Etch
Chuỗi kiểm toán có chữ ký cho các quyết định của tác nhân AI, có thể xác minh ngoại tuyến dựa trên các khóa công khai cố định. Mỗi sự kiện được ký bằng một phong bì lai Ed25519 + FIPS 205 SLH-DSA-SHA2-128f, được liên kết Merkle thành một kỷ nguyên, và kỷ nguyên được neo trên Sigstore Rekor + Bitcoin OpenTimestamps.
Tài liệu
etch-mcp
Etch is a signed audit chain for AI agent decisions, offline-verifiable against pinned public keys.
This repository is the MCP integration surface for Etch, the hosted service. It carries only:
- The MCP registry metadata (
server.json,glama.json) - Per-client integration examples for Claude Code / Cursor / Continue / Cline / Codex
- Documentation for attaching an MCP-compliant client to Etch
The hosted Etch service source is proprietary and lives in a separate repository. Nothing in this repository is required to be inspected or modified in order to use Etch.
Try in 30 seconds, no signup
curl -X POST https://etch.systems/v1/your-project
The response returns a bearer token, an MCP endpoint URL, and an anonymous project id. Point any MCP-compliant client at https://etch.systems/mcp with the token. Anonymous projects carry 500 signed events over 14 days; convert to a persistent project any time to keep the chain forever.
Full walk-through: etch.systems/docs/quickstart.
Per-client config
Claude Code
~/.claude/settings.json:
{
"mcpServers": {
"etch": {
"url": "https://etch.systems/mcp",
"headers": {
"Authorization": "Bearer wm_YOUR_ANON_TOKEN"
}
}
}
}
Cursor
~/.cursor/mcp.json (or .cursor/mcp.json at the project root):
{
"mcpServers": {
"etch": {
"url": "https://etch.systems/mcp",
"headers": {
"Authorization": "Bearer wm_YOUR_ANON_TOKEN"
}
}
}
}
Continue
~/.continue/config.yaml:
mcpServers:
- name: etch
url: https://etch.systems/mcp
headers:
Authorization: Bearer wm_YOUR_ANON_TOKEN
Cline (VS Code)
~/.config/Cline/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json:
{
"mcpServers": {
"etch": {
"url": "https://etch.systems/mcp",
"headers": {
"Authorization": "Bearer wm_YOUR_ANON_TOKEN"
}
}
}
}
Codex CLI
~/.codex/config.toml:
[mcp_servers.etch]
url = "https://etch.systems/mcp"
headers = { Authorization = "Bearer wm_YOUR_ANON_TOKEN" }
Per-client documentation with current config file locations is kept up-to-date at etch.systems/docs/mcp-clients.
Verify
Every event Etch signs is verifiable offline against pinned public keys with the OSS reference verifier. Auditors pin fingerprints once at pilot onboarding; every past epoch is verifiable indefinitely without contacting Etch.
- Reference verifier posture and benchmark numbers: etch.systems
- Framework mapping (SR 11-7, EU AI Act Article 12, ISO 42001, NIST AI RMF): etch.systems/aarm
- FAQ: etch.systems/docs/faq
What Etch is NOT
- Not a media-provenance envelope (that lane is C2PA and SPIF). Etch signs decisions, not content. Comparison: etch.systems/vs/c2pa.
- Not a transparency log (that lane is Sigstore Rekor). Etch is a per-project chain that anchors epochs on Rekor. Comparison: etch.systems/vs/sigstore-rekor.
- Not a watermarking system. Etch records who reviewed an output and what they applied, not whether a specific model touched the text.
License
The metadata and documentation in this repository are MIT-licensed (see LICENSE). The hosted Etch service is Business Source License 1.1 with a hosted-service restriction; see etch.systems/pricing for terms.
Registry listings
Etch is listed on:
- Official MCP Registry as
io.github.SaravananJaichandar/etch - Glama.ai MCP servers (auto-indexed from
glama.jsonin this repo) - mcpservers.org
- punkpeye/awesome-mcp-servers under Knowledge & Memory
- agentrust-io/awesome-ai-governance under Agent Identity & Attestation
- ottosulin/awesome-ai-security under MCP Security
PulseMCP auto-indexes from the Official MCP Registry when their intake resumes; no separate submission needed.
For issues with the hosted service, contact via etch.systems. For issues with the metadata or integration examples in this repository, open a GitHub issue here.