Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "kenwea.notary.check"
⟨125 unchanged words⟩ network connections, DNS lookups and programs itattempts.attempts; a single file is traced the same way. Dependencies are not installed. Returns: installSteps (what ⟨26 unchanged words⟩ , an Ed25519 signature over all of those.For a package,approved meansevery installeverythingstepthat rantofinished,completionwasandtracednonewhole and tried to reach nothing on the network; a step that tried, failed or ⟨51 unchanged words⟩ signup; 20 checks per hour per network address (an IPv6 /64 counts as one address) within a shared hourly ceiling, refused with rate_limited ⟨10 unchanged words⟩ a Bearer token uses that key's own quota. At most four checks run at once; one that gets no slot within 10 seconds comes back manual_review with reasonCode runner_busy and nothing run, so retry. The same bytes at the same address under the same checker version get the record issued the first time, marked cached, and nothing is run again. Stores nothing about the artifact or what you ⟨36 unchanged words⟩
Changed the definition of "kenwea.notary.check", "kenwea.notary.getPublicKey" and "kenwea.notary.verify"
⟨79 unchanged words⟩ network, all capabilities dropped, read-only filesystem, not as root, 15 seconds for a file and4555 for a package. For a package it runs the install steps npm would run (preinstall, install, postinstall, and the node-gyp step npm adds for a binding.gyp), each traced for the network connections, DNS lookups and programs it attempts. Dependencies are not installed. Returns:ainstallStepsverdict(what runs at install; empty means nothing does) and observed (approved,whatmanual_reviewtheor
Certificate recorded, valid to 2026-12-29
Authorization not required
Unknown → Live
First tool surface recorded: 3 tools (server version 1.0.0)
https://mcp.kenwea.com/notary/v1 (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 7 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨17 unchanged words⟩ instead of kenwea.notary.verify. Input: none. Behavior: readstheKenwea's published keyfromlist (https://www.kenwea.com/.well-known/kenwea-attestation-key, the address every signed record names,//www.kenwea.com/.well-known/kenwea-attestation-keys.json) and caches it for an hour. Runs nothing ⟨4 unchanged words⟩ the check quota. Fails with key_unavailable if thekeylist cannot be fetched. Returns:keyId (compare it withtheaactiverecord'skey'ssignedAttestation.keyId)keyId, algorithm ed25519, the key as base64 (32 raw bytes) and as PEM, keyUrl andkeyUrl.keysUrl, and keys, every published key with its status (active, retired or revoked). To verify, check signedAttestation.signature (base64) over the exact bytes of signedAttestation.payload withthisthekey.key whose keyId the payload names, and treat a revoked key as no signature. Not for: checking an artifact (use kenwea.notary.check ⟨10 unchanged words⟩
⟨76 unchanged words⟩ runs nothing and makes no request except fetchingtheKenwea'spublicpublished key list (https://www.kenwea.com/.well-known/kenwea-attestation-keys.json), which it caches for anhour.hourItandchecksreadsagainstagainthewhen a record names a keypublisheditnow,doessonotahold. A record names its key inside the signedbeforepayloada(formatkey2)rotationandreturnsisvalidcheckedfalse;againstcomparethatthekey;returnedankeyIdolder record is tried against every published key. A record signed withthearecord'skeykeyIdKenweatohastellrevokedthatreturnsapartvalidfromfalsetampering.and says so. Read-only and idempotent; it never counts against the check quota. Returns: valid, the keyId and its status, and the signed facts (artifactRefverdict,contentSha256reasonCode,verdictinstallSteps,ranobserved,exitCodecontentSha256, issuedAt and the rest); with contentSha256, also matchesContentSha256. An altered ⟨7 unchanged words⟩ the reason, not an error. If the key list cannot be fetched the call fails with key_unavailable ⟨28 unchanged words⟩