6.1 KiB
VeriTrust MCPF Credential Submission
Overview
KISC already has a VeriTrust organization profile. This submission requests a MCPServerCredential for the new did:web:llm.kis.gov.lv identity.
Existing KISC Profile in VeriTrust
Holder DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
Public Alias: did:web:veritrust.vc:portal:company:df0684bd-b54a-4684-b3d6-93a3b1c4bcb9
Status: Verified
New Identity for MCP Server
DID: did:web:llm.kis.gov.lv
Public Key (multibase): z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w
Service Endpoint: https://llm.kis.gov.lv/mcp
Manifest: https://llm.kis.gov.lv/.well-known/mcp/manifest.json
Submission Process
Step 1: Verify Local Deployment
Before submitting to VeriTrust, ensure:
# All .well-known endpoints accessible
curl https://llm.kis.gov.lv/.well-known/did.json
curl https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json
curl https://llm.kis.gov.lv/.well-known/mcp/manifest.json
# MCP server operational
curl https://llm.kis.gov.lv/mcp-health
Step 2: Submit Credential Request
Method 1: Via VeriTrust Portal (Recommended)
- Log into VeriTrust portal: https://veritrust.vc/portal
- Navigate to your KISC organization profile
- Click "Request Credential" → "MCP Server Credential"
- Fill in form with data from
mcp-server-request.json - Upload or paste:
- DID:
did:web:llm.kis.gov.lv - Public key (multibase):
z6MkjWGNnJsdyvutfbsytFJhkwDwyHkMkfWVL8X1fS1yBm2w - Endpoint:
https://llm.kis.gov.lv/mcp - Manifest URL:
https://llm.kis.gov.lv/.well-known/mcp/manifest.json
- DID:
- Submit for review
Method 2: Via API (If Available)
# POST to VeriTrust credential issuance API
curl -X POST https://veritrust.vc/api/v1/credentials/issue \
-H "Authorization: Bearer $VERITRUST_API_KEY" \
-H "Content-Type: application/json" \
-d @mcp-server-request.json
Method 3: Email Submission
Send mcp-server-request.json to: credentials@veritrust.vc
Include:
- Subject: "KISC MCP Server Credential Request - did:web:llm.kis.gov.lv"
- Body: Reference existing KISC profile (did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9)
- Attach: mcp-server-request.json
Step 3: Verification by VeriTrust
VeriTrust will verify:
- ✅ KISC organization profile exists and is verified
- ✅
llm.kis.gov.lvdomain is controlled by KISC - ✅ DID document accessible at
https://llm.kis.gov.lv/.well-known/did.json - ✅ MCP manifest valid at
https://llm.kis.gov.lv/.well-known/mcp/manifest.json - ✅ Public key matches DID document
- ✅ Compliance claims are accurate (GDPR, NIS2)
Timeline: 1-5 business days (typically 1-2 days for verified organizations)
Step 4: Receive Credential
VeriTrust will provide:
{
"@context": [
"https://www.w3.org/2018/credentials/v1",
"https://mcpf.dev/credentials/v1"
],
"id": "https://veritrust.vc/credentials/[UUID]",
"type": ["VerifiableCredential", "MCPServerCredential"],
"issuer": {
"id": "did:web:veritrust.vc",
"name": "VeriTrust"
},
"issuanceDate": "2026-01-30T10:00:00Z",
"expirationDate": "2027-01-30T10:00:00Z",
"credentialSubject": {
"id": "did:web:llm.kis.gov.lv#mcp-server",
...
},
"credentialStatus": {
"id": "https://veritrust.vc/status/2026#94567",
"type": "StatusList2021Entry",
...
},
"proof": {
"type": "Ed25519Signature2020",
"created": "2026-01-30T10:00:00Z",
"verificationMethod": "did:web:veritrust.vc#key-1",
"proofPurpose": "assertionMethod",
"proofValue": "z5vgK8B..." // VeriTrust's cryptographic signature
}
}
Step 5: Install Credential
Use the provided install-credential.sh script:
# On llm.kis.gov.lv server
cd /opt/kisc-llm/poc/deploy
# Save VeriTrust credential to temporary file
cat > /tmp/veritrust-credential.json << 'EOF'
{
... (paste VeriTrust-provided credential JSON) ...
}
EOF
# Run install script
./veritrust/install-credential.sh /tmp/veritrust-credential.json
# Verify installation
curl https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json | jq
Step 6: Register in MCPF Registry
VeriTrust will automatically register the MCP server in their MCPF registry at https://mcp.veritrust.vc.
Verify registration:
# Search by country
curl "https://mcp.veritrust.vc/mcp/search?country=LV"
# Get specific server
curl "https://mcp.veritrust.vc/mcp/servers/did:web:llm.kis.gov.lv"
Expected response:
{
"did": "did:web:llm.kis.gov.lv",
"endpoint": "https://llm.kis.gov.lv/mcp",
"manifest": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json",
"credentials": [
"https://llm.kis.gov.lv/.well-known/credentials/mcp-server.json"
],
"metadata": {
"organization": "Kultūras informācijas sistēmu centrs",
"country": "LV",
"tags": ["architecture", "government", "latvia", "culture"],
"status": "active"
}
}
Troubleshooting
VeriTrust cannot verify domain ownership
Solution: Add DNS TXT record:
_veritrust.llm.kis.gov.lv TXT "did=did:web:llm.kis.gov.lv"
VeriTrust cannot fetch DID document
Solution: Verify HTTPS and CORS:
curl -I https://llm.kis.gov.lv/.well-known/did.json
# Should show:
# HTTP/2 200
# access-control-allow-origin: *
# content-type: application/json
Credential issuance delayed
Solution: Contact VeriTrust support with:
- Organization: KISC
- Existing DID: did:key:z6Mkuwv1z6y2yorbBf4LEkNzJCg16ERVfWE3bJEPKXtQm7a9
- New DID: did:web:llm.kis.gov.lv
- Request ID: (if provided)
Contact
VeriTrust Support:
- Website: https://veritrust.vc
- Email: support@veritrust.vc (or credentials@veritrust.vc)
- Portal: https://veritrust.vc/portal
KISC Contact:
- Rihards (VeriTrust relationship)
- KISC IT operations team
Credential Renewal
Expiration: 1 year from issuance
Renewal Process: 30 days before expiration, VeriTrust will notify KISC via email
Action Required: Confirm renewal (usually automatic for verified organizations)
Version: 1.0
Last Updated: 2026-01-30
Status: Ready for Submission