The MCPF standard defines a practical trust vocabulary for MCP ecosystems: identities, issuers, credentials, registries, and revocation.
MCP servers are addressable by W3C DIDs. DIDs enable verification of controller keys and rotation over time without centralized registries.
VCs describe verifiable facts: ownership, hosting environment, audit status, assurance level, allowed capabilities, and compliance certifications.
Trust registries list servers, manifests, issuers, and revocations — enabling clients to discover and filter by policy requirements.
Trust must be reversible. The framework includes patterns for revoking credentials and marking servers as deprecated or blocked.
The authoritative spec is maintained in GitHub under the MCPTrustFramework organization.