Metadata-Version: 2.5
Name: alex-evidence-verify-mcp
Version: 0.1.0
Summary: Verify signed ALEX evidence bundles as an MCP tool for Claude Desktop, Claude Code, and other MCP clients.
Project-URL: Homepage, https://bewusstki.de/mcp
Project-URL: Documentation, https://bewusstki.de/mcp
Author: Bewusst.Ki
License: Copyright 2026 Bewusst.Ki
        
        Licensed under the Apache License, Version 2.0 (the "License");
        you may not use this file except in compliance with the License.
        You may obtain a copy of the License at
        
            http://www.apache.org/licenses/LICENSE-2.0
        
        Unless required by applicable law or agreed to in writing, software
        distributed under the License is distributed on an "AS IS" BASIS,
        WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
        See the License for the specific language governing permissions and
        limitations under the License.
License-File: LICENSE
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Requires-Python: >=3.10
Requires-Dist: langchain-alex<0.2,>=0.1.1
Requires-Dist: mcp<3,>=2.0
Provides-Extra: dev
Requires-Dist: build>=1.2.2; extra == 'dev'
Requires-Dist: pytest>=8.3; extra == 'dev'
Requires-Dist: ruff>=0.11; extra == 'dev'
Description-Content-Type: text/markdown

# alex-evidence-verify-mcp

Verify signed ALEX Evidence Packages as an MCP tool, usable from Claude Desktop, Claude Code, or
any other MCP client. This is a thin MCP adapter around the same independent verifier that
[`langchain-alex`](https://pypi.org/project/langchain-alex/) exposes as a LangChain tool — no
second verification algorithm is maintained here.

`valid=True` means the evidence package passed verification and carries a verified outcome.
Authentic bundles documenting failed or inconclusive runs are reported as such, not hidden;
inspect `reason` and `outcome` separately.

## Requirements

- Python 3.10 or newer
- OpenSSL available as `openssl` on `PATH`

## Install

```bash
pip install alex-evidence-verify-mcp
```

## Use with Claude Desktop or Claude Code

Add to your MCP client configuration:

```json
{
  "mcpServers": {
    "alex-evidence-verify": {
      "command": "alex-evidence-verify-mcp"
    }
  }
}
```

## Tool contract

```
Tool:   verify_alex_evidence
Input:  bundle (JSON object, JSON string, or filesystem path)
        trust_anchor_pem
        approval_anchor_pem (optional)
Output: valid, reason, outcome, bundle_id, schema_version, claim_ladder
```

The trust anchor is intentionally supplied separately from the bundle. A public key embedded only
in the bundle under test is not trusted.

## Run directly

```bash
python -m alex_evidence_verify_mcp.server
```

## Development

```bash
python -m pip install -e ".[dev]"
python -m pytest
ruff check .
python -m build
```

The verifier implementation lives in `langchain-alex` (`langchain_alex._verifier`), which is also
used by the repository's standalone Python CLI at `tools/verify-bundle/verify.py`. This package
adds MCP wiring only.

## Public evidence

The [public ALEX record](https://bewusstki.de/akte/pr-38) shows a human-readable projection of a
signed Evidence Package plus the verifier path and explicit limits of the claim. It is evidence of
the recorded execution and controls, not proof that the underlying work is professionally correct.
