ECZ-ID MCP Trust
Resolve the MCP server before you allow it to act.
Free, local-first trust checks for Model Context Protocol (MCP) servers and clients. See what is resolvable, what is missing, and what to fix next — without uploading any source.
- 🔍 Detects
mcp.json, .vscode/mcp.json, claude_desktop_config.json, and .well-known/ecz-mcp.json
- 🧭 Plain-English posture: resolvable, partial, or no public resolver proof yet
- 🔗 One click to Resolver lookup, TrustOps MCP setup, and Developer Gateway docs
- 🔒 No source upload. No telemetry by default. No proof claims without Resolver.
Resolve the server. Resolve the agent. Re-check before reliance.

Screenshot placeholder — replace media/screenshot-panel.png with a capture of the MCP Trust panel before publishing.
What it checks
- MCP server configuration files (
mcp.json, .vscode/mcp.json, mcp.config.*).
- Known MCP client configs (e.g.
claude_desktop_config.json, modelcontextprotocol references).
- Presence of an
ecz-mcp.json / .well-known/ecz-mcp.json resolver reference.
- Whether a resolver-verifiable proof reference is missing for a detected server.
What this extension does / does not do
Does
- Discover MCP surfaces locally by filename and path.
- Explain posture in soft, plain-English language and copy a claim-free resolver proof request.
- Route you to Resolver (proof), TrustOps (setup), and the Developer Gateway (docs).
Does not
- Upload source code, prompts, transport strings, or secrets.
- Write canonical truth, decide BOUND state, or activate entitlement — Backend/Core and TrustOps own that.
- Make trust claims about any server. Resolver is the only source of proof, and local policy decides.
- Take payment or run any checkout. Commercial actions happen only in TrustOps.
Commands
ECZ-ID MCP Trust: Check MCP Trust
ECZ-ID MCP Trust: Scan MCP Server
ECZ-ID MCP Trust: Open MCP Resolver Guidance
ECZ-ID MCP Trust: Copy MCP Resolver Proof Request
ECZ-ID MCP Trust: Open TrustOps MCP Setup
ECZ-ID MCP Trust: Open Resolver
ECZ-ID MCP Trust: Open Developer Gateway Docs
Privacy
Local-first. Metadata-only handoff. No telemetry. No source upload. No checkout in the extension. Respects VS Code Workspace Trust and degrades gracefully when offline. See PRIVACY.md.
Links
ECZ-ID is an independent project and is not affiliated with or sponsored by Microsoft, GitHub, VS Code, OpenAI, Anthropic, Google, or AWS. ECZ-ID helps make identity, authority, and resolver posture easier to review. Local policy decides whether this is sufficient.
| |