# Signet

> Proof layer for AI agents. Cryptographically verify every action.

- **Type:** MCP server
- **Install:** `agentstack add mcp-prismer-ai-signet`
- **Verified:** Pending review
- **Seller:** [Prismer-AI](https://agentstack.voostack.com/s/prismer-ai)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.4.1
- **License:** Apache-2.0
- **Upstream author:** [Prismer-AI](https://github.com/Prismer-AI)
- **Source:** https://github.com/Prismer-AI/signet
- **Website:** https://signet-auth.vercel.app/

## Install

```sh
agentstack add mcp-prismer-ai-signet
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

Signet

  Don't just log agent actions. Prove them.
  Cryptographic receipts for every AI agent tool call — signed, hash-chained, offline-verifiable. Independent of any provider.

  
  
  
  
  

  
  
  
  

  
    TypeScript packages:
    @signet-auth/core ·
    @signet-auth/mcp ·
    @signet-auth/mcp-server ·
    @signet-auth/mcp-tools ·
    @signet-auth/node ·
    @signet-auth/vercel-ai
  

  
  

  ▶ Try the live demo — sign a tool call in your browser, change a field, and watch verification fail. (mirror: GitHub Pages)

  
    
  

  ▶ Walkthrough: signing, audit log, and verification · ▶ Demo: execution boundary &amp; MCP integration

  

  Single-host pilot flow: sign every tool call, hand off a signed evidence bundle, re-verify on any machine — no signet keystore required. Pilot runbook →

**Your AI agent just placed an order, deleted a row, sent an email, merged a PR. Can you prove exactly what it did — to an auditor, a customer, or yourself after an incident?**

Signet is the **independent verification layer** for agent actions. Every tool call gets a signed receipt that anyone can verify offline, without trusting the platform that hosted the agent or the vendor that stored the logs.

> **Your agents run on their infrastructure. The proof belongs to you.**

## Why Not Just Logs?

Traditional logs tell you what a platform **says** happened. They're mutable, provider-dependent, and unverifiable without trusting the party that wrote them.

Signet receipts are different. Modify any field — tool name, parameters, timestamp, signer — and the Ed25519 signature breaks. Delete or reorder entries and the SHA-256 hash chain breaks. Verification requires only the public key. No network call, no API, no login.

| Ordinary logs | Signet receipts |
| --- | --- |
| Provider says it happened | Anyone can verify it, offline |
| Mutable after the fact | Signature breaks on tamper |
| No ordering proof | Hash chain breaks on delete/reorder |
| Trust the log host | Verify with the public key |
| One-sided claim | Bilateral co-signing available |

Use logs for observability. Use Signet when you need **evidence**.

## Who Is This For?

- **MCP builders** — wrap any MCP server with `signet proxy`, sign every `tools/call`, no code changes
- **Security / compliance teams** — tamper-evident audit trail that satisfies EU AI Act Art. 12, SOC 2 CC7.2, ISO 27001 A.8.15
- **Enterprise agent platforms** — prove what the agent did, who authorized it, which policy was in force
- **Framework users** — LangChain, CrewAI, Claude Code, Codex, OpenAI Agents, Vercel AI SDK — all supported
- **Agent-to-agent deployments** — bilateral co-signing when both sides hold keys

**If a tool call cannot be verified independently, it should not be trusted unconditionally.** This matters when an auditor asks for proof, when an incident happens on infrastructure you don't control, or when the question isn't "what does the console say" but "what actually happened."

Each agent gets an Ed25519 identity. Every tool call can be signed, appended to a hash-chained audit trail, verified offline or before execution, co-signed by the server, bound to a delegation chain, and optionally bound to a policy decision.

The video above shows the full flow. The SVG below shows the CLI signing details, or jump to [See It Reject Bad Requests](#execution-boundary-demo) to watch the server block bad requests before they run.

  

  This first demo shows signing + audit receipts. See also the MCP flow diagram.

## What Signet Adds

Signet adds a lightweight trust layer for agent actions:

- **Sign** every tool call with the agent's cryptographic key
- **Verify** requests offline or at the execution boundary before they are trusted
- **Proxy** any MCP server transparently — sign requests without touching agent or server code, with local bilateral audit co-signing in the proxy path
- **Co-sign** server responses with bilateral receipts when you control both sides
- **Trace** multi-step workflows by linking receipts with `trace_id` and `parent_receipt_id`
- **Authorize** agents with scoped delegation chains that prove who allowed the action
- **Attest policy** by embedding a signed `PolicyAttestation` when a YAML policy is satisfied
- **Inspect locally** with an append-only audit log and dashboard, no hosted control plane required

## What's New In 0.9

- **MCP proxy**: `signet proxy --target  --key ` — drop Signet in front of any MCP server as a transparent stdio proxy. No changes to the agent or server required. Signs every `tools/call` and appends bilateral co-signatures to the local audit path; client-visible bilateral response handling is stronger through integrated transport/server helpers.
- **Trace correlation**: `trace_id` and `parent_receipt_id` fields on `Action` link receipts across multi-step workflows into a causal chain. Both fields are part of the signed payload — tampering invalidates the signature.
- **Policy engine**: `signet sign --policy policy.yaml` enforces policy before signing and binds the decision into the receipt. The proxy also respects `--policy`, blocking denied calls before they reach the server while producing signed bilateral `rejected` / `requires_approval` outcomes and a hash-chained `policy_violation` audit record.
- **Delegation chains**: `signet delegate ...` produces v4 receipts that prove who authorized the agent and what scope it had.
- **Local dashboard**: `signet dashboard` shows timeline, chain integrity, signature health, and delegated vs direct activity.
- **Broader integrations**: official Claude Code plugin, Codex plugin, MCP middleware, Python SDK, and Vercel AI SDK callbacks.

## Compliance

Signet provides the technical controls that auditors look for when assessing AI agent operations. See the full [Compliance Mapping](docs/COMPLIANCE.md) for details.

| Framework | What Signet Addresses |
|-----------|---------------------|
| **SOC 2 Type II** | Signed audit trail (CC7.2), tamper detection (CC7.3), role-based scope (CC6.3), authorization proof (CC8.1) |
| **ISO 27001** | Event logging (A.8.15), access control (A.5.15), authentication (A.5.17), configuration management (A.8.9) |
| **EU AI Act** | Article 12 record-keeping: event logging, traceability, identification, integrity |
| **DORA** | ICT incident logging (Art. 17), third-party risk evidence (Art. 28-30), audit trail integrity |
| **NIST AI RMF** | Govern (delegation chains), Map (signed receipts), Measure (audit queries), Manage (policy engine) |

> Signet is a tool, not a certification. It provides controls that support compliance — your deployment and configuration determine compliance posture.

## Try It In 30 Seconds

```bash
pip install signet-auth
```

```python
from signet_auth import SigningAgent

agent = SigningAgent.create("my-agent", owner="team")
receipt = agent.sign("github_create_issue", params={"title": "fix bug"})

assert agent.verify(receipt)
print(receipt.id)
```

## Why Star This Repo?

Signet is building a new category: **verifiable tool-call receipts for AI agents**. Starring isn't just a bookmark — it helps push cryptographic evidence for agent actions into the ecosystem so regulated industries, enterprise platforms, and framework users don't have to roll their own.

- Working with **Microsoft Agent Governance Toolkit** (example merged in [PR #1196](https://github.com/microsoft/agent-governance-toolkit/pull/1196))
- Named contributor in **LangChain's ComplianceBackend RFC** ([#35691](https://github.com/langchain-ai/langchain/issues/35691))
- Conformance work toward the **IETF draft-farley-acta-signed-receipts** spec
- Maps to **NIST NCCoE's four pillars** for AI agent identity and authorization (Q4 2026 Interoperability Profile)

If you're building agents that need to survive an audit, an incident, or a third party asking "prove it" — star the repo, try it, open an issue.

If you're new, start with one of these five paths:

## Choose Your Path

- [**Claude Code**](#claude-code-plugin): Best for the fastest first run in a coding agent. Run `/plugin install signet@claude-plugins-official` in Claude Code. In 5 minutes you'll have signed tool calls and a local audit log at `~/.signet/audit/`.
- [**Codex CLI**](#codex-plugin): Best for signing Bash tool calls in Codex. Copy `plugins/codex/` into `~/.codex/plugins/signet` and add one `PostToolUse` hook. In 5 minutes you'll have signed Bash actions in Codex using the same audit trail.
- [**Python SDK**](#python-sdk): Best if you want receipts inside LangGraph, LlamaIndex, OpenAI Agents, CrewAI, or your own tool runner. Start with `SigningAgent.create(...)` and add framework hooks only where you need them.
- [**MCP clients**](#mcp-client-integration): Best if you control an MCP client or transport. Wrap your transport with `new SigningTransport(inner, secretKey, "my-agent")`. In 5 minutes you'll have signed `tools/call` requests with receipts in `params._meta._signet`.
- [**MCP servers**](#mcp-server-verification): Best if you want verification before execution. Call `verifyRequest(request, {...})` in your tool handler. In 5 minutes you'll have signer, freshness, target-binding, and tool/params checks at the execution boundary.

## See It Reject Bad Requests

Run the shortest execution-boundary demo:

```bash
cd examples/mcp-agent
npm run execution-boundary-demo
```

  

  Prefer motion? Download the MP4 or GIF.

See [examples/mcp-agent/demo-execution-boundary.mjs](./examples/mcp-agent/demo-execution-boundary.mjs) for the demo source.

## Delegation Chains: Who Authorized This Agent?

Signet receipts prove **what** happened. Delegation chains prove **who allowed it**.

A root identity (human or org) cryptographically delegates scoped authority to an agent. Permissions can only narrow, never widen. The agent's v4 receipt carries the full proof of authorization.

```text
Owner (alice) → Agent A (tools: [Bash, Read], max_depth: 0)
                    ↓
              v4 Receipt: tool=Bash, authorization.chain proves alice → Agent A
```

```bash
# Create a delegation token (expires in 24 hours)
signet delegate create --from alice --to deploy-bot --to-name deploy-bot \
    --tools Bash,Read --targets "mcp://github" --max-depth 0 --ttl 24h

# Sign with authorization proof (v4 receipt)
signet delegate sign --key deploy-bot --tool Bash \
    --params '{"cmd":"git pull"}' --target "mcp://github" --chain chain.json

# Verify: signature + chain + scope + root trust
signet delegate verify-auth receipt.json --trusted-roots alice
```

> **Best practice:** Use short-lived delegations (`--ttl 1h`, `--ttl 24h`) instead of long-lived or non-expiring tokens. If an agent is compromised, the delegation expires automatically. Re-issue tokens as needed. This is the same pattern used by short-lived JWTs and X.509 certificates.

Or in Python:

```python
from signet_auth import sign_delegation, sign_authorized, verify_authorized

# Delegation functions accept JSON strings for scope, chain, and receipts
token_json = sign_delegation(root_key_b64, "alice", agent_pubkey_b64, "bot", scope_json)
receipt_json = sign_authorized(agent_key_b64, action_json, "bot", f"[{token_json}]")
scope_json = verify_authorized(receipt_json, [root_pubkey_b64])
```

  

## Policy Attestations: Was This Allowed?

Signet can enforce a YAML policy before signing. When an action is allowed, the signed receipt carries a `PolicyAttestation` proving which policy hash, rule, and decision were in force.

```yaml
version: 1
name: production-agents
default_action: deny
rules:
  - id: allow-read
    match:
      tool: Read
    action: allow
  - id: deny-rm-rf
    match:
      tool: Bash
      params:
        command:
          contains: "rm -rf"
    action: deny
    reason: destructive command
```

```bash
signet policy validate policy.yaml
signet policy check policy.yaml --tool Bash --params '{"command":"rm -rf /"}'

signet sign --key deploy-bot --tool Read \
    --params '{"path":"README.md"}' --target "mcp://github" --policy policy.yaml
```

Denied actions fail before a receipt is produced. Allowed actions produce a receipt whose signed payload proves the policy decision.

## When Teams Reach For Signet

- You need a tamper-evident audit trail for coding agents, MCP tools, or CI automation
- You want to prove which agent requested an action and who authorized it after an incident
- You need receipts that can be verified offline without depending on a hosted service
- You want lightweight policy enforcement before signing without adding a proxy to your stack

## What Signet Is And Isn't

- **Signet is** a trust layer for agent actions: signing, audit, verification, delegation, and policy attestation
- **Signet is** designed to fit into existing agent stacks with SDKs, plugins, and MCP middleware
- **Signet can** reject unsigned, stale, replayed, or mis-targeted MCP requests before execution
- **Signet can** deny actions before signing when you provide a policy file
- **Signet is not** a hosted gateway, always-on control plane, or replacement for sandboxing and least-privilege design

## Install

```bash
# CLI
cargo install signet-cli

# Python
pip install signet-auth

# TypeScript (MCP middleware)
npm install @signet-auth/core @signet-auth/mcp

# TypeScript (MCP server verification)
npm install @signet-auth/mcp-server

# TypeScript (Node local audit/operator helpers)
npm install @signet-auth/node

# TypeScript (Vercel AI SDK middleware)
npm install @signet-auth/vercel-ai

# TypeScript (standalone MCP signing server)
npx @signet-auth/mcp-tools
```

## Quick Start

### Claude Code Plugin

Auto-sign every tool call in [Claude Code](https://claude.ai/code) with zero configuration:

```bash
# Option A: From the official Anthropic plugin marketplace
/plugin install signet@claude-plugins-official

# Option B: Add Signet as a marketplace source, then install
/plugin marketplace add Prismer-AI/signet
/plugin install signet@signet
```

Every tool call is signed with Ed25519 and logged to a hash-chained audit trail at `~/.signet/audit/`.

Alternative install methods:

```bash
# From Git
claude plugin add --from https://github.com/Prismer-AI/signet

# Via signet CLI
signet claude install
```

### Codex Plugin

Auto-sign every Bash tool call in [Codex CLI](https://github.com/openai/codex):

```bash
git clone https://github.com/Prismer-AI/signet.git
cp -r signet/plugins/codex ~/.codex/plugins/signet
```

Then add the hook to `~/.codex/hooks.json`:

```json
{
  "hooks": {
    "PostToolUse": [{
      "matcher": "Bash",
      "hooks": [{
        "type": "command",
        "command": "node \"$HOME/.codex/plugins/signet/bin/sign.cjs\"",
        "timeout": 5
      }]
    }]
  }
}
```

Or use the MCP server for on-demand signing tools:

```bash
codex mcp add signet -- npx @signet-auth/mcp-tools
```

### CLI

```bash
# Generate an agent identity
signet identity generate --name my-agent

# Sign an action
signet sign --key my-agent --tool "github_create_issue" \
  --params '{"title":"fix bug"}' --target mcp://github.local

# Verify a receipt
signet verify receipt.json --pubkey my-agent

# Audit recent actions
signet audit --since 24h

# Verify log integrity
signet verify --chain
```

### MCP Client Integration (TypeScript)

  

```typescript
import { Client } from "@modelcontextprotocol/sdk/client/index.js";
import { StdioClientTransport } from "@modelcontextprotocol/sdk/client/stdio.js";
import { generateKeypair } from "@signet-auth/core";
import { SigningTransport } from "@signet-auth/mcp";

// Generate an agent identity
const { secretKey } = generateKeypair();

// Wrap any MCP transport -- all tool calls are now signed
const inner = new StdioClientTransport({ command: "my-mcp-server" });
const transport = new SigningTransport(inner, secretKey, "my-agent");

const client = new Client({ name: "my-agent", version: "1.0" }, {});
await client.connect(transport);

// Every callTool() is now cryptographically signed
const result = await client.callTool({
  name: "echo",
  a

…

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Prismer-AI](https://github.com/Prismer-AI)
- **Source:** [Prismer-AI/signet](https://github.com/Prismer-AI/signet)
- **License:** Apache-2.0
- **Homepage:** https://signet-auth.vercel.app/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.4.1 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.4.1** — security scan: flagged — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-prismer-ai-signet
- Seller: https://agentstack.voostack.com/s/prismer-ai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
