PluginBench
MCP Server
Active
MIT

io.github.Vorim-AI-Labs/vorim-mcp-server MCP Server

io.github.Vorim-AI-Labs/vorim-mcp-server

Cryptographic identity, scoped permissions, and tamper-evident audit trails for AI agents.

What is the io.github.Vorim-AI-Labs/vorim-mcp-server MCP server?

The Vorim AI MCP server gives every AI agent its own Ed25519 cryptographic identity, time-bounded scoped permissions, and a hash-linked audit trail. It exposes 19 tools for agent registration, permission management, credential delegation, audit logging, and public trust verification—enabling compliance-ready identity and trust for autonomous agents in Claude, Cursor, and any MCP-compatible client.

Vorim AI is the identity and trust layer for autonomous AI agents. It provides cryptographic identities, fine-grained permissions with rate limits, tamper-evident audit trails, and publicly verifiable trust scores. Use it to register agents, grant and revoke permissions, delegate credentials, log actions, and export signed audit bundles for compliance with EU AI Act, US Executive Order 14110, and SOC 2 requirements.

How to install io.github.Vorim-AI-Labs/vorim-mcp-server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • VORIM_API_KEY
    required
    secret

    Vorim API key (agid_sk_live_...)

  • VORIM_BASE_URL

    Vorim API base URL

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "vorim-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@vorim/mcp-server"
      ],
      "env": {
        "VORIM_API_KEY": "<YOUR_VORIM_API_KEY>",
        "VORIM_BASE_URL": "<YOUR_VORIM_BASE_URL>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • vorim_ping — Check API health and connectivity
  • vorim_register_agent — Register a new agent with Ed25519 cryptographic identity
  • vorim_register_ephemeral — Register a did:key ephemeral agent with TTL
  • vorim_get_agent — Get agent details by ID
  • vorim_list_agents — List all agents with pagination and filtering
  • vorim_update_agent — Update agent metadata (name, description, status)
  • vorim_revoke_agent — Permanently revoke an agent
  • vorim_check_permission — Check if agent has a permission scope (sub-5ms)
  • vorim_grant_permission — Grant a permission with optional expiry and rate limits
  • vorim_list_permissions — List all active permissions for an agent
  • vorim_revoke_permission — Revoke a specific permission scope
  • vorim_delegate_credential — Delegate OAuth credentials to an agent
  • vorim_request_token — Agent requests a short-lived access token
  • vorim_list_delegations — List active credential delegations
  • vorim_emit_event — Log an audit event for an agent action
  • vorim_export_audit — Export signed audit bundle with SHA-256 manifest
  • vorim_verify_trust — Verify agent trust score (public, no auth required)
  • vorim_onboard_start — Start device-authorization onboarding for a user with no API key; returns a user code and activation URL
  • vorim_onboard_check — Check whether the user approved onboarding and retrieve the issued API key

Use cases

  • Register and manage cryptographic identities for multiple autonomous AI agents
  • Grant time-bounded, scoped permissions with rate limits and revoke them on demand
  • Delegate OAuth credentials to agents for 24-hour or custom-duration access to external services
  • Log and export tamper-evident audit trails of agent actions for compliance and forensics
  • Verify public trust scores for agents without requiring authentication

io.github.Vorim-AI-Labs/vorim-mcp-server MCP server FAQ

What is the Vorim AI MCP server?

It's an MCP server that exposes 19 tools for managing AI agent identity, permissions, credentials, audit trails, and trust scores. Each agent gets its own Ed25519 keypair, scoped permissions, and a hash-linked audit log.

Is Vorim AI free?

Yes. Sign up at vorim.ai with no credit card required. You receive an API key with agents:*, audit:*, and trust:* scopes.

How do I install it in Claude Desktop?

Add the server to ~/Library/Application Support/Claude/claude_desktop_config.json with the command 'npx @vorim/mcp-server' and set the VORIM_API_KEY environment variable.

How do I install it in Cursor?

Add the server to .cursor/mcp.json in your project root with the command 'npx @vorim/mcp-server' and set the VORIM_API_KEY environment variable.

Do I need an API key?

Yes. Sign up at vorim.ai, go to Settings > API Keys, and create a key with agents:*, audit:*, and trust:* scopes.

What compliance standards does Vorim support?

Vorim is designed for EU AI Act, US Executive Order 14110, SOC 2, and GDPR compliance with cryptographic identity, fine-grained permissions, and tamper-evident audit trails.

README (reference)

Source of truth, from the repository.

Vorim AI — MCP Server

npm version smithery badge MIT License

Give every AI agent its own cryptographic identity, scoped permissions, and a tamper-evident audit trail — directly from Claude Desktop, Cursor, or any MCP-compatible client.

What is Vorim AI?

Vorim AI is the identity and trust layer for autonomous AI agents. It gives each agent its own Ed25519 keypair, time-bounded scoped permissions, hash-linked audit events, and a publicly verifiable trust score — so when an agent does something, you can prove who acted, what they were allowed to do, and what happened.

The protocol underneath (VAIP) is open, MIT-licensed, and submitted to IETF as draft-nyantakyi-vaip-agent-identity-01.

This package is the MCP (Model Context Protocol) server that exposes 19 Vorim tools to any MCP-compatible AI client.

Works with Claude Desktop, Cursor, VS Code, Google Antigravity, and any other MCP client.

Quick Start

npm install -g @vorim/mcp-server

Or run directly with npx:

VORIM_API_KEY=agid_sk_live_... npx @vorim/mcp-server

Configuration

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

Cursor

Add to .cursor/mcp.json in your project root:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

VS Code

Add to your VS Code MCP settings with the same format.

Google Antigravity

Add to the workspace config at .agents/mcp_config.json, or the global config at ~/.gemini/config/mcp_config.json:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

You can also add it from the UI: Settings → Customizations → Installed MCP Servers → Add MCP.

Get an API Key

  1. Sign up at vorim.ai (free, no credit card)
  2. Go to Settings > API Keys
  3. Create a key with agents:*, audit:*, trust:* scopes

Available Tools (19)

Health

ToolDescription
vorim_pingCheck API health and connectivity

Agent Identity

ToolDescription
vorim_register_agentRegister a new agent with Ed25519 cryptographic identity
vorim_register_ephemeralRegister a did:key ephemeral agent with TTL
vorim_get_agentGet agent details by ID
vorim_list_agentsList all agents with pagination and filtering
vorim_update_agentUpdate agent metadata (name, description, status)
vorim_revoke_agentPermanently revoke an agent

Permissions

ToolDescription
vorim_check_permissionCheck if agent has a permission scope (sub-5ms)
vorim_grant_permissionGrant a permission with optional expiry and rate limits
vorim_list_permissionsList all active permissions for an agent
vorim_revoke_permissionRevoke a specific permission scope

Credential Delegation

ToolDescription
vorim_delegate_credentialDelegate OAuth credentials to an agent
vorim_request_tokenAgent requests a short-lived access token
vorim_list_delegationsList active credential delegations

Audit

ToolDescription
vorim_emit_eventLog an audit event for an agent action
vorim_export_auditExport signed audit bundle with SHA-256 manifest

Trust

ToolDescription
vorim_verify_trustVerify agent trust score (public, no auth required)

Onboarding

ToolDescription
vorim_onboard_startStart device-authorization onboarding for a user with no API key; returns a user code and activation URL
vorim_onboard_checkCheck whether the user approved onboarding and retrieve the issued API key

Example Usage

Once configured, use natural language in Claude, Cursor, or any MCP client:

  • "Register an agent called invoice-processor with read and execute permissions"
  • "Check if agent agid_acme_a1b2 has permission to execute"
  • "Log a tool_call event for the agent: action=process_invoice, result=success"
  • "What's the trust score for agent agid_acme_a1b2?"
  • "Export the audit trail for the last 30 days"
  • "Delegate my GitHub OAuth token to this agent for 24 hours"
  • "Revoke agent agid_acme_a1b2"

Why Use Vorim AI

  • Cryptographic identity — Ed25519 keypairs for every agent. Not a shared service account.
  • Fine-grained permissions — 7 scopes with time bounds and rate limits, sub-5ms checks.
  • Tamper-evident audit trails — SHA-256 hash-linked events, signed export bundles for compliance.
  • Public trust scoring — anyone can verify any agent without auth (no shared secrets).
  • Open protocol — VAIP submitted to IETF, MIT-licensed, freely implementable.
  • Compliance-ready — EU AI Act, US Executive Order 14110, SOC 2, GDPR.

Environment Variables

VariableRequiredDefaultDescription
VORIM_API_KEYYes—Your Vorim API key (agid_sk_live_...)
VORIM_BASE_URLNohttps://api.vorim.aiAPI base URL (override for self-hosted)

Links

License

MIT — see LICENSE for details.


Built by Vorim AI. Questions or feedback: kwame@vorim.ai.

Related MCP servers

Connect AI assistants to Outline for document search, reading, and management

153
Python
MIT
View repository →

MCP server for Tekna events and news

0
Python
MIT
View repository →

Verifiable shared memory for AI agents: signed facts about the physical world, no key required.

39
Rust
Apache-2.0
View repository →

Compile EUDR Annex II Due Diligence Statements from operator, supplier, and plot geolocation.

0
View repository →

Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture

6
TypeScript
View repository →

Publish AI images & video to Vynly, the AI-only social feed. Verified provenance, no signup.

3
JavaScript
MIT
View repository →