193 lines
5.1 KiB
Markdown
193 lines
5.1 KiB
Markdown
# MCPF Initialize Response - Expected Format
|
|
|
|
## Request Format
|
|
```bash
|
|
curl -X POST http://localhost:8787/mcp \
|
|
-H "Content-Type: application/json" \
|
|
-H "Accept: application/json, text/event-stream" \
|
|
-d '{
|
|
"jsonrpc": "2.0",
|
|
"method": "initialize",
|
|
"params": {
|
|
"protocolVersion": "2025-03-26",
|
|
"capabilities": {},
|
|
"clientInfo": {
|
|
"name": "test-client",
|
|
"version": "1.0"
|
|
}
|
|
},
|
|
"id": 1
|
|
}'
|
|
```
|
|
|
|
## Response Format (SSE Stream)
|
|
|
|
The server returns Server-Sent Events (SSE) format:
|
|
|
|
```
|
|
event: message
|
|
data: {JSON_RESPONSE}
|
|
```
|
|
|
|
## Complete JSON Response Structure
|
|
|
|
```json
|
|
{
|
|
"result": {
|
|
"protocolVersion": "2025-03-26",
|
|
"capabilities": {
|
|
"tools": {
|
|
"listChanged": true
|
|
}
|
|
},
|
|
"serverInfo": {
|
|
"name": "kisc-arch-kultura-valodu-mcp",
|
|
"version": "0.2.0"
|
|
},
|
|
"_meta": {
|
|
"identity": {
|
|
"id": "did:web:llm.kis.gov.lv",
|
|
"service": {
|
|
"mcp": "https://llm.kis.gov.lv/mcp"
|
|
},
|
|
"keys": {
|
|
"jwks_uri": "https://llm.kis.gov.lv/.well-known/jwks.json"
|
|
}
|
|
},
|
|
"mcpf": {
|
|
"version": "0.1",
|
|
"spec": {
|
|
"repository": "https://github.com/MCPTrustFramework/MCPF-specification"
|
|
},
|
|
"entrypoint": {
|
|
"type": "manifest",
|
|
"url": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json"
|
|
},
|
|
"artifacts": {
|
|
"trust_registry": "https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json",
|
|
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json"
|
|
}
|
|
},
|
|
"trust": {
|
|
"verifications": [
|
|
{
|
|
"verifier": "did:web:veritrust.vc",
|
|
"type": [
|
|
"VerifiableCredential",
|
|
"MCPServerVerification"
|
|
],
|
|
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json",
|
|
"covers": "did:web:llm.kis.gov.lv",
|
|
"proof_hint": {
|
|
"verificationMethod": "did:web:veritrust.vc#key-1",
|
|
"created": "2026-01-29T10:12:41Z"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"jsonrpc": "2.0",
|
|
"id": 1
|
|
}
|
|
```
|
|
|
|
## MCPF Layer 1: Session-Level Trust Metadata
|
|
|
|
The `_meta` field contains three key sections:
|
|
|
|
### 1. Identity
|
|
```json
|
|
{
|
|
"id": "did:web:llm.kis.gov.lv",
|
|
"service": {
|
|
"mcp": "https://llm.kis.gov.lv/mcp"
|
|
},
|
|
"keys": {
|
|
"jwks_uri": "https://llm.kis.gov.lv/.well-known/jwks.json"
|
|
}
|
|
}
|
|
```
|
|
|
|
**Purpose:** Establishes the server's decentralized identity (DID) and key material location.
|
|
|
|
### 2. MCPF Metadata
|
|
```json
|
|
{
|
|
"version": "0.1",
|
|
"spec": {
|
|
"repository": "https://github.com/MCPTrustFramework/MCPF-specification"
|
|
},
|
|
"entrypoint": {
|
|
"type": "manifest",
|
|
"url": "https://llm.kis.gov.lv/.well-known/mcp/manifest.json"
|
|
},
|
|
"artifacts": {
|
|
"trust_registry": "https://llm.kis.gov.lv/.well-known/mcp-trust-registry.json",
|
|
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json"
|
|
}
|
|
}
|
|
```
|
|
|
|
**Purpose:** Links to MCPF specification and trust artifacts for agent discovery.
|
|
|
|
### 3. Trust Verifications
|
|
```json
|
|
{
|
|
"verifications": [
|
|
{
|
|
"verifier": "did:web:veritrust.vc",
|
|
"type": ["VerifiableCredential", "MCPServerVerification"],
|
|
"credential": "https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json",
|
|
"covers": "did:web:llm.kis.gov.lv",
|
|
"proof_hint": {
|
|
"verificationMethod": "did:web:veritrust.vc#key-1",
|
|
"created": "2026-01-29T10:12:41Z"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
```
|
|
|
|
**Purpose:** Documents third-party verification by VeriTrust credential service.
|
|
|
|
## Verification Steps
|
|
|
|
An MCPF-aware agent should:
|
|
|
|
1. **Extract DID** from `_meta.identity.id`
|
|
2. **Resolve DID document** at `https://llm.kis.gov.lv/.well-known/did.json`
|
|
3. **Fetch verification credential** from VeriTrust
|
|
4. **Verify credential signature** using VeriTrust's public key
|
|
5. **Check credential subject** matches server DID
|
|
6. **Optionally fetch** trust registry and manifest for additional context
|
|
|
|
## Test with jq
|
|
|
|
Extract specific fields:
|
|
|
|
```bash
|
|
# Get the DID
|
|
curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.identity.id'
|
|
# Output: did:web:llm.kis.gov.lv
|
|
|
|
# Get MCPF version
|
|
curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.mcpf.version'
|
|
# Output: 0.1
|
|
|
|
# Get verifier DID
|
|
curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.trust.verifications[0].verifier'
|
|
# Output: did:web:veritrust.vc
|
|
|
|
# Get credential URL
|
|
curl ... | grep '^data:' | sed 's/^data: //' | jq -r '.result._meta.trust.verifications[0].credential'
|
|
# Output: https://veritrust.vc/portal/mcp/credentials/aec9930b-9139-4b33-ac6f-ad3bd3d91da0.json
|
|
```
|
|
|
|
## Notes
|
|
|
|
- The `_meta` field is **in addition to** standard MCP initialize response fields
|
|
- Backward compatible: non-MCPF clients ignore `_meta`
|
|
- Layer 1 (session-level) + Layer 2 (per-response attestations) = Dual-layer trust
|
|
- Session ID returned in `Mcp-Session-Id` response header (not shown in JSON)
|