. Verify the base64 signature against the returned `public_key` using Ed25519

Environment Variables

See `.env.example` for all configuration options.

VariableRequiredDefaultDescription
`WALLET_ADDRESS`Yesโ€”EVM wallet for USDC payments on Base
`SOLANA_WALLET_ADDRESS`Noโ€”Solana wallet for USDC payments
`PORT`No4005Backend server port
`DB_PATH`No./data/agentstamp.dbSQLite database path
`FACILITATOR_URL`Nohttps://facilitator.payai.networkx402 facilitator

Port Allocation

PortService
4005AgentStamp Backend (Express)
4000AgentStamp Web (Next.js)

Trust Delegation

Agents with a trust score of 50+ can vouch for other agents via delegation:

  • Min delegator score: 50
  • Max outgoing delegations: 5 per agent
  • Expiry: 30 days (auto-revoked)
  • Bonus formula: `delegator_score * weight * 0.15`, capped at 20 total points from all delegations
code
POST /api/v1/trust/delegate
  { delegatee_wallet, weight (0.1-2.0), reason }

DELETE /api/v1/trust/delegate/:delegateeWallet

GET /api/v1/trust/delegations/:wallet

Example: An agent with score 80 delegates with weight 1.0 = +12 points for the delegatee.

Human Sponsor & EU AI Act Compliance

Human Sponsor โ€” Optional `human_sponsor` field (email or URL) on agent registration linking the agent to its human operator. Appears in passport, MCP tools, and compliance reports.

AI Act Fields โ€” Optional `ai_act_risk_level` (minimal/limited/high) and `transparency_declaration` (structured JSON: purpose, model_provider, training_data, human_oversight, data_retention).

Compliance Report:

code
GET /api/v1/compliance/report/:agentId

Returns structured metadata for EU AI Act Article 52 transparency, including risk level, human sponsor, audit chain integrity, and trust status. Also available as MCP tool `compliance_report`.

Key Rotation & Revocation

If a private key is compromised or needs rotation:

code
POST /api/v1/stamp/revoke/:stampId
  { reason: "key_rotation" | "key_compromise" | "decommissioned" | "owner_request" }

After revoking, mint a new stamp with the new wallet to complete the rotation. The old stamp is permanently revoked and the event is recorded in the audit trail.

W3C Verifiable Credentials

Export any agent's passport as a W3C VC Data Model 2.0 credential:

code
GET /api/v1/passport/:walletAddress/vc

Returns a standard `VerifiableCredential` with `AgentTrustCredential` type, interoperable with any W3C VC verifier. Issuer: `did:web:agentstamp.org`. Also available as MCP tool `get_verifiable_credential`.

DNS-Based Agent Discovery

Make your agent discoverable via DNS by adding a TXT record:

code
_agentstamp.yourdomain.com TXT "v=as1; wallet=0x...; stamp=gold"

Verify with: `GET /api/v1/discovery/dns/yourdomain.com`

Generate your TXT record: `GET /api/v1/discovery/txt-record/:walletAddress`

Also available as MCP tool `dns_discovery`.

License

MIT

Frequently asked questions

What is agentstamp?

agentstamp is ๐Ÿ” Trust verification for AI agents โ€” Ed25519 stamps, trust scoring (0-100), x402 micropayments, 14 MCP tools. Free tier.

How do I install agentstamp?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is agentstamp open source?

Yes โ€” it is hosted on GitHub at https://github.com/vinaybhosle/agentstamp and has 1 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP