Veritap
Provides an MCP endpoint for agents to check whether a real-world fact can be verified, covering businesses, listings, objects, and places, while refusing claims about individuals. It acts as a demand sensor that logs verification attempts, even for unfulfillable requests.
README
Veritap
An MCP endpoint where agents check whether a real-world fact can be verified — before acting on it.
Live: https://veritap.dev/mcp · npm: veritap-mcp · MCP registry: dev.veritap/veritap
{ "mcpServers": { "veritap": { "command": "npx", "args": ["-y", "veritap-mcp"] } } }
Free, no auth, read-only, and it never returns a bare failure. Covers businesses, listings, objects and places. Claims about individuals are refused as a matter of policy.
What works today
- Business-exists claims are answered on the spot -- an automated desk check across GLEIF LEI records, SEC EDGAR filings, Wikidata, and website liveness returns a dated evidence bundle with sources and an honest confidence. Free while verification is new. Never a bare verdict.
- Triage (
triage_unknowns): batch every uncertainty in a task; each is classified as answerable-yourself (with a suggested source), verifiable here, or not determinable (with planning advice). Items you can settle yourself are routed away, not sold to you. - Plan mapping (
plan_verification): which steps of a multi-step plan rest on checkable real-world facts. - Feasibility checks (
check_feasibilityand friends): call speculatively before relying on, buying from, or citing anything seen online.
Answers repeat instantly from a shared attestation cache. Nothing is charged; paid verification is not open.
What this actually is
A demand sensor. The product is the ledger, not the verification.
Agents constantly hit steps that depend on facts they cannot confirm, and today they either guess or silently drop the step — so the demand is invisible. Every call here writes a structured row: what was asked, what it was worth to the caller, and whether anything could answer it. Requests we cannot fulfil are the most valuable rows in the database.
That dataset cannot be backfilled, which is why the endpoint went live before fulfillment existed.
Design decisions worth knowing
- No human in the loop, ever. No dispatch, no verifier network. If the copy
ever implies otherwise,
scripts/a3-audit.mjsfails the build. - No outbound referrals. A miss keeps its signal in-house, so it must stay
decision-grade on its own: closest alternatives, honest self-help, and a real
promise to report back (
src/notify.ts). - Quarantine, don't drop. Suspected flooding tags rows rather than refusing them. A wrongly-throttled agent prunes us from its tool rotation permanently; a wrongly-tagged row costs nothing and can be un-flagged later.
- Claims about people are refused, not deferred. FCRA exposure and the
obvious harassment vector. Refusals are logged without their text.
scripts/policy-check.tsis a two-sided control battery — a gate that refuses nothing and a gate that is switched off look identical from the outside. - The fingerprint is not an identity. MCP has no installation id, so components are stored separately rather than baking a guess into a hash.
Layout
src/index.ts Worker entry, MCP protocol layer, cron
src/router.ts the core: normalize -> hash -> cache -> catalog -> ledger
src/policy.ts people-claim exclusion (hard refusal)
src/triage.ts unknown classification, routes web-answerable items away
src/notify.ts the return path: report back when a gap closes
src/ledger.ts append-only demand ledger, batched writes
src/admin.ts operator dashboard, Cloudflare Access protected
public/ agent-legible surface: llms.txt, openapi, well-known, pages
docs/decisions.md every deviation from spec, with reasoning
Develop
npm install
npx wrangler d1 migrations apply groundtruth --local
npx wrangler dev
Gates that must pass before any deploy:
npx tsc --noEmit
node scripts/a3-audit.mjs # honesty: no dispatch, no referral, no purchasability
node scripts/policy-check.ts # people-claim gate, both directions
./scripts/history-scan.sh # secrets across git HISTORY, before any public push
history-scan.sh exists because a working-tree audit cannot catch what a
public push actually exposes. Grepping git ls-files only ever sees the
current checkout — it passes happily while earlier commits, and commit
messages, still carry the thing you removed.
Secrets are never committed. ALERT_EMAIL and NTFY_TOPIC are set with
wrangler secret put — the ntfy topic in particular is a capability, since
anyone holding it can both read the digest and publish alerts to the operator.
Stack
Cloudflare Workers (stateless createMcpHandler — no Durable Objects), D1,
@modelcontextprotocol/server v2. A frozen project costs $0 to leave running,
which is the point: the sensor keeps accruing whether or not anyone is watching.
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。