quantakrypto pqc-tools MCP Server
io.github.quantakrypto/pqc-tools
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
What is the quantakrypto pqc-tools MCP server?
The quantakrypto pqc-tools MCP server is a Model Context Protocol server that gives AI coding agents post-quantum cryptography readiness tools. It enables scanning codebases for quantum-vulnerable crypto (RSA, ECDSA, EdDSA, etc.), generating migration plans, and conformance-testing post-quantum implementations across 14 programming languages.
This server integrates quantakrypto's post-quantum readiness tooling into Claude and other AI agents. It provides 16 tools for scanning code, inventorying crypto usage, explaining vulnerabilities, suggesting hybrid approaches, generating compliance reports (CBOM, SARIF, evidence), planning migrations, triaging findings, remediating code, and probing live endpoints. Use it to identify quantum-vulnerable cryptography in your codebase, gate builds against compliance mandates (CNSA 2.0, NIST IR 8547), and plan migration to post-quantum algorithms.
How to install quantakrypto pqc-tools
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
scan— Scan codebase for quantum-vulnerable cryptography across 14 languages with readiness scoring and compliance mandate gating.inventory— Generate an inventory of cryptographic usage in the codebase.explain— Explain quantum vulnerabilities and their impact.suggest-hybrid— Suggest hybrid post-quantum/classical cryptography approaches.plan-migration— Generate a prioritized migration plan to post-quantum algorithms.cbom— Generate a cryptographic bill of materials.triage— Triage and re-rank findings with LLM assistance.remediate— Suggest and apply code remediations for quantum-vulnerable crypto.probe-endpoint— Actively probe live TLS/SSH endpoints for post-quantum readiness.conformance-test— Conformance-test post-quantum implementations against FIPS 203/204/205.
Use cases
- Scan a codebase to identify all quantum-vulnerable cryptography (RSA, ECDSA, EdDSA, etc.) and get a readiness score.
- Generate a compliance report showing which cryptographic findings violate CNSA 2.0 or NIST IR 8547 mandates with dated deadlines.
- Plan a phased migration from classical to post-quantum cryptography with prioritized recommendations.
- Conformance-test a post-quantum implementation (ML-KEM, ML-DSA, SLH-DSA) against NIST FIPS standards.
- Probe live TLS/SSH endpoints you own to verify post-quantum hybrid key exchange readiness.
quantakrypto pqc-tools MCP server FAQ
It provides AI agents with 16 post-quantum cryptography readiness tools: scanning code for quantum-vulnerable crypto across 14 languages, generating migration plans, conformance-testing PQC implementations, gating builds against compliance mandates (CNSA 2.0, NIST IR 8547), and probing live endpoints.
Yes, quantakrypto-tools is open-source under the Apache-2.0 license with zero runtime dependencies.
Install via npm: `claude mcp add quantakrypto npx @quantakrypto/mcp` or use the remote HTTP endpoint at https://mcp.quantakrypto.com/mcp.
The core scanning and conformance tools require no authentication. Optional LLM-powered triage and remediation use the `@quantakrypto/agent` package, which supports BYOK (bring-your-own-key) with Anthropic and OpenAI-compatible adapters.
qScan detects quantum-vulnerable cryptography across 14 languages: JavaScript/TypeScript, Python, Go, Java, Kotlin, Scala, C#, Rust, Ruby, PHP, Elixir, C/C++, Swift, Objective-C, Dart, and Solidity/Move/Cairo.
No, by design. quantakrypto is a scanner, CI gate, and conformance harness. It identifies what to migrate and tests replacements; you supply the actual PQC library (e.g., liboqs / Open Quantum Safe).
README (reference)
Source of truth, from the repository.
quantakrypto-tools
Open-source post-quantum readiness tooling by quantakrypto. Find quantum-vulnerable cryptography in any codebase, wire post-quantum readiness into your editor and your CI, and conformance-test post-quantum implementations — with zero runtime dependencies (Node built-ins only).
Design goals: simple, clean, reusable code; zero runtime dependencies; everything documented, tested, and example-driven.
What's inside
| Tool | What it does | Get it |
|---|---|---|
qScan (@quantakrypto/qscan) | CLI that finds quantum-vulnerable crypto (RSA, (EC)DH, ECDSA, EdDSA, …) across 14 languages (JS/TS, Python, Go, Java/Kotlin/Scala, C#, Rust, Ruby, PHP, Elixir, C/C++, Swift, Objective-C, Dart, Solidity/Move/Cairo) and prints a readiness score. SARIF / JSON / CBOM / evidence (ISO 27001 A.8.24) / OpenVEX output, baselines, incremental & parallel scans. Compliance mandate gate: --mandate cnsa-2.0 / nist-ir-8547 reports each prohibited finding with its dated clause and fails the build on the mandate's deadlines (--lead-months, --fail-now). Opt-in --triage (BYOK LLM re-rank/explain) and a qremediate codemod CLI. | npx @quantakrypto/qscan ./ |
MCP (@quantakrypto/mcp) | Model Context Protocol server that gives AI coding agents post-quantum readiness tools (16 tools — scan, inventory, explain, suggest-hybrid, CBOM, plan-migration, triage, remediate, probe-endpoint, …). Local stdio + hostable HTTP. | claude mcp add quantakrypto npx @quantakrypto/mcp |
Sieve (@quantakrypto/sieve) | Conformance battery for ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) implementations, driven over a JSON stdin/stdout protocol. | npx @quantakrypto/sieve --help |
Action (@quantakrypto/action) | GitHub Action that runs the qScan/Sieve/qProbe checks in CI, writes SARIF for code-scanning upload, annotates the diff, and fails the build only on new quantum-vulnerable crypto. | uses: quantakrypto/pqc-tools/packages/action@v1 |
agent (@quantakrypto/agent) | Optional, zero-dependency BYOK (bring-your-own-key) LLM client (native fetch; Anthropic + OpenAI-compatible adapters) that powers qScan --triage and qremediate --llm. Networked, key-holding — kept isolated (see also qProbe). | npm i @quantakrypto/agent |
qProbe (@quantakrypto/qprobe) | Actively probes live TLS/SSH endpoints you own for post-quantum readiness — PQC-hybrid key exchange (X25519MLKEM768) and classical certificate posture. Gated behind an ownership attestation; reports, never modifies ("engine disposes"). See THREAT-MODEL. | npx @quantakrypto/qprobe --i-own-this host |
All of qScan, MCP, the Action, agent, and qProbe share the engine in
@quantakrypto/core (npm i @quantakrypto/core) — detectors,
the vulnerable-dependency DB, the readiness score, SARIF/JSON/CBOM/evidence/OpenVEX
reporting, and the
offline agent-plane primitives (context redactor, verify_fix gate, codemods, patch
policy). Sieve is standalone: it tests other implementations and implements no
crypto itself.
Infrastructure coverage. Beyond application source, the shared core engine
carries config-scope detectors for Terraform/OpenTofu IaC and cloud KMS, JSON
Web Keys, Kubernetes / cert-manager / Istio, CI/CD artifact & code signing
(cosign/GPG/jarsigner/codesign/minisign), secrets at rest (SOPS/age, PGP, Sealed
Secrets), message brokers (Kafka/MQTT), databases (pgcrypto, libpq sslmode), and
JOSE/JWE key management — so qscan, the Action, and MCP flag infrastructure
crypto with no extra install. qProbe adds the live-endpoint dimension (see the
table above). The narrative anchor for infrastructure is harvest now, decrypt
later: data and secrets captured today are decryptable once a CRQC exists.
Quick start
# 1. Scan a codebase for quantum-vulnerable cryptography.
npx @quantakrypto/qscan ./
# 2. Give your AI coding agent post-quantum readiness tools.
claude mcp add quantakrypto npx @quantakrypto/mcp
# 3. Conformance-test a post-quantum implementation (adapter speaks the JSON protocol).
npx @quantakrypto/sieve --impl "node ./my-impl.js" --param ml-kem-768
# 4. Gate against a compliance mandate's dated deadlines (CNSA 2.0 / NIST IR 8547).
# Verdicts also ride in --format json/sarif/evidence; --policy lets an org
# acknowledge families it is knowingly migrating (exempt from early gating).
npx @quantakrypto/qscan ./ --mandate cnsa-2.0 [--policy .quantakrypto/crypto-policy.json]
Add the CI gate by dropping
packages/action/examples/quantum-readiness.yml
into .github/workflows/, or wire it up directly:
- uses: quantakrypto/pqc-tools/packages/action@v1
with:
path: "."
severity-threshold: "high"
Each package README has the full options reference and more examples: qScan · MCP · Sieve · Action · core · agent.
Using quantakrypto alongside a PQC library (liboqs / OQS)
quantakrypto does not implement post-quantum cryptography, by design — it is
the scanner, the CI gate, and the conformance harness you wrap around a real PQC
library like liboqs / Open Quantum Safe. They
compose: quantakrypto finds and gates classical crypto (qscan, the Action),
tells you what to migrate to and in what order (qscan --tier, MCP
plan_migration, qremediate), and conformance-tests the replacement
(sieve runs any ML-KEM/ML-DSA/SLH-DSA implementation against FIPS 203/204/205,
with exact-value KATs when you supply official NIST ACVP vectors). liboqs
supplies the primitives.
See the worked end-to-end walkthrough — scan → migrate → verify → gate — in
examples/liboqs-migration/.
Workspace layout
quantakrypto-tools/
├── packages/
│ ├── core/ @quantakrypto/core — shared engine (the contract lives in src/types.ts + src/index.ts)
│ ├── qscan/ @quantakrypto/qscan — CLI
│ ├── mcp/ @quantakrypto/mcp — MCP server (stdio now, HTTP scaffold for hosting)
│ ├── action/ @quantakrypto/action — GitHub Action
│ ├── sieve/ @quantakrypto/sieve — conformance battery + JSON protocol
│ ├── agent/ @quantakrypto/agent — opt-in BYOK LLM client (triage + remediation)
│ └── qprobe/ @quantakrypto/qprobe — active TLS/SSH endpoint probing (gated; the only prober)
├── docs/ architecture, hosted-MCP design, improvement roadmap
└── examples/ end-to-end examples
Development
Requires Node ≥ 20.
npm install # links the workspaces
npm run build # tsc --build (project references)
npm test # node:test across all packages
The toolchain is intentionally tiny: TypeScript + tsx (to run node:test on
.ts) are the only dev dependencies; there are no runtime dependencies.
Documentation & compliance
Full documentation lives in docs/:
- Objectives & scope — what the toolchain is for, what each library does, the load-bearing decisions, and the deliberate scope boundaries. Start here.
- Architecture decisions — the immutable "why" behind each load-bearing choice (zero deps, shared core contract, two-plane agent, …).
- Standards & compliance — what the tools touch and could align to: NIST FIPS 203/204/205, SP 800-208, CNSA 2.0, SARIF, CWE, ISO/IEC 27001 (A.8.24), Common Criteria, FIPS 140-3, EU DORA/NIS2, US M-23-02 / NSM-10, and OSS assurance (SLSA, OpenSSF Scorecard, SPDX/REUSE).
- Governance: Contributing · Security · Code of Conduct · Changelog.
License
Apache-2.0. The methodology is open; the assessments, attestation reports, and deliverables are where the quantakrypto practice lives.
Support & training
Questions, commercial support, or post-quantum readiness training for your team — visit quantakrypto.com or email hello@quantakrypto.com.
Related MCP servers

Graqle
Graph-powered codebase reasoning and institutional memory for AI agents—turn your organization's knowledge into persistent, queryable intelligence.

io.github.quantumproxies/quanticdata-mcp
Live web access for agents: scrape, SERP search, crawl/map, 74 collectors, datasets, proxies.
Web scraping, SERP search, crawl/map and 74 Collectors through residential proxies. 25 tools.
Mobile money fees, African tax rates, currency conversion and Uganda PAYE for AI agents.
View repository →Deterministic eligibility checker for grants, jobs and scholarships in Africa.
View repository →Parses MTN MoMo and Airtel Money Uganda SMS into structured JSON.
View repository →