Skip to main content
Glama

trooth_verify

Read-onlyIdempotent

Verify a Trooth Trust Ledger Token (a signed, portable trust receipt in tlt2 / tlt form, or its JTI). Re-runs both signatures independently and returns whether the token is valid, expired, revoked, or tampered - plus honest provenance: Trooth's outer signature attests only the witnessing event and the byte-for-byte payload at issuance, never the truthfulness of the declared claims. Unknown tokens return an honest not-found.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
tokenYesA Trust Ledger Token (tlt2. or tlt. form) or its JTI

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYesMachine-branchable outcome for this lookup.
subjectYesThe company, domain or token this answer is about.
summaryYesThe same answer as the text content, for display.
claim_urlNoPresent only when the subject has no published record and could be claimed by its owner.
provenanceYesWhere this answer came from. An honest_absence is missing data, never a judgment about the subject.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Changed1 schema field changed
    • changedInput schema / properties / token / description
      Previous value: -"A Trust Ledger Token (tlt2.… / tlt.…) or its JTI"New value: +"A Trust Ledger Token (tlt2. or tlt. form) or its JTI"
  2. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "claim_url": {
      +      "description": "Present only when the subject has no published record and could be claimed by its owner.",
      +      "type": "string"
      +    },
      +    "provenance": {
      +      "description": "Where this answer came from. An honest_absence is missing data, never a judgment about the subject.",
      +      "enum": [
      +        "witnessed_signed",
      +        "signed_scan",
      +        "live_observation",
      +        "honest_absence",
      +        "withheld_by_owner",
      +        "knowledge_base",
      +        "input_error"
      +      ],
      +      "type": "string"
      +    },
      +    "status": {
      +      "description": "Machine-branchable outcome for this lookup.",
      +      "enum": [
      +        "published",
      +        "listed",
      +        "unclaimed",
      +        "private",
      +        "observed",
      +        "valid",
      +        "invalid",
      +        "expired",
      +        "revoked",
      +        "answered",
      +        "out_of_scope",
      +        "bad_input"
      +      ],
      +      "type": "string"
      +    },
      +    "subject": {
      +      "description": "The company, domain or token this answer is about.",
      +      "type": "string"
      +    },
      +    "summary": {
      +      "description": "The same answer as the text content, for display.",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "status",
      +    "provenance",
      +    "subject",
      +    "summary"
      +  ],
      +  "type": "object"
      +}
  3. First observed

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations, the description adds valuable behavioral detail: it re-runs both signatures independently, reports specific outcome categories, explicitly states the provenance limitation that Trooth's outer signature does not attest truthfulness, and discloses that unknown tokens return a not-found result.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences deliver purpose, outcome categories, behavioral caveats, and unknown-token handling. The description is front-loaded and every sentence adds distinct, necessary information without filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema available and one fully documented parameter, the description covers behavior, result categories, provenance limits, and unknown-token handling. It is complete for calling the tool correctly, though it could be stronger by explicitly positioning itself against sibling tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already documents the single token parameter with 100% coverage, including tlt2/tlt/JTI forms. The description repeats these accepted forms but adds no new parameter-level semantics beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with an explicit verb and resource: 'Verify a Trooth Trust Ledger Token,' and further specifies accepted forms (tlt2/tlt/JTI). It clearly distinguishes the verification function from sibling tools by stating exactly what it returns: valid, expired, revoked, or tampered.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies appropriate usage—when you have a token or JTI and need its validity status—but it never explicitly contrasts trooth_verify with sibling tools like trooth_ask, trooth_outside_in_read, or trooth_public_trust_profile. No when-not-to-use guidance is provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.4/5.0
Disambiguation5/5

Each tool targets a distinct purpose: product Q&A, live security observation, published trust profile lookup, and token verification. Even the two domain-related tools are clearly separated by live scan versus published record.

Naming Consistency3/5

All tools share the trooth_ prefix and snake_case style, but the post-prefix names are mixed: ask and verify are bare verbs, outside_in_read is a compound verb, and public_trust_profile is a noun. This is readable but not a consistent verb_noun pattern.

Tool Count5/5

Four tools is a well-scoped count for this server's purpose. Each tool earns its place with no obvious redundancy or bloat.

Completeness5/5

The tool surface covers the core read-only lifecycle: product knowledge, live security reads, trust profile lookup, and token verification. There are no obvious dead ends or missing operations for the apparent domain.

Resources