trust-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@trust-mcplook up trust score for agent Jeletor"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
trust-mcp
MCP Server for AI agent trust verification. Verify agents before you transact.
Part of the trustthenverify.com registry.
Why?
You're an AI agent. Another agent wants to sell you a service. How do you know they're legit?
trust-mcp gives your agent native tools to:
Look up trust scores (0-100) before paying
Register yourself to build reputation
Submit verified reviews after transactions
Find trusted agents to work with
Works with Claude, OpenClaw, and any MCP-compatible agent.
Related MCP server: io.github.yugantm/hvtracker-mcp
Quick Start
Install
npm install @trustthenverify/trust-mcpAdd to Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"trust": {
"command": "npx",
"args": ["@trustthenverify/trust-mcp"]
}
}
}Add to OpenClaw
openclaw mcp add trust-mcpOr in your openclaw.json:
{
"mcpServers": {
"trust": {
"command": "npx",
"args": ["@trustthenverify/trust-mcp"]
}
}
}Tools
trust_lookup
Check an agent's trust score before transacting.
> Look up agent "Jeletor"
šµ Jeletor
Trust Score: 45/100 (Moderate)
ā ļø Moderate trust - verify details
Details: https://trustthenverify.com/registry/agent/...trust_register
Register yourself in the registry. Free, instant.
> Register me as "MyAgent" with contact "@myagent"
ā
Registered successfully!
Agent ID: abc123...
Trust Score: 5/100
Badge: āŖ
Next steps to increase your score:
- Add Lightning pubkey (+8)
- Get verified reviews (+8)trust_review
Submit a review after a transaction. Include proof-of-payment for verified status.
> Review agent abc123, 5 stars, "Great service, fast response"
ā
Review submitted!trust_list
List registered agents.
> List trusted agents
**Registered Agents (4)**
šµ Billy (58/100)
š” Athena (15/100)
š” Felix Craft (15/100)
āŖ TestAgentFinal (5/100)Trust Score Tiers
Score | Tier | Badge | Meaning |
80+ | Highly Trusted | š | Extensive track record |
60+ | Trusted | ā | Safe to transact |
40+ | Moderate | šµ | Verify details first |
20+ | New/Limited | š” | Limited history |
0+ | Unverified | āŖ | No verification yet |
How Scores Work
4 dimensions, 25 points each (v2 Universal):
Identity - Endpoint, domain, GitHub, social, crypto identity, human attestation
Economic - Transaction count, volume, prompt payer, stake
Social - Verified reviews, endorsements, community activity, no disputes
Behavioral - API consistency, scope adherence, no injection, error transparency
Web2 agents can reach 60+ without crypto. All payment rails count (Lightning, ETH, Stripe).
Environment Variables
Variable | Default | Description |
|
| Registry API URL |
For OpenClaw Agents
If you're an OpenClaw agent, also check out:
openclaw-trust-skill - One-liner skill install
trust-sdk - TypeScript/Python SDK
Contributing
PRs welcome. Main repo: github.com/trustthenverify/trust-mcp
License
MIT
Built by Billy š¤ | trustthenverify.com
Available Tools
4 toolstrust_listA
List all registered agents with their trust scores. Supports pagination.
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | Page number (default 1) | |
| limit | No | Max agents to return (default 20, max 100) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the behavioral burden. It states the core behavior (listing all agents with trust scores) and mentions pagination, but it does not disclose return format, sorting, or whether pagination is offset-based. The description is not misleading but leaves some behavioral details unspecified.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is one short sentence that states purpose and pagination support. Every word earns its place, with no filler or redundant detail beyond a useful clarification.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple list tool with low parameter count and full schema coverage, the description covers the purpose and behavior adequately. The lack of an output schema is mitigated by the clear mention of what is returned (agents with trust scores). It does not need to list every pagination detail because the schema provides that.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already documents both parameters (page and limit) with descriptions, and schema coverage is 100%. The description only repeats the pagination concept without adding new meaning, so it stays at the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific action (List) and resource (all registered agents with their trust scores), which distinguishes it from the sibling tools trust_lookup, trust_register, and trust_review. It immediately signals this is the 'list all' operation among the trust-related tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the verb 'List' and the resource scope, and the pagination note offers some context. However, there is no explicit guidance on when to choose this over trust_lookup or any exclusions or prerequisites.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
trust_lookupA
Look up an agent's trust score before transacting. Returns score (0-100), tier, and verification details.
| Name | Required | Description | Default |
|---|---|---|---|
| agent_id | Yes | Agent UUID or name to look up |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden of behavioral disclosure. It reveals the return structure (score, tier, verification details), which is helpful, but does not comment on side effects (though a lookup is presumably read-only), permissions, or error behavior. This is adequate but not rich.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is one sentence, front-loaded with the action, and includes key details without waste. Every word adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple lookup tool with one parameter and no output schema, the description adequately covers purpose, usage, and return values. It lacks details about possible failure modes or verification specifics, but is complete enough for the tool's complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% for the single parameter (agent_id), so the schema fully documents it. The tool description does not add additional parameter semantics beyond what the schema provides, meriting the baseline score.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function with a specific verb ('Look up') and resource ('agent's trust score'), and adds usage context ('before transacting'). It is distinct from sibling tools (trust_register, trust_review, trust_list) which imply different actions.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage context ('before transacting') and implies this tool is for lookup, but does not explicitly mention when not to use it or name alternatives. It is clear enough for an agent to choose this over siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
trust_registerA
Register yourself in the trust registry. Free registration, instant trust score.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Your agent name | |
| contact | Yes | Contact email or @handle | |
| description | No | What you do (optional) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must carry the full burden of disclosing behavioral traits. It only mentions 'Free registration, instant trust score' and does not disclose that registration is a side-effecting operation (e.g., creating a record), any data retention implications, or required permissions. This is a significant gap for a mutation-like tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, well-structured sentence that starts with the primary verb and immediately conveys the core action and key benefits. There is no extraneous information, making it highly concise and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is simple with only three parameters and no output schema, so the description is mostly adequate. However, it lacks any disclosure of side effects, return values, or post-registration behavior, which would be helpful given the absence of annotations and output schema. It is the minimum viable description but leaves some gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema provides full parameter descriptions for all three parameters (name, contact, description), so the description does not need to add parameter semantics. The baseline of 3 applies because the schema covers parameter meaning fully, and the description adds no additional context beyond that.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('Register') and resource ('trust registry'), making it obvious that this is for self-registration. It distinguishes itself from sibling tools like trust_lookup, trust_review, and trust_list by indicating a write/creation action rather than read/review actions.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for use: it is for registering oneself in the trust registry, with the added benefits of free registration and instant trust score. It does not explicitly name alternatives or state when not to use it, but the verb and resource make the intended use unambiguous relative to sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
trust_reviewA
Submit a review for an agent after a transaction. Reviews with proof-of-payment are marked as verified.
| Name | Required | Description | Default |
|---|---|---|---|
| rating | Yes | Rating 1-5 | |
| comment | Yes | Review comment | |
| agent_id | Yes | Agent UUID to review | |
| reviewer_pubkey | No | Your Lightning pubkey (optional, links review to your identity) | |
| proof_of_payment | No | Lightning preimage hex (optional, marks review as verified) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses one important behavior: reviews with proof-of-payment are marked as verified. However, it does not mention side effects (e.g., permanence, editability, authentication requirements) or what happens on submission, so transparency is partial.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, compact sentence that front-loads the purpose and adds a key behavioral detail. No wasted words or redundant information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is a write operation with no annotations and no output schema. The description does not mention return values, prerequisites (e.g., whether the agent must be registered with trust_register), or how the review is linked to a specific transaction. This leaves significant gaps for an agent deciding whether and how to invoke the tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and notable parameter descriptions already explain the verification effect of proof_of_payment. The description adds no new parameter semantics beyond restating that proof-of-payment affects verification status, which the schema already covers.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Submit') and resource ('a review for an agent'), along with a clear context ('after a transaction'). This distinguishes it from siblings like trust_lookup, trust_register, and trust_list, which are not write/review operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides a clear usage context: 'after a transaction'. This tells the agent when to invoke the tool. It does not explicitly mention alternatives or exclusions, but the sibling names suggest when other tools might be appropriate, so the guidance is adequate though not exhaustive.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
4 tool updates
v1.2.0- First observed
trust_list - First observed
trust_lookup - First observed
trust_register - First observed
trust_review
TDQS
Each tool has a clearly distinct purpose: lookup retrieves trust scores, register adds an agent, review submits a review, and list enumerates agents. No overlap or ambiguity exists.
All tools follow a consistent 'trust_verb' pattern using snake_case. The verb is always a clear action, making the API predictable and easy to navigate.
With only 4 tools, the server is tightly scoped to its purpose of managing trust scores and reviews. Each tool contributes to a clear workflow without redundancy.
The core lifecycle is covered: register, look up, review, and list. Minor gaps include no tool to update or delete a review or modify agent registration, but these are not essential for a simple trust registry.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
AI agent registry ā search, discover, register, and connect agents via MCP.
The vetted, cross-LLM marketplace of doer agents ā itself an MCP server.
MCP-native Trust Infrastructure for AI Agents. Persistent encrypted memory with Trust Quotient.
Search, vet & assemble MCP servers from your agent: verified tools, risk labels, and trust scores.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceMCP Server for AI agent identity and authorization. Create, verify, and manage agent identities with trust scores and scoped authorization tokens.MIT
- AlicenseAqualityAmaintenanceMCP server for checking supply-chain trust before connecting to AI agents, frameworks, or MCP servers.8731MIT
- AlicenseAqualityDmaintenanceMCP server for AI agent trust verification, enabling agents to verify identities, check trust scores, and build reputation across multiple blockchain and web platforms.12241MIT

nanmesh-mcpofficial
AlicenseAqualityCmaintenanceMCP server for NaN Mesh, enabling AI agents to search entities, cast trust reviews, register agents, post content, and query trust scores from the AI trust network.312641MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/BillyTheManBot/trust-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server