Tools

Tools & reference implementations

MCPF is intended to be adoptable: small pieces you can add to your existing MCP deployment, one step at a time.

Issuer tooling

Issue VCs for MCP servers and publish revocations. Keep keys in proper HSM/KMS when possible.

Registry service

Publish server entries, manifests, issuer lists, and revocations in a queryable API.

Runtime policy gate

A small component that enforces allow/deny rules before an agent calls a tool.

Capability snapshot / drift check

Detect when an MCP server’s exposed tools changed and require re-approval.

All code: the canonical repositories are under github.com/MCPTrustFramework.