# MCPF Initialize Response - Expected Format ## Request Format ```bash curl -X POST http://localhost:8787/mcp \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{ "jsonrpc": "2.0", "method": "initialize", "params": { "protocolVersion": "2025-03-26", "capabilities": {}, "clientInfo": { "name": "test-client", "version": "1.0" } }, "id": 1 }' ``` ## Response Format (SSE Stream) The server returns Server-Sent Events (SSE) format: ``` event: message data: {JSON_RESPONSE} ``` ## Complete JSON Response Structure ```json { "result": { "protocolVersion": "2025-03-26", "capabilities": { "tools": { "listChanged": true } }, "serverInfo": { "name": "kisc-arch-kultura-valodu-mcp", "version": "0.2.0" }, "_meta": { "identity": { "id": "did:web:llm.kis.gov.lv", "service": { "mcp": "https://llm.kis.gov.lv/mcp" }, "keys": { "jwks_uri": "https://llm.kis.gov.lv/.well-known/jwks.json" } }, "mcpf": { "version": "0.1", "spec": { "repository": "https://github.com/MCPTrustFramework/MCPF-specification" }, "entrypoint": { "type": "manifest", "url": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json" }, "artifacts": { "trust_registry": "https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json", "credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json" } }, "trust": { "verifications": [ { "verifier": "did:web:veritrust.vc", "type": [ "VerifiableCredential", "MCPServerVerification" ], "credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json", "covers": "did:web:llm.kis.gov.lv", "proof_hint": { "verificationMethod": "did:web:veritrust.vc#key-1", "created": "2026-01-29T10:12:41Z" } } ] } } }, "jsonrpc": "2.0", "id": 1 } ``` ## MCPF Layer 1: Session-Level Trust Metadata The `_meta` field contains three key sections: ### 1. Identity ```json { "id": "did:web:llm.kis.gov.lv", "service": { "mcp": "https://llm.kis.gov.lv/mcp" }, "keys": { "jwks_uri": "https://llm.kis.gov.lv/.well-known/jwks.json" } } ``` **Purpose:** Establishes the server's decentralized identity (DID) and key material location. ### 2. MCPF Metadata ```json { "version": "0.1", "spec": { "repository": "https://github.com/MCPTrustFramework/MCPF-specification" }, "entrypoint": { "type": "manifest", "url": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json" }, "artifacts": { "trust_registry": "https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json", "credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json" } } ``` **Purpose:** Links to MCPF specification and trust artifacts for agent discovery. ### 3. Trust Verifications ```json { "verifications": [ { "verifier": "did:web:veritrust.vc", "type": ["VerifiableCredential", "MCPServerVerification"], "credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json", "covers": "did:web:llm.kis.gov.lv", "proof_hint": { "verificationMethod": "did:web:veritrust.vc#key-1", "created": "2026-01-29T10:12:41Z" } } ] } ``` **Purpose:** Documents third-party verification by VeriTrust credential service. ## Verification Steps An MCPF-aware agent should: 1. **Extract DID** from `_meta.identity.id` 2. **Resolve DID document** at `https://llm.kis.gov.lv/.well-known/did.json` 3. **Fetch verification credential** from VeriTrust 4. **Verify credential signature** using VeriTrust's public key 5. **Check credential subject** matches server DID 6. **Optionally fetch** trust registry and manifest for additional context ## Test with jq Extract specific fields: ```bash # Get the DID curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.identity.id' # Output: did:web:llm.kis.gov.lv # Get MCPF version curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.mcpf.version' # Output: 0.1 # Get verifier DID curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.trust.verifications[0].verifier' # Output: did:web:veritrust.vc # Get credential URL curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.trust.verifications[0].credential' # Output: https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json ``` ## Notes - The `_meta` field is **in addition to** standard MCP initialize response fields - Backward compatible: non-MCPF clients ignore `_meta` - Layer 1 (session-level) + Layer 2 (per-response attestations) = Dual-layer trust - Session ID returned in `Mcp-Session-Id` response header (not shown in JSON)