# VeriTrust MCPF Credential Submission ## Overview KISC already has a VeriTrust organization profile. This submission requests a **MCPServerCredential** for the new `did:web:llm.kis.gov.lv` identity. --- ## Existing KISC Profile in VeriTrust **Holder DID:** `did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9` **Public Alias:** `did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9` **Status:** Verified --- ## New Identity for MCP Server **DID:** `did:web:llm.kis.gov.lv` **Public Key (multibase):** `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w` **Service Endpoint:** `https://llm.kis.gov.lv/mcp` **Manifest:** `https://llm.kis.gov.lv/.well-known/mcp/manifest.json` --- ## Submission Process ### Step 1: Verify Local Deployment Before submitting to VeriTrust, ensure: ```bash # All .well-known endpoints accessible curl https://llm.kis.gov.lv/.well-known/did.json curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json # MCP server operational curl https://llm.kis.gov.lv/mcp-health ``` --- ### Step 2: Submit Credential Request **Method 1: Via VeriTrust Portal (Recommended)** 1. Log into VeriTrust portal: https://veritrust.vc/portal 2. Navigate to your KISC organization profile 3. Click "Request Credential" → "MCP Server Credential" 4. Fill in form with data from `mcp-server-request.json` 5. Upload or paste: - DID: `did:web:llm.kis.gov.lv` - Public key (multibase): `z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w` - Endpoint: `https://llm.kis.gov.lv/mcp` - Manifest URL: `https://llm.kis.gov.lv/.well-known/mcp/manifest.json` 6. Submit for review **Method 2: Via API (If Available)** ```bash # POST to VeriTrust credential issuance API curl -X POST https://veritrust.vc/api/v1/credentials/issue \ -H "Authorization: Bearer $VERITRUST_API_KEY" \ -H "Content-Type: application/json" \ -d @mcp-server-request.json ``` **Method 3: Email Submission** Send `mcp-server-request.json` to: credentials@veritrust.vc Include: - Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv" - Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9) - Attach: mcp-server-request.json --- ### Step 3: Verification by VeriTrust VeriTrust will verify: 1. ✅ KISC organization profile exists and is verified 2. ✅ `llm.kis.gov.lv` domain is controlled by KISC 3. ✅ DID document accessible at `https://llm.kis.gov.lv/.well-known/did.json` 4. ✅ MCP manifest valid at `https://llm.kis.gov.lv/.well-known/mcp/manifest.json` 5. ✅ Public key matches DID document 6. ✅ Compliance claims are accurate (GDPR, NIS2) **Timeline:** 1-5 business days (typically 1-2 days for verified organizations) --- ### Step 4: Receive Credential VeriTrust will provide: ```json { "@context": [ "https://www.w3.org/2018/credentials/v1", "https://mcpf.dev/credentials/v1" ], "id": "https://veritrust.vc/credentials/[UUID]", "type": ["VerifiableCredential", "MCPServerCredential"], "issuer": { "id": "did:web:veritrust.vc", "name": "VeriTrust" }, "issuanceDate": "2026-01-30T10:00:00Z", "expirationDate": "2027-01-30T10:00:00Z", "credentialSubject": { "id": "did:web:llm.kis.gov.lv#mcp-server", ... }, "credentialStatus": { "id": "https://veritrust.vc/status/2026#94567", "type": "StatusList2021Entry", ... }, "proof": { "type": "Ed25519Signature2020", "created": "2026-01-30T10:00:00Z", "verificationMethod": "did:web:veritrust.vc#key-1", "proofPurpose": "assertionMethod", "proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature } } ``` --- ### Step 5: Install Credential Use the provided `install-credential.sh` script: ```bash # On llm.kis.gov.lv server cd /opt/kisc-llm/poc/deploy # Save VeriTrust credential to temporary file cat > /tmp/veritrust-credential.json << 'EOF' { ... (paste VeriTrust-provided credential JSON) ... } EOF # Run install script ./veritrust/install-credential.sh /tmp/veritrust-credential.json # Verify installation curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq ``` --- ### Step 6: Register in MCPF Registry VeriTrust will automatically register the MCP server in their MCPF registry at `https://mcp.veritrust.vc`. Verify registration: ```bash # Search by country curl "https://mcp.veritrust.vc/mcp/search?country=LV" # Get specific server curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv" ``` Expected response: ```json { "did": "did:web:llm.kis.gov.lv", "endpoint": "https://llm.kis.gov.lv/mcp", "manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json", "credentials": [ "https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json" ], "metadata": { "organization": "Kultūras informācijas sistēmu centrs", "country": "LV", "tags": ["architecture", "government", "latvia", "culture"], "status": "active" } } ``` --- ## Troubleshooting ### VeriTrust cannot verify domain ownership **Solution:** Add DNS TXT record: ``` _veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv" ``` ### VeriTrust cannot fetch DID document **Solution:** Verify HTTPS and CORS: ```bash curl -I https://llm.kis.gov.lv/.well-known/did.json # Should show: # HTTP/2 200 # access-control-allow-origin: * # content-type: application/json ``` ### Credential issuance delayed **Solution:** Contact VeriTrust support with: - Organization: KISC - Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9 - New DID: did:web:llm.kis.gov.lv - Request ID: (if provided) --- ## Contact **VeriTrust Support:** - Website: https://veritrust.vc - Email: support@veritrust.vc (or credentials@veritrust.vc) - Portal: https://veritrust.vc/portal **KISC Contact:** - Rihards (VeriTrust relationship) - KISC IT operations team --- ## Credential Renewal **Expiration:** 1 year from issuance **Renewal Process:** 30 days before expiration, VeriTrust will notify KISC via email **Action Required:** Confirm renewal (usually automatic for verified organizations) --- **Version:** 1.0 **Last Updated:** 2026-01-30 **Status:** Ready for Submission