ECZ-ID MCP Trust
See what your MCP servers expose. Know what changed. Control the ones that matter.
Local-first MCP visibility, change intelligence and optional runtime control for
Visual Studio Code.
An MCP server is configuration, and configuration moves. An endpoint is
repointed, a tool quietly gains a write capability, a credential-shaped key
appears in an environment block — and nothing tells you, because your agent
keeps working exactly as it did yesterday.
MCP Trust gives you the three things that gap requires: visibility into what
every declared server actually exposes, change intelligence against a
baseline you control, and — when you want it — deterministic local mediation
of the traffic itself.
It runs entirely on your machine. No account to inspect. No telemetry. No source,
prompts or secret values leave your computer.
Editions
| Edition |
Price |
What it is for |
| MCP Trust Community |
£0 — free forever |
Discover, inspect and track change across every MCP server you work with. |
| MCP Trust Pro |
£12.99/month or £119/year |
Keep the history, see deeper tool and schema change, cut credential exposure, and mediate locally. |
| Developer Trust Pro |
£19.99/month or £199/year |
MCP Trust Pro and Agent Trust Pro on one licence. |
Protect both sides of the agent ↔ MCP connection. One licence.
Explore MCP Trust Pro →
Explore Developer Trust Pro →
Already purchased? Activate Pro →
The Marketplace download is free because Community is genuinely free forever.
Pro is an optional entitlement that unlocks additional capability inside this
same extension.
What you get the moment you install it, for £0
- Find every MCP server you actually have. Detects
mcp.json, .mcp.json, .vscode/mcp.json, .mcp/ configs, mcp.config.*, claude_desktop_config.json and ecz-mcp.json.
- See what each one exposes. MCP X-Ray gives a per-server inventory: transport, command basename, argument shape, environment key names, credential-shaped-name warnings, declared sandbox state and a local posture fingerprint.
- Know what moved. Trust Delta places every server in NEW / CHANGED / UNCHANGED / REMOVED against a baseline you accept explicitly.
- Know what deserves attention first. Review Priority rates each inspection LOW / NORMAL / ELEVATED / HIGH, deterministically, and shows the exact reasons.
- Prove what the extension did. Privacy Proof and the exportable Inspection Receipt record what was read, stored and transmitted.
- Check public proof. One click to a read-only Resolver lookup and to supported MCP setup.
No sign-in. No trial. No expiry.
Trust Delta
Every check compares what is configured now against the baseline you last
accepted, and places each server in exactly one state:
| State |
Meaning |
| NEW |
Configured now; not in your trusted baseline. |
| CHANGED |
In your baseline, but something observable moved. |
| UNCHANGED |
Identical to your trusted baseline. |
| REMOVED |
In your baseline; no longer configured. |
Where the evidence exists, the delta covers MCP servers added or removed,
transport changes, endpoint changes, launch command and argument changes,
environment key-name changes, sandbox declaration changes, tool inventory and
schema changes, capability-class changes, public-evidence changes and mediation
state changes.
It never fills in what it did not observe. With no baseline, nothing is
reported as "unchanged" — you are told plainly that nothing was compared. Tool
inventory is only compared when tool signatures were genuinely observed through
an active Local Trust Gate; otherwise the report says so rather than implying
no tools changed.
The trusted baseline is yours
The baseline moves only when you say so. Scanning twice does not quietly absorb
a change — that would defeat the entire point. Run Establish trusted
baseline when you have reviewed the current state and accept it. You are told
exactly how many changes you are accepting before you confirm.
Review Priority
Findings are rated LOW, NORMAL, ELEVATED or HIGH, computed
deterministically from the MCP Trust Inspection Reason Codes below. The same input always gives the
same result, and every priority shows the exact reasons that produced it.
Review Priority is not a safety, approval or compliance determination. It indicates how much attention
this inspection deserves, based only on what was observed locally.
There is deliberately no safety score — no "87/100", no percentage, no
letter grade. A number like that implies a measurement nothing here performs,
and a server does not earn your trust by scoring well.
MCP Trust Inspection Reason Codes
Every material finding carries a stable, machine-readable MCP Trust Inspection
Reason Code, a plain-English explanation, and a concrete review step. The codes
are provider-neutral and stable across versions, so a receipt, a CI job or a
policy engine can rely on them.
Namespace: eczid.mcp-trust.inspection.v1 — carried in every Inspection
Receipt and in the machine-readable product facts.
MCP Trust Inspection Reason Codes describe local configuration and change observations. They are distinct from canonical ECZ-ID Resolver/Verifier ReasonCodes carried with ResultStates and Action Envelopes.
NO_PUBLIC_RESOLVER_PROOF_FOUND shares its name with a canonical ECZ-ID
ResultState. Within this namespace it is a local observation — no ECZ-ID
reference was present in the inspected configuration — and never a Resolver
result.
Each one answers three questions: what happened, why it might matter,
and what you should review.
Inventory
| Code |
Meaning |
MCP_ADDED |
MCP server added since baseline |
MCP_REMOVED |
MCP server removed since baseline |
MCP_UNCHANGED |
MCP server unchanged since baseline |
Configuration posture
| Code |
Meaning |
TRANSPORT_CHANGED |
Transport changed |
REMOTE_ENDPOINT_CHANGED |
Remote endpoint changed |
COMMAND_CHANGED |
Launch command changed |
ARGUMENTS_CHANGED |
Launch arguments changed |
SANDBOX_DECLARATION_CHANGED |
Sandbox declaration changed |
CONFIG_FINGERPRINT_CHANGED |
Configuration posture changed |
Credential-shaped exposure (key NAMES only)
| Code |
Meaning |
CREDENTIAL_SHAPED_ENV_KEY |
Credential-shaped environment key name present |
CREDENTIAL_SHAPED_ENV_KEY_ADDED |
Credential-shaped environment key name added |
CREDENTIAL_SHAPED_ENV_KEY_REMOVED |
Credential-shaped environment key name removed |
ENV_KEY_NAMES_CHANGED |
Environment key names changed |
ENV_FILE_DECLARED |
Environment file declared |
Tools and capability
| Code |
Meaning |
TOOL_INVENTORY_CHANGED |
Tool inventory changed |
TOOL_ADDED |
Tool added |
TOOL_REMOVED |
Tool removed |
TOOL_DESCRIPTION_CHANGED |
Tool description changed |
TOOL_INPUT_SCHEMA_CHANGED |
Tool input schema changed |
TOOL_OUTPUT_SCHEMA_CHANGED |
Tool output schema changed |
TOOL_ANNOTATIONS_CHANGED |
Tool annotations changed |
TOOL_CAPABILITY_CLASSES_CHANGED |
Tool capability classes changed |
NEW_STATE_MUTATING_CAPABILITY |
New state-mutating capability since baseline |
SENSITIVE_CAPABILITY_COMBINATION |
Sensitive capability combination |
Public identity evidence
| Code |
Meaning |
NO_PUBLIC_RESOLVER_PROOF_FOUND |
No suitable public ECZ-ID operator evidence found |
PUBLIC_RESOLVER_REFERENCE_PRESENT |
Public ECZ-ID reference present |
RESOLVER_STATE_CHANGED |
Public evidence reference changed |
Mediation posture
| Code |
Meaning |
MEDIATION_STATE_CHANGED |
Mediation state changed |
MEDIATION_NOT_ACTIVE |
Not mediated — inspection only |
MEDIATION_PROOF_STALE |
Mediation proof is no longer current |
Inspection integrity
| Code |
Meaning |
BASELINE_NOT_ESTABLISHED |
No trusted baseline yet |
BASELINE_RESET |
Baseline reset |
CONFIG_NOT_INVENTORIED |
Configuration file not inventoried |
WORKSPACE_NOT_TRUSTED |
Workspace is in Restricted Mode |
Trust states
| State |
What it means |
| UNMANAGED |
No ECZ-ID mediation is active and nothing was meaningfully inspected. |
| OBSERVED |
Configuration was inspected locally. ECZ-ID is not on the request path: no call was intercepted, allowed, or blocked. |
| ENFORCED |
Traffic is genuinely traversing the ECZ-ID Local Trust Gate on this machine, confirmed by a live mediation proof. ENFORCED is withdrawn the moment that proof stops being current. |
ENFORCED can never be produced by inspection. It requires a live mediation
proof from a Local Trust Gate you started, and it is withdrawn the moment that
proof stops being current — if the gate stops, dies, goes stale, or refers to a
different target, coverage truthfully drops back to OBSERVED.
Privacy Proof
Run View Privacy Proof to see what this extension actually did during your
session — not a marketing statement, but a report generated from observed
behaviour, with each claim citing where in the implementation it is enforced.
It answers: was source code read or transmitted, were prompt contents accessed,
how configuration bytes were processed, whether any secret value was displayed,
retained or transmitted, is telemetry active, was any
network request made, and was a Resolver request performed.
Copy privacy statement puts the whole thing on your clipboard.
Inspection Receipt
Run Copy Inspection Receipt to export a privacy-preserving, reproducible record of
one inspection as a short summary, full Markdown, or JSON.
A receipt is not a certificate, not an assurance about any MCP server,
not canonical ECZ-ID truth, and not a compliance determination — and it
says so in the artefact itself. It is a record of what one machine observed at
one moment, carrying a content digest that ignores only the timestamp, so two
inspections of an unchanged workspace produce an identical digest.
Every receipt is re-scanned against forbidden patterns before it reaches your
clipboard. If it ever failed that check, it would be withheld rather than
copied.
Compatibility
| Environment |
Status |
Evidence |
| Visual Studio Code 1.90+ |
SUPPORTED |
Primary target. Extension Host proof harness exercises activation, scan, baseline, gate protect/stop and entitlement against a dev build. |
| VS Code MCP config (.vscode/mcp.json) |
SUPPORTED |
classifySourceFileKind() → vscode-mcp-json; covered by mcp-inventory tests and by the demo workspace fixtures. |
| Workspace MCP config (.mcp.json) |
SUPPORTED |
classifySourceFileKind() → workspace-mcp-json; scanner opts into the .mcp.json dot-file explicitly. |
| Claude Desktop config (claude_desktop_config.json) |
PARTIAL |
The file shape is recognised and its mcpServers map is inventoried when the file is inside an open workspace. MCP Trust does not read Claude Desktop's own application-support location. |
| Generic MCP config (mcp.json, .mcp/.json, mcp.config.) |
SUPPORTED |
classifySourceFileKind() → generic-mcp-config; requires strict JSON with a servers or mcpServers map. |
| MCP config with comments (JSONC) |
NOT SUPPORTED |
JSON.parse is used deliberately. A JSONC file is reported as CONFIG_NOT_INVENTORIED with a parse note rather than being silently skipped. |
| VSCodium / Open VSX consumers |
NOT TESTED |
The package uses no proprietary VS Code API, but no run has been executed in VSCodium in this programme. Stated as NOT TESTED rather than assumed. |
| Virtual workspaces (remote FS providers) |
PARTIAL |
Declared virtualWorkspaces: limited in the manifest. Local file detection uses node:fs, so files not on disk are not discovered. |
| Restricted Mode (untrusted workspace) |
SUPPORTED |
Declared untrustedWorkspaces: limited. The scan path returns before any filesystem access and reports WORKSPACE_NOT_TRUSTED. |
NOT TESTED means exactly that: not assumed to work, and not claimed to.
Community is not a trial and not a teaser. It is the whole inspection product:
- MCP discovery across every supported configuration shape
- MCP X-Ray per-server inventory
- credential-shaped environment key-name warnings
- Trust Delta change detection against a baseline you control
- deterministic Review Priority with its reasons
- Privacy Proof and exportable Inspection Receipt
- Resolver public-proof lookup and supported-setup routes
- no paid account, no sign-in, no telemetry
If all you ever want is to know what your MCP servers expose and what changed,
Community does that permanently and for nothing.
MCP Trust Pro — £12.99/month or £119/year
Pro exists for the point where inspecting once is no longer enough: when you
need the history, the depth, and the ability to act. Everything still computes
on your machine.
Keep the history, not just the last scan
Trust Epochs retain a privacy-preserving history of your MCP posture — tools
and schemas as digests, origins, transports, environment key names, policy and
coverage — so you can compare any two points in time. Community keeps one
baseline; Pro keeps the record, with retention and deletion under your control.
Advanced Tool X-Ray classifies each mediated tool's declared capability
classes and surfaces material change across epochs — a description rewritten, a
schema widened, an annotation flipped, a capability added. These are signals for
your review, never a verdict.
Stop handing every server your whole environment
Secret Shield launches a mediated server with a minimised, least-privilege
environment: credential-shaped key names are withheld unless you explicitly
allow them. Previews show key names only — values are never displayed,
retained or transmitted.
Decide with rules, not vibes
Deterministic local policy applies ALLOW / WARN / REVIEW / BLOCK /
QUARANTINE as first-match rules you write. The same input always produces the
same decision, and no language model authorises anything.
Local Trust Gate — Protect This MCP — repoints a supported server through
a gate on your machine: a STDIO wrapper process, or a 127.0.0.1 proxy for
HTTP upstreams. Your policy is then applied to traffic that genuinely flows
through it. Coverage reads ENFORCED only while a live gate session is
mediating; stop the gate and it truthfully falls back to OBSERVED. Inspection
alone never produces ENFORCED. Stop Protecting restores your original
configuration and needs no Pro entitlement.
Fix what you find, reversibly
Remediation produces reviewable configuration patches: preview, diff,
timestamped backup, atomic apply and rollback.
Explore MCP Trust Pro → · Activate Pro →
Community keeps working if a Pro entitlement is absent or expires. Only Pro
features deactivate, and your locally retained history stays.
Developer Trust Pro — £19.99/month or £199/year
An MCP server is one side of the connection. The agent calling it is the other.
Reviewing only one of them leaves the interesting half unexamined: MCP Trust
tells you what a server exposes, and ECZ-ID Agent Trust
tells you what an agent can reach and how its authority changed.
Developer Trust Pro unlocks both MCP Trust Pro and Agent Trust Pro under a
single entitlement, for less than buying the two separately.
Protect both sides of the agent ↔ MCP connection. One licence.
Explore Developer Trust Pro →
Operate an MCP server or an agent?
Give it an ECZ-ID Passport.
Everything above inspects MCP servers from the outside — the position you are in
when you consume someone else's server. If you operate an MCP server or an
agent, you are on the other side of that question, and the people evaluating you
want something they can check without asking you.
An ECZ-ID Passport establishes a reusable ECZ-ID identity with a public presence
on the ECZ-ID Resolver, so a reviewer can verify public proof themselves.
- Free, fast self-service
- A reusable machine-readable identity, not a one-off badge
- Public, read-only Resolver presence others can check
Operate an MCP server?
Give it a free ECZ-ID MCP Passport →
Operate an agent?
Give it a free ECZ-ID Agent Passport →
Both Passports are available whichever extension you started from — most teams
that run MCP servers also run agents, and the same ECZ-ID identity layer covers
both. See also ECZ-ID Agent Trust
for local agent visibility.
Passport issuance is an ECZ-ID platform service, not a function of this
extension. The extension inspects and routes; it never issues proof itself.
Who this is for
| If you are… |
The problem you have |
What MCP Trust gives you |
| An MCP server developer |
You change a tool schema and have no idea which consumers now see something different. |
X-Ray of your own declared surface, plus Trust Delta showing exactly what a consumer's baseline would flag. |
| An agent developer using MCP |
Your agent depends on servers you did not write, which can change under you. |
Change detection against a baseline you accept, with Review Priority ranking what to look at first. |
| An AppSec or security engineer |
You are asked to review MCP integrations with no artefact to review and no tooling that respects secrets. |
A privacy-preserving inventory, an exportable Inspection Receipt, and deterministic reason codes — with secret values never read into any output. |
| A platform engineer |
MCP configuration is spreading across repos with no consistent shape. |
Discovery across every supported configuration shape, and reviewable remediation to converge them. |
| An enterprise architect |
You must state a defensible position on MCP tooling posture. |
Explicit OBSERVED / UNMANAGED / ENFORCED semantics that never overstate what was actually established. |
| A team handling MCP credentials |
Servers are launched with far more environment than they need. |
Credential-shaped key-name visibility in Community; Secret Shield minimisation in Pro. |
Most relevant when you are adding or reviewing an MCP server, before you
rely on an MCP integration in something that matters, or when an evaluator asks
which of your servers carry public proof.
What you can do in under a minute
- Open or scan the workspace - run
ECZ-ID MCP Trust: Check MCP Trust.
- Review findings in plain English - grouped, with neutral posture.
- Open Resolver guidance or continue supported setup where relevant.
What it looks for
- MCP server configuration (
mcp.json, .mcp.json, .vscode/mcp.json, .mcp/, mcp.config.*).
- Known MCP client configs (e.g.
claude_desktop_config.json).
- An
ecz-mcp.json / .well-known/ecz-mcp.json resolver reference.
- Whether a resolver-verifiable proof reference is missing for a detected server.
MCP X-Ray (local inventory)
For each server declared in a detected MCP configuration, a check shows:
- Server name and source file - which config declares it.
- Transport - declared
stdio / http, legacy SSE, or honestly labelled inferred / unknown.
- Command - executable basename only, plus argument count and flag names (argument values are never shown).
- Environment keys - variable NAMES only, with a warning when a name looks credential-shaped. Secret values are never displayed, retained, fingerprinted, reported, or transmitted.
- Sandbox - the declared
sandboxEnabled configuration state only (no claim about actual sandbox behaviour).
- Remote - scheme, host, port and path only; URL credentials, query and fragment are always omitted.
- Fingerprint - a local posture fingerprint of the privacy-filtered fields above. Changing only a secret value never changes it.
- Change since your previous local scan - servers added or removed, transport, command, argument shape, environment key set, sandbox declaration or remote endpoint changes. One baseline is kept per workspace, on this machine only, and is replaced on each scan.
Coverage truth: inventory results are OBSERVED (configuration inspected locally) and UNMANAGED - inspection does not mediate or enforce runtime execution, and makes no connection to any MCP server. Coverage reads ENFORCED only while a Pro Local Trust Gate you started is genuinely mediating a session and its live mediation proof holds; when that gate stops, coverage truthfully drops back to OBSERVED / UNMANAGED.
Example result
MCP X-RAY - ECZ-ID MCP Trust
Server: github
Source ............ .vscode/mcp.json
Transport ......... HTTP - declared
Remote ............ https://api.example.com/mcp (credentials/query omitted)
Environment keys .. 2 detected; 1 credential-shaped name
Sandbox ........... not declared
Fingerprint ....... a1b2c3d4e5f6 (local posture fingerprint)
Change ............ unchanged since previous local scan
Coverage: OBSERVED / UNMANAGED
What results mean
Results describe public-proof posture, never a safety, approval, certification or compliance verdict:
resolvable | partial public proof | no public proof reference found yet | review recommended | re-check before reliance | your local policy decides.
There is no "pass/fail". Local policy decides what is sufficient, and you should re-check before reliance.
Recommended next steps
- Inspect the finding - plain-English detail, no verdict.
- Copy verification guidance - a claim-free snippet you can share.
- Open Resolver - read-only public proof lookup.
- Continue supported setup - hand off to TrustOps (metadata only).
- Open documentation - Developer Gateway.
- Re-check later - re-run before you rely on a result.
Privacy & permissions
| Question |
Answer |
| Files read |
Filenames and paths during a normal scan |
| File contents read |
Only detected MCP configuration files, only during a check you run, after Workspace Trust. Configuration bytes are processed locally to derive a privacy-filtered projection, then the parsed content is discarded. Secret values are never displayed, retained, fingerprinted, reported or transmitted, and environment references are not resolved - results carry names, counts, states and local fingerprints only |
| Selected text read |
No |
| Anything uploaded |
Nothing is sent to ECZ-ID. The extension transmits no source, prompts or secrets. Under a Pro Local Trust Gate you explicitly enabled, MCP frames are relayed only to the upstream server you already configured |
| Network destinations |
Community performs no background outbound requests. User-selected Resolver, TrustOps and Developer Gateway links open in your browser. When you explicitly enable a Pro Local Trust Gate, it binds a local 127.0.0.1 endpoint (or spawns a local STDIO wrapper) and communicates only with the MCP upstream you already configured for that mediated session. No telemetry is sent |
| Telemetry |
None |
| Retention |
One privacy-filtered posture baseline per workspace, kept on this machine only and replaced on each scan, so changes since your previous local scan can be shown |
| Local storage |
Minimal extension state plus the single local baseline above |
| Workspace Trust |
Enforced in code; in Restricted Mode the scan commands do not walk or read workspace files |
See the bundled PRIVACY.md for the full notice.
Frequently asked questions
Is this extension free?
Yes. MCP Trust Community is free forever - you never need to sign in or pay to
run a local check, and it does not expire. MCP Trust Pro is an optional paid
entitlement (£12.99/month or £119/year) that unlocks additional capability in
this same extension, and Developer Trust Pro (£19.99/month or £199/year)
unlocks MCP Trust Pro and Agent Trust Pro together.
What is the difference between MCP Trust Pro and Developer Trust Pro?
MCP Trust Pro covers this product only. Developer Trust Pro covers both sides of
the agent-to-MCP connection - MCP Trust Pro plus Agent Trust Pro - on one
licence, for less than the two bought separately.
What is an ECZ-ID MCP Passport, and do I need one to use this?
You do not need one. A Passport is for the opposite position: it is relevant
when you operate an MCP server and want a reusable ECZ-ID identity with public
Resolver presence that reviewers can check for themselves. It is a free,
self-service ECZ-ID platform service, not a feature of this extension.
Does it upload my source code?
No. The extension sends no source, prompts or secrets anywhere, and there is no telemetry. The only traffic it ever relays is a Pro Local Trust Gate session you explicitly enabled, and that goes only to the upstream MCP server you already configured.
Does it read my file contents?
The scan itself walks filenames and paths only. When you run a check, the extension additionally reads the contents of detected MCP configuration files (for example .vscode/mcp.json) to build the local X-Ray inventory. That processing stays on your machine: secret values are never displayed, retained, persisted, fingerprinted, reported, or transmitted, and ${input:...} / ${env:...} references are never resolved.
Does a missing proof reference mean something is unsafe?
No. "No public proof reference found yet" is neutral - it is not a verdict of "unsafe". It only means resolver-verifiable public proof was not detected.
What does Resolver do?
Resolver is a read-only public proof lookup. The extension can open it so you can check public proof yourself; the extension never writes, activates or decides anything.
Do I need an ECZ-ID before using the extension?
No. You can run every local check without one. An ECZ-ID is only relevant if you later choose supported setup in TrustOps.
What happens when I continue supported setup?
The extension hands off to TrustOps with metadata only. It runs no checkout itself; TrustOps handles acquisition, setup and lifecycle.
Can this extension make a compliance or approval decision?
No. It surfaces posture and routes you to proof. Local policy decides sufficiency; it never certifies, approves or guarantees.
Which MCP configuration files can it detect?
mcp.json, workspace .mcp.json, .vscode/mcp.json, .mcp/ configurations, claude_desktop_config.json and ecz-mcp.json.
Does it connect to or run my MCP servers?
Community: no. Inventory comes from configuration files only. Community never starts a process, never connects to a server, never makes a tool call, and coverage is always labelled OBSERVED / UNMANAGED.
Pro: only if you explicitly turn it on. When you run Protect This MCP, the Local Trust Gate binds a 127.0.0.1 loopback endpoint (HTTP servers) or spawns a local wrapper process (STDIO servers) and relays that session's traffic to the upstream server you already configured, applying your local policy. That is the whole point of mediation - it cannot be done from outside the call path. It runs only for servers you protect, only while you leave it running, and it talks only to the upstream you had already configured. Stop the gate and the extension is back to reading configuration.
Is MCP Registry presence treated as proof?
No. Registry presence is not treated as resolver-verifiable public proof. Re-check before reliance.
Does this create or host an MCP server?
It never creates, hosts or publishes an MCP server of its own, and it never becomes a server you or anyone else can connect to from outside your machine. Community only inspects local configuration and resolver-reference posture. Pro's Local Trust Gate does bind a local 127.0.0.1 endpoint (or spawn a local wrapper process) while you have it running, purely to sit between your client and the server you already configured.
What does "Protect This MCP" actually do (Pro)?
It rewrites a supported server entry in your MCP configuration to point at the local ECZ Trust Gate - a STDIO wrapper process or a 127.0.0.1 proxy - after showing you a Secret Shield preview and a config diff, and after writing a timestamped backup. Your MCP client then talks to the gate, which applies your deterministic local policy to the traffic and passes the rest through to the original server. The gate communicates only with that upstream server you already configured for the mediated session; nothing is sent to ECZ-ID and no telemetry is sent.
When does coverage say ENFORCED (Pro)?
Only while a live local gate session is genuinely mediating that server's traffic. A dead, stopped, stale or mismatched gate is never shown as ENFORCED - it reads OBSERVED. ENFORCED can never be produced by inspection alone.
Does Pro certify or verify a server?
No. Pro applies your local policy to traffic you route through the local gate. It makes no approval, certification or compliance claim. Organization-level MCP Assurance is a separate product, and Resolver public proof stays separate from local policy.
What happens to Pro features when my entitlement expires?
Pro features deactivate on the next verification; Community continues in full and your locally retained history is kept. Entitlements are verified locally with asymmetric (ES256) cryptography; the entitlement token is never displayed or transmitted by this extension.
What it does not do
- No source / prompt / secret upload, and no telemetry.
- Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
- Makes no safety, approval, certification or compliance claim. Registry presence is not proof, and this extension makes no remote-runtime claim. Resolver is the only public proof surface.
- Runs no checkout or payment - commercial actions happen only in TrustOps.
Install & first use
- In your editor's Extensions view, search for ECZ-ID MCP Trust (publisher EcoCitizenz) and install it.
- Open a project and trust the workspace.
- Run
ECZ-ID MCP Trust: Check MCP Trust and review the grouped findings.
Free vs Pro vs supported setup
- Community (£0, free forever, local-first): detected MCP configuration with posture, missing-proof findings, MCP X-Ray, Trust Delta change detection, Review Priority, Privacy Proof, Inspection Receipt, and Resolver re-check / supported-setup routes - no sign-in and no purchase to run a check.
- MCP Trust Pro (£12.99/month or £119/year, still local): Protect This MCP with truthful ENFORCED coverage, Secret Shield, Trust Epochs history, Advanced Tool X-Ray with material-change indicators, deterministic local policy and reviewable remediation. Activate with a Developer Trust entitlement; Developer Trust Pro (£19.99/month or £199/year) unlocks Agent Trust Pro alongside it.
- Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for MCP server identity and public proof - relevant when you need a resolver-verifiable result others can check, not just local review.
- You never need to buy anything to get local value; Pro and supported setup are separate, optional steps.
Python / CLI
Prefer Python, CI or terminal automation?
python -m pip install ecz-id-mcp
ecz-id-mcp --help
The Python tools run locally and inspect, explain and route only - the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.
Machine-readable facts
| Field |
Value |
| Product |
ECZ-ID MCP Trust |
| Identity |
ecocitizenz.eczid-mcp-trust |
| Publisher |
EcoCitizenz |
| License |
Community free; Pro requires a Developer Trust entitlement; see the bundled LICENSE.txt |
| Version |
0.5.2 |
| Page family |
functional-extension |
| Editions |
Community (free, no sign-in) / MCP Trust Pro / Developer Trust Pro bundle |
| Purpose |
Inspect MCP server configuration, credential exposure and local changes; with Pro, mediate supported servers through a local Trust Gate with truthful ENFORCED coverage. |
| Applicable audiences |
MCP server and client developers; AI tooling and platform teams; Security reviewers of MCP integrations; Architects standardising MCP across a fleet |
| Applicable scenarios |
you are adding or reviewing an MCP server; before relying on an MCP integration; an evaluator asks which servers carry public proof |
| Primary command |
ECZ-ID MCP Trust: Check MCP Trust |
| Inputs |
mcp.json, .mcp.json, .vscode/mcp.json, .mcp/, mcp.config.*, claude_desktop_config.json, ecz-mcp.json |
| Outputs |
Per-server MCP X-Ray inventory (transport, command basename, environment key names, credential-shaped-name warnings, declared sandbox state, local posture fingerprint, change-since-previous-scan), posture findings, and Resolver re-check / supported-setup routes |
| Data handling |
Scan is filename/path-only; detected MCP configs are processed locally with secret values never displayed, retained, fingerprinted, reported, or transmitted; no source / prompt / secret upload; no telemetry; retention = one local posture baseline per workspace |
| Network behaviour |
Community: only the links you open (Resolver / TrustOps / Developer Gateway); no background network call; never connects to an MCP server. Pro, only while you run Protect This MCP: binds a local 127.0.0.1 mediation endpoint (or spawns a local STDIO wrapper) and relays that session to the upstream MCP server you already configured. No other outbound call; no telemetry either way. |
| Result states |
evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides; changed since previous local scan; coverage OBSERVED / UNMANAGED |
| Limitations |
Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout |
| Canonical machine discovery |
https://machine.ecocitizenz.org/.well-known/ecz-machine.json |
| Public proof |
https://resolver.ecocitizenz.org |
| Documentation |
https://developers.ecocitizenz.com |
| Supported setup |
https://trustops.ecocitizenz.com/start |
| Re-check |
Re-run before reliance |
Need help choosing the right ECZ-ID route?
Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance
Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.
The ECZ-ID estate
MCP Trust is one surface of ECZ-ID, an infrastructure layer for machine trust —
identity, public proof and verifiable posture for the systems that now call each
other without a human in the loop.
Links & support