RowAttest
Runs an eight-stage isolation test against your staging Supabase and issues a signed attestation.
Hosted MCP Server
npx add-mcp 'https://app.rowattest.com/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
RowAttest MCP server
RowAttest runs an eight-stage isolation test against your staging Supabase and issues a signed attestation. The MCP server gives your AI assistant the same six actions a RowAttest API key has: list your projects, start a run, follow it, and read the findings and the signed report. Projects are connected on the website only. The server cannot connect projects, change settings, or pay for anything.
Endpoint
URL
https://app.rowattest.com/mcp
Transport
Streamable HTTP. The endpoint accepts POST; GET answers 405.
Authentication
Authorization: Bearer rak_… — a RowAttest API key, created on the API keys page in the app.
Accept header
Clients send Accept: application/json, text/event-stream. Standard MCP clients do this on their own.
Open handshake, keyed tools
initialize, tools/list and server/discover answer without a key, so clients and directories can see what the server offers before a key is configured. Every tools/call needs a key. Without a valid one the server answers 401 with:
This request needs a valid RowAttest API key in the Authorization header.
Connect your assistant
Claude Code:
claude mcp add --transport http rowattest https://app.rowattest.com/mcp --header "Authorization: Bearer rak_your_key"
Clients that read an mcpServers block (Cursor and others):
{
"mcpServers": {
"rowattest": {
"url": "https://app.rowattest.com/mcp",
"headers": { "Authorization": "Bearer rak_your_key" }
}
}
}
The API keys page in the app shows ready-to-paste settings for Claude Code, Cursor and mcp-remote.
The six tools
list_projects
Lists the Supabase projects connected to this account with id, name, connection state and whether each is ready to run. Call this first to get a project_id.
Input: none
run_review
Starts an authorization test run on a connected project and returns the run_id and status. If the project already has a run waiting to start, returns that run instead of starting another. Runs that do not fail count against the monthly allowance.
Input: project_id
get_run_status
Returns a run's status (queued, running, complete or failed), its current stage, timestamps and, when a signed report exists, its verify_url.
Input: run_id
wait_for_run
Waits up to timeout_seconds (1 to 60) for a run to finish, then returns the same information as get_run_status. Call it again while the status is still queued or running.
Input: run_id, timeout_seconds (optional)
get_findings
Returns the cells that did not pass in a complete run that has a signed report — verdict, surface, operation, boundary, identity, layer outcomes and notes — plus tenancy flags and blocking findings. For a complete run with no signed report, while one can still be bought on the run page, it returns the run's unverified result instead: the verdict, surface, operation and principal of each cell that did not pass, the run page's finding lines, the counts, the coverage lines and the access model summary. The list of cells is empty when every tested cell passed. Contains no fix suggestions: the engine records only what it observed.
Input: run_id
get_report
Returns the full signed report of a complete run as the exact stored JSON, with its verify_url and report_sha256 (sha256 of the canonical signed bytes, the fingerprint shown on the verify page). Use get_findings for the compact view.
Input: run_id
A typical session: list_projects → run_review → wait_for_run until the status is complete or failed → get_findings, and get_report when a signed report exists.
What a key can and cannot do
Create a key on the API keys page. A key can list your projects, start runs, follow them, and read findings and the signed report. It cannot connect projects, change settings, or pay for anything. Keys and agents never hold your project's credentials.
Allowance
Runs started through MCP count against the account's monthly allowance, the same as runs started in the dashboard or through the REST API. Failed runs do not count.
Unsigned and signed
Free runs show their results on the run page and through the API, labelled as unverified; get_findings returns that unverified result. Buying the signed report for a run adds the signed PDF, a public verify link, and the signed JSON, which get_report returns. Anyone can check a signed report at its verify link on rowattest.com/verify.
Requests without a key
Requests that need a key but carry no valid one are rate-limited. The privacy policy describes what is recorded for that and for how long.
Also available
- REST API with the same actions: OpenAPI description at
https://app.rowattest.com/api/v1/openapi.json. - Official MCP Registry entry:
com.rowattest/rowattest. - Source and security policy: github.com/rowattest.
- Questions: info@rowattest.com. ← Back to RowAttest