io.github.Kzino/vorim-mcp-server MCP Server
io.github.Kzino/vorim-mcp-server
Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.
What is the io.github.Kzino/vorim-mcp-server MCP server?
The Vorim AI MCP server gives every AI agent its own Ed25519 cryptographic identity, time-bounded scoped permissions, and a hash-linked audit trail. It exposes 19 tools for agent registration, permission management, credential delegation, audit logging, and trust verification—enabling compliance-ready autonomous agent governance directly from Claude, Cursor, or any MCP client.
Vorim AI is the identity and trust layer for autonomous agents. It provides cryptographic identities, fine-grained permission scoping with sub-5ms checks, tamper-evident audit trails, and publicly verifiable trust scores. Use it to register agents, grant and revoke permissions, delegate credentials, log actions, and export signed audit bundles for compliance.
How to install io.github.Kzino/vorim-mcp-server
Copy-paste configuration for popular MCP clients.
VORIM_API_KEYrequiredsecretVorim API key (agid_sk_live_...)
VORIM_BASE_URLVorim API base URL
Tools & capabilities
Tools this server exposes to the agent.
vorim_ping— Check API health and connectivityvorim_register_agent— Register a new agent with Ed25519 cryptographic identityvorim_register_ephemeral— Register a did:key ephemeral agent with TTLvorim_get_agent— Get agent details by IDvorim_list_agents— List all agents with pagination and filteringvorim_update_agent— Update agent metadata (name, description, status)vorim_revoke_agent— Permanently revoke an agentvorim_check_permission— Check if agent has a permission scope (sub-5ms)vorim_grant_permission— Grant a permission with optional expiry and rate limitsvorim_list_permissions— List all active permissions for an agentvorim_revoke_permission— Revoke a specific permission scopevorim_delegate_credential— Delegate OAuth credentials to an agentvorim_request_token— Agent requests a short-lived access tokenvorim_list_delegations— List active credential delegationsvorim_emit_event— Log an audit event for an agent actionvorim_export_audit— Export signed audit bundle with SHA-256 manifestvorim_verify_trust— Verify agent trust score (public, no auth required)vorim_onboard_start— Start device-authorization onboarding for a user with no API key; returns a user code and activation URLvorim_onboard_check— Check whether the user approved onboarding and retrieve the issued API key
Use cases
- Register and manage cryptographic identities for autonomous AI agents with Ed25519 keypairs
- Grant, check, and revoke fine-grained permissions with time bounds and rate limits for agent actions
- Delegate OAuth credentials to agents and issue short-lived access tokens for secure credential management
- Log and export tamper-evident audit trails with SHA-256 hash-linked events for compliance and governance
- Verify public trust scores for agents without requiring authentication or shared secrets
io.github.Kzino/vorim-mcp-server MCP server FAQ
It's an MCP server that exposes 19 tools for managing AI agent identity, permissions, credential delegation, audit logging, and trust scoring. Each agent gets a cryptographic Ed25519 identity, scoped permissions with sub-5ms checks, and a tamper-evident audit trail.
Yes. Sign up at vorim.ai with no credit card required. You get an API key to use with the MCP server.
Install via npm (npm install -g @vorim/mcp-server) or use npx. Add the server to ~/Library/Application Support/Claude/claude_desktop_config.json with your VORIM_API_KEY environment variable.
Add the server to .cursor/mcp.json in your project root with the command npx @vorim/mcp-server and your VORIM_API_KEY environment variable.
Yes. Sign up at vorim.ai, go to Settings > API Keys, and create a key with agents:*, audit:*, and trust:* scopes.
VAIP (Vorim Agent Identity Protocol), which is open-source, MIT-licensed, and submitted to IETF as draft-nyantakyi-vaip-agent-identity-01.
README (reference)
Source of truth, from the repository.
Vorim AI — MCP Server
Give every AI agent its own cryptographic identity, scoped permissions, and a tamper-evident audit trail — directly from Claude Desktop, Cursor, or any MCP-compatible client.
What is Vorim AI?
Vorim AI is the identity and trust layer for autonomous AI agents. It gives each agent its own Ed25519 keypair, time-bounded scoped permissions, hash-linked audit events, and a publicly verifiable trust score — so when an agent does something, you can prove who acted, what they were allowed to do, and what happened.
The protocol underneath (VAIP) is open, MIT-licensed, and submitted to IETF as draft-nyantakyi-vaip-agent-identity-01.
This package is the MCP (Model Context Protocol) server that exposes 19 Vorim tools to any MCP-compatible AI client.
Works with Claude Desktop, Cursor, VS Code, Google Antigravity, and any other MCP client.
Quick Start
npm install -g @vorim/mcp-server
Or run directly with npx:
VORIM_API_KEY=agid_sk_live_... npx @vorim/mcp-server
Configuration
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"vorim": {
"command": "npx",
"args": ["@vorim/mcp-server"],
"env": {
"VORIM_API_KEY": "agid_sk_live_..."
}
}
}
}
Cursor
Add to .cursor/mcp.json in your project root:
{
"mcpServers": {
"vorim": {
"command": "npx",
"args": ["@vorim/mcp-server"],
"env": {
"VORIM_API_KEY": "agid_sk_live_..."
}
}
}
}
VS Code
Add to your VS Code MCP settings with the same format.
Google Antigravity
Add to the workspace config at .agents/mcp_config.json, or the global config at ~/.gemini/config/mcp_config.json:
{
"mcpServers": {
"vorim": {
"command": "npx",
"args": ["@vorim/mcp-server"],
"env": {
"VORIM_API_KEY": "agid_sk_live_..."
}
}
}
}
You can also add it from the UI: Settings → Customizations → Installed MCP Servers → Add MCP.
Get an API Key
- Sign up at vorim.ai (free, no credit card)
- Go to Settings > API Keys
- Create a key with
agents:*,audit:*,trust:*scopes
Available Tools (19)
Health
| Tool | Description |
|---|---|
vorim_ping | Check API health and connectivity |
Agent Identity
| Tool | Description |
|---|---|
vorim_register_agent | Register a new agent with Ed25519 cryptographic identity |
vorim_register_ephemeral | Register a did:key ephemeral agent with TTL |
vorim_get_agent | Get agent details by ID |
vorim_list_agents | List all agents with pagination and filtering |
vorim_update_agent | Update agent metadata (name, description, status) |
vorim_revoke_agent | Permanently revoke an agent |
Permissions
| Tool | Description |
|---|---|
vorim_check_permission | Check if agent has a permission scope (sub-5ms) |
vorim_grant_permission | Grant a permission with optional expiry and rate limits |
vorim_list_permissions | List all active permissions for an agent |
vorim_revoke_permission | Revoke a specific permission scope |
Credential Delegation
| Tool | Description |
|---|---|
vorim_delegate_credential | Delegate OAuth credentials to an agent |
vorim_request_token | Agent requests a short-lived access token |
vorim_list_delegations | List active credential delegations |
Audit
| Tool | Description |
|---|---|
vorim_emit_event | Log an audit event for an agent action |
vorim_export_audit | Export signed audit bundle with SHA-256 manifest |
Trust
| Tool | Description |
|---|---|
vorim_verify_trust | Verify agent trust score (public, no auth required) |
Onboarding
| Tool | Description |
|---|---|
vorim_onboard_start | Start device-authorization onboarding for a user with no API key; returns a user code and activation URL |
vorim_onboard_check | Check whether the user approved onboarding and retrieve the issued API key |
Example Usage
Once configured, use natural language in Claude, Cursor, or any MCP client:
- "Register an agent called invoice-processor with read and execute permissions"
- "Check if agent agid_acme_a1b2 has permission to execute"
- "Log a tool_call event for the agent: action=process_invoice, result=success"
- "What's the trust score for agent agid_acme_a1b2?"
- "Export the audit trail for the last 30 days"
- "Delegate my GitHub OAuth token to this agent for 24 hours"
- "Revoke agent agid_acme_a1b2"
Why Use Vorim AI
- Cryptographic identity — Ed25519 keypairs for every agent. Not a shared service account.
- Fine-grained permissions — 7 scopes with time bounds and rate limits, sub-5ms checks.
- Tamper-evident audit trails — SHA-256 hash-linked events, signed export bundles for compliance.
- Public trust scoring — anyone can verify any agent without auth (no shared secrets).
- Open protocol — VAIP submitted to IETF, MIT-licensed, freely implementable.
- Compliance-ready — EU AI Act, US Executive Order 14110, SOC 2, GDPR.
Environment Variables
| Variable | Required | Default | Description |
|---|---|---|---|
VORIM_API_KEY | Yes | — | Your Vorim API key (agid_sk_live_...) |
VORIM_BASE_URL | No | https://api.vorim.ai | API base URL (override for self-hosted) |
Links
- Platform: vorim.ai
- API Docs: vorim.ai/docs
- Protocol Spec (VAIP): github.com/Vorim-AI-Labs/vorim-protocol
- TypeScript SDK: @vorim/sdk on npm
- Python SDK: vorim on PyPI
- OpenClaw Skill: Vorim-AI-Labs/vorim-openclaw-skill
- Agent Discovery: vorim.ai/.well-known/agent.json
License
MIT — see LICENSE for details.
Built by Vorim AI. Questions or feedback: kwame@vorim.ai.
Related MCP servers

joLink
A lightweight Java IDE for AI agents: incremental builds, fast tests, HotSwap and live debugging.

Docker MCP Server
Manage Docker (containers, images, Compose, Swarm, registries) via the Docker SDK and CLI.
Game-dev sprite tools: PNG/GIF to spritesheet, split, trim, animate. OAuth-authenticated MCP server.
ProphetKey MCP bridge - encrypted local-first API key vault for AI agents, keys never exposed

FailTrace
Debugging experiments for coding agents: reproduce failures and verify fixes with test evidence.

Metroidvania Studio
Create and edit connected 2D maps with a local, workspace-scoped MCP server and Lua scripts.