Skip to main content
Glama
thefraudfather

FLINT Agent Passport

FLINT Cross-Domain Agent Passport

Know Your Agent at transaction time. Verify an AI agent's integrity and authority with FLINT before it moves money, and keep a signed record of what was checked.

License: MIT MCP Site


What this is

This repository is the FLINT plugin for Claude Code and Cowork. It bundles two things:

  1. The FLINT remote connector — a hosted MCP server at https://flint.network/mcp that exposes FLINT's agent-verification tools. Nothing to run locally, no account required to start.

  2. The verify-agent-integrity skill — a guided workflow that runs the verify-before-pay loop for you, so the assistant confirms an agent is authorized and uncompromised before it spends.

FLINT is the neutral verification network for AI agents that transact. It does not issue agents and it does not move money. It verifies, at the moment value moves, that the specific agent asking to pay is the one it claims to be, is still inside the authority it was granted, and has not been taken over. Every check returns a clear verdict and a signed record the counterparty keeps as evidence.

Related MCP server: Proof Layer MCP

Why it exists

AI agents are being handed spending authority across stablecoin and card rails. The fraud and identity stack was built for humans: a device, a session, an account the institution itself issued and could watch. An agent transacting directly against an API has none of that, and the counterparty it transacts with did not issue it. Proving the human is real does not tell you the agent acting for them right now is authorized and uncompromised. That is the layer FLINT verifies.

Install

As a plugin (Claude Code or Cowork):

/plugin marketplace add thefraudfather/flint-plugin
/plugin install flint@flint-network

This installs both the remote connector and the verify-agent-integrity skill.

Connector only (any MCP-compatible client):

Point your client at the FLINT remote server. The connection is a single entry:

{
  "mcpServers": {
    "flint": {
      "type": "streamable-http",
      "url": "https://flint.network/mcp"
    }
  }
}

Or connect from flint.network/connect.

The verify-before-pay loop

The skill runs this loop; you can also call the tools directly.

  1. Issue a passport for the agent — issue_agent_passport. Free, hybrid-signed, returns a public verifiable URL. Agent name or id is enough.

  2. Authorize the intended action before any spend — issue_authorization_record. Binds the agent to a scope (what, how much, to whom).

  3. Verify at the moment of execution — verify_agent_authority. Returns a four-state verdict: allow, step-up, review, or block.

  4. Record the result after completion, dispute, or review — submit_transaction_outcome. Feeds the cross-merchant reputation signal and leaves a retained record.

Tools

The connector exposes ten tools:

Tool

Purpose

issue_agent_passport

Issue a free, hybrid-signed passport for an agent; returns a public verifiable URL.

get_agent_passport

Fetch an existing passport and its current state.

create_flint_trust_manifest

Produce a portable trust manifest for an agent.

generate_authorization_scope

Build a scope describing what an agent is permitted to do.

issue_authorization_record

Bind an agent to an authorization before a spend.

update_agent_mandate

Update the standing mandate that governs an agent's authority.

verify_agent_authority

Verify authority and integrity at transaction time; returns the four-state verdict.

lookup_agent_reputation

Check an agent's cross-merchant reputation before a higher-risk deal.

submit_transaction_outcome

Record the outcome after completion, dispute, or review.

validate_agent_commerce_readiness

Score how ready an agent or flow is to transact.

How verification works

At the transaction handshake, FLINT runs six locked verification layers:

Principal Identity (the human or organization the agent acts for), Agent Identity (the specific agent it claims to be), Wallet Provenance (the funding source is what it should be), Authorization Scope (the action falls inside the authority granted), Environment Identity (the agent is running where its history says it runs), and Cross-Merchant Reputation (how the agent has behaved across the network).

Each verification returns one of four verdicts — allow, step-up, review, block — and a signed verification record. Records are hybrid-signed with both a classical and a post-quantum signature, so the evidence holds as cryptography evolves.

Learn more

About

FLINT is built by KillChain, Inc. (d/b/a FLINT Network). FLINT is rail-agnostic and neutral by design: it verifies the agent so identity providers can keep proving the human and the rails can keep moving the money.

Questions or partnership: contact@flint.network

License

MIT. See LICENSE.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityStale
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Security layer for AI agents that evaluates transaction intents and returns verdicts (ALLOW/WARN/DENY) using deterministic rules, on-chain checks, and simulation.
    11
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides cryptographic governance receipts for AI agents, enabling pre-execution evaluation and signed verdicts (EXECUTE/BLOCK/REVIEW/SHADOW) with offline-verifiable audit trails.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to get read-only trust verdicts on knowledge records by evaluating evidence maturity, provenance, intended use, risk level, and scope before deciding whether knowledge may be used.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Provides tools to evaluate an AI agent's step before execution, returning signed ALLOW/DENY receipts, and to verify receipt chain integrity.
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/thefraudfather/flint-plugin'

If you have feedback or need assistance with the MCP directory API, please join our Discord server