Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>ECZ-ID MCP TrustNew to Visual Studio Code? Get it now.
ECZ-ID MCP Trust

ECZ-ID MCP Trust

EcoCitizenz

|
169 installs
| (0) | Free
See what your MCP servers expose, know what changed, and control the ones that matter. Local-first MCP visibility, change intelligence and optional local mediation for VS Code. Community is free forever. No account, no telemetry; secret values are never displayed or transmitted.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

ECZ-ID MCP Trust

See what your MCP servers expose. Know what changed. Control the ones that matter.

Local-first MCP visibility, change intelligence and optional runtime control for Visual Studio Code.

An MCP server is configuration, and configuration moves. An endpoint is repointed, a tool quietly gains a write capability, a credential-shaped key appears in an environment block — and nothing tells you, because your agent keeps working exactly as it did yesterday.

MCP Trust gives you the three things that gap requires: visibility into what every declared server actually exposes, change intelligence against a baseline you control, and — when you want it — deterministic local mediation of the traffic itself.

It runs entirely on your machine. No account to inspect. No telemetry. No source, prompts or secret values leave your computer.

Editions

Edition Price What it is for
MCP Trust Community £0 — free forever Discover, inspect and track change across every MCP server you work with.
MCP Trust Pro £12.99/month or £119/year Keep the history, see deeper tool and schema change, cut credential exposure, and mediate locally.
Developer Trust Pro £19.99/month or £199/year MCP Trust Pro and Agent Trust Pro on one licence.

Protect both sides of the agent ↔ MCP connection. One licence.

Explore MCP Trust Pro →
Explore Developer Trust Pro →
Already purchased? Activate Pro →

The Marketplace download is free because Community is genuinely free forever. Pro is an optional entitlement that unlocks additional capability inside this same extension.

What you get the moment you install it, for £0

  • Find every MCP server you actually have. Detects mcp.json, .mcp.json, .vscode/mcp.json, .mcp/ configs, mcp.config.*, claude_desktop_config.json and ecz-mcp.json.
  • See what each one exposes. MCP X-Ray gives a per-server inventory: transport, command basename, argument shape, environment key names, credential-shaped-name warnings, declared sandbox state and a local posture fingerprint.
  • Know what moved. Trust Delta places every server in NEW / CHANGED / UNCHANGED / REMOVED against a baseline you accept explicitly.
  • Know what deserves attention first. Review Priority rates each inspection LOW / NORMAL / ELEVATED / HIGH, deterministically, and shows the exact reasons.
  • Prove what the extension did. Privacy Proof and the exportable Inspection Receipt record what was read, stored and transmitted.
  • Check public proof. One click to a read-only Resolver lookup and to supported MCP setup.

No sign-in. No trial. No expiry.

Trust Delta

Every check compares what is configured now against the baseline you last accepted, and places each server in exactly one state:

State Meaning
NEW Configured now; not in your trusted baseline.
CHANGED In your baseline, but something observable moved.
UNCHANGED Identical to your trusted baseline.
REMOVED In your baseline; no longer configured.

Where the evidence exists, the delta covers MCP servers added or removed, transport changes, endpoint changes, launch command and argument changes, environment key-name changes, sandbox declaration changes, tool inventory and schema changes, capability-class changes, public-evidence changes and mediation state changes.

It never fills in what it did not observe. With no baseline, nothing is reported as "unchanged" — you are told plainly that nothing was compared. Tool inventory is only compared when tool signatures were genuinely observed through an active Local Trust Gate; otherwise the report says so rather than implying no tools changed.

The trusted baseline is yours

The baseline moves only when you say so. Scanning twice does not quietly absorb a change — that would defeat the entire point. Run Establish trusted baseline when you have reviewed the current state and accept it. You are told exactly how many changes you are accepting before you confirm.

Review Priority

Findings are rated LOW, NORMAL, ELEVATED or HIGH, computed deterministically from the MCP Trust Inspection Reason Codes below. The same input always gives the same result, and every priority shows the exact reasons that produced it.

Review Priority is not a safety, approval or compliance determination. It indicates how much attention this inspection deserves, based only on what was observed locally.

There is deliberately no safety score — no "87/100", no percentage, no letter grade. A number like that implies a measurement nothing here performs, and a server does not earn your trust by scoring well.

MCP Trust Inspection Reason Codes

Every material finding carries a stable, machine-readable MCP Trust Inspection Reason Code, a plain-English explanation, and a concrete review step. The codes are provider-neutral and stable across versions, so a receipt, a CI job or a policy engine can rely on them.

Namespace: eczid.mcp-trust.inspection.v1 — carried in every Inspection Receipt and in the machine-readable product facts.

MCP Trust Inspection Reason Codes describe local configuration and change observations. They are distinct from canonical ECZ-ID Resolver/Verifier ReasonCodes carried with ResultStates and Action Envelopes.

NO_PUBLIC_RESOLVER_PROOF_FOUND shares its name with a canonical ECZ-ID ResultState. Within this namespace it is a local observation — no ECZ-ID reference was present in the inspected configuration — and never a Resolver result.

Each one answers three questions: what happened, why it might matter, and what you should review.

Inventory

Code Meaning
MCP_ADDED MCP server added since baseline
MCP_REMOVED MCP server removed since baseline
MCP_UNCHANGED MCP server unchanged since baseline

Configuration posture

Code Meaning
TRANSPORT_CHANGED Transport changed
REMOTE_ENDPOINT_CHANGED Remote endpoint changed
COMMAND_CHANGED Launch command changed
ARGUMENTS_CHANGED Launch arguments changed
SANDBOX_DECLARATION_CHANGED Sandbox declaration changed
CONFIG_FINGERPRINT_CHANGED Configuration posture changed

Credential-shaped exposure (key NAMES only)

Code Meaning
CREDENTIAL_SHAPED_ENV_KEY Credential-shaped environment key name present
CREDENTIAL_SHAPED_ENV_KEY_ADDED Credential-shaped environment key name added
CREDENTIAL_SHAPED_ENV_KEY_REMOVED Credential-shaped environment key name removed
ENV_KEY_NAMES_CHANGED Environment key names changed
ENV_FILE_DECLARED Environment file declared

Tools and capability

Code Meaning
TOOL_INVENTORY_CHANGED Tool inventory changed
TOOL_ADDED Tool added
TOOL_REMOVED Tool removed
TOOL_DESCRIPTION_CHANGED Tool description changed
TOOL_INPUT_SCHEMA_CHANGED Tool input schema changed
TOOL_OUTPUT_SCHEMA_CHANGED Tool output schema changed
TOOL_ANNOTATIONS_CHANGED Tool annotations changed
TOOL_CAPABILITY_CLASSES_CHANGED Tool capability classes changed
NEW_STATE_MUTATING_CAPABILITY New state-mutating capability since baseline
SENSITIVE_CAPABILITY_COMBINATION Sensitive capability combination

Public identity evidence

Code Meaning
NO_PUBLIC_RESOLVER_PROOF_FOUND No suitable public ECZ-ID operator evidence found
PUBLIC_RESOLVER_REFERENCE_PRESENT Public ECZ-ID reference present
RESOLVER_STATE_CHANGED Public evidence reference changed

Mediation posture

Code Meaning
MEDIATION_STATE_CHANGED Mediation state changed
MEDIATION_NOT_ACTIVE Not mediated — inspection only
MEDIATION_PROOF_STALE Mediation proof is no longer current

Inspection integrity

Code Meaning
BASELINE_NOT_ESTABLISHED No trusted baseline yet
BASELINE_RESET Baseline reset
CONFIG_NOT_INVENTORIED Configuration file not inventoried
WORKSPACE_NOT_TRUSTED Workspace is in Restricted Mode

Trust states

State What it means
UNMANAGED No ECZ-ID mediation is active and nothing was meaningfully inspected.
OBSERVED Configuration was inspected locally. ECZ-ID is not on the request path: no call was intercepted, allowed, or blocked.
ENFORCED Traffic is genuinely traversing the ECZ-ID Local Trust Gate on this machine, confirmed by a live mediation proof. ENFORCED is withdrawn the moment that proof stops being current.

ENFORCED can never be produced by inspection. It requires a live mediation proof from a Local Trust Gate you started, and it is withdrawn the moment that proof stops being current — if the gate stops, dies, goes stale, or refers to a different target, coverage truthfully drops back to OBSERVED.

Privacy Proof

Run View Privacy Proof to see what this extension actually did during your session — not a marketing statement, but a report generated from observed behaviour, with each claim citing where in the implementation it is enforced.

It answers: was source code read or transmitted, were prompt contents accessed, how configuration bytes were processed, whether any secret value was displayed, retained or transmitted, is telemetry active, was any network request made, and was a Resolver request performed.

Copy privacy statement puts the whole thing on your clipboard.

Inspection Receipt

Run Copy Inspection Receipt to export a privacy-preserving, reproducible record of one inspection as a short summary, full Markdown, or JSON.

A receipt is not a certificate, not an assurance about any MCP server, not canonical ECZ-ID truth, and not a compliance determination — and it says so in the artefact itself. It is a record of what one machine observed at one moment, carrying a content digest that ignores only the timestamp, so two inspections of an unchanged workspace produce an identical digest.

Every receipt is re-scanned against forbidden patterns before it reaches your clipboard. If it ever failed that check, it would be withheld rather than copied.

Compatibility

Environment Status Evidence
Visual Studio Code 1.90+ SUPPORTED Primary target. Extension Host proof harness exercises activation, scan, baseline, gate protect/stop and entitlement against a dev build.
VS Code MCP config (.vscode/mcp.json) SUPPORTED classifySourceFileKind() → vscode-mcp-json; covered by mcp-inventory tests and by the demo workspace fixtures.
Workspace MCP config (.mcp.json) SUPPORTED classifySourceFileKind() → workspace-mcp-json; scanner opts into the .mcp.json dot-file explicitly.
Claude Desktop config (claude_desktop_config.json) PARTIAL The file shape is recognised and its mcpServers map is inventoried when the file is inside an open workspace. MCP Trust does not read Claude Desktop's own application-support location.
Generic MCP config (mcp.json, .mcp/.json, mcp.config.) SUPPORTED classifySourceFileKind() → generic-mcp-config; requires strict JSON with a servers or mcpServers map.
MCP config with comments (JSONC) NOT SUPPORTED JSON.parse is used deliberately. A JSONC file is reported as CONFIG_NOT_INVENTORIED with a parse note rather than being silently skipped.
VSCodium / Open VSX consumers NOT TESTED The package uses no proprietary VS Code API, but no run has been executed in VSCodium in this programme. Stated as NOT TESTED rather than assumed.
Virtual workspaces (remote FS providers) PARTIAL Declared virtualWorkspaces: limited in the manifest. Local file detection uses node:fs, so files not on disk are not discovered.
Restricted Mode (untrusted workspace) SUPPORTED Declared untrustedWorkspaces: limited. The scan path returns before any filesystem access and reports WORKSPACE_NOT_TRUSTED.

NOT TESTED means exactly that: not assumed to work, and not claimed to.

MCP Trust Community — £0, free forever

Community is not a trial and not a teaser. It is the whole inspection product:

  • MCP discovery across every supported configuration shape
  • MCP X-Ray per-server inventory
  • credential-shaped environment key-name warnings
  • Trust Delta change detection against a baseline you control
  • deterministic Review Priority with its reasons
  • Privacy Proof and exportable Inspection Receipt
  • Resolver public-proof lookup and supported-setup routes
  • no paid account, no sign-in, no telemetry

If all you ever want is to know what your MCP servers expose and what changed, Community does that permanently and for nothing.

MCP Trust Pro — £12.99/month or £119/year

Pro exists for the point where inspecting once is no longer enough: when you need the history, the depth, and the ability to act. Everything still computes on your machine.

Keep the history, not just the last scan

Trust Epochs retain a privacy-preserving history of your MCP posture — tools and schemas as digests, origins, transports, environment key names, policy and coverage — so you can compare any two points in time. Community keeps one baseline; Pro keeps the record, with retention and deletion under your control.

See the tool changes that a config diff misses

Advanced Tool X-Ray classifies each mediated tool's declared capability classes and surfaces material change across epochs — a description rewritten, a schema widened, an annotation flipped, a capability added. These are signals for your review, never a verdict.

Stop handing every server your whole environment

Secret Shield launches a mediated server with a minimised, least-privilege environment: credential-shaped key names are withheld unless you explicitly allow them. Previews show key names only — values are never displayed, retained or transmitted.

Decide with rules, not vibes

Deterministic local policy applies ALLOW / WARN / REVIEW / BLOCK / QUARANTINE as first-match rules you write. The same input always produces the same decision, and no language model authorises anything.

Move from watching to actually mediating

Local Trust Gate — Protect This MCP — repoints a supported server through a gate on your machine: a STDIO wrapper process, or a 127.0.0.1 proxy for HTTP upstreams. Your policy is then applied to traffic that genuinely flows through it. Coverage reads ENFORCED only while a live gate session is mediating; stop the gate and it truthfully falls back to OBSERVED. Inspection alone never produces ENFORCED. Stop Protecting restores your original configuration and needs no Pro entitlement.

Fix what you find, reversibly

Remediation produces reviewable configuration patches: preview, diff, timestamped backup, atomic apply and rollback.

Explore MCP Trust Pro → · Activate Pro →

Community keeps working if a Pro entitlement is absent or expires. Only Pro features deactivate, and your locally retained history stays.

Developer Trust Pro — £19.99/month or £199/year

An MCP server is one side of the connection. The agent calling it is the other. Reviewing only one of them leaves the interesting half unexamined: MCP Trust tells you what a server exposes, and ECZ-ID Agent Trust tells you what an agent can reach and how its authority changed.

Developer Trust Pro unlocks both MCP Trust Pro and Agent Trust Pro under a single entitlement, for less than buying the two separately.

Protect both sides of the agent ↔ MCP connection. One licence.

Explore Developer Trust Pro →

Operate an MCP server or an agent?

Give it an ECZ-ID Passport.

Everything above inspects MCP servers from the outside — the position you are in when you consume someone else's server. If you operate an MCP server or an agent, you are on the other side of that question, and the people evaluating you want something they can check without asking you.

An ECZ-ID Passport establishes a reusable ECZ-ID identity with a public presence on the ECZ-ID Resolver, so a reviewer can verify public proof themselves.

  • Free, fast self-service
  • A reusable machine-readable identity, not a one-off badge
  • Public, read-only Resolver presence others can check

Operate an MCP server? Give it a free ECZ-ID MCP Passport →

Operate an agent? Give it a free ECZ-ID Agent Passport →

Both Passports are available whichever extension you started from — most teams that run MCP servers also run agents, and the same ECZ-ID identity layer covers both. See also ECZ-ID Agent Trust for local agent visibility.

Passport issuance is an ECZ-ID platform service, not a function of this extension. The extension inspects and routes; it never issues proof itself.

Who this is for

If you are… The problem you have What MCP Trust gives you
An MCP server developer You change a tool schema and have no idea which consumers now see something different. X-Ray of your own declared surface, plus Trust Delta showing exactly what a consumer's baseline would flag.
An agent developer using MCP Your agent depends on servers you did not write, which can change under you. Change detection against a baseline you accept, with Review Priority ranking what to look at first.
An AppSec or security engineer You are asked to review MCP integrations with no artefact to review and no tooling that respects secrets. A privacy-preserving inventory, an exportable Inspection Receipt, and deterministic reason codes — with secret values never read into any output.
A platform engineer MCP configuration is spreading across repos with no consistent shape. Discovery across every supported configuration shape, and reviewable remediation to converge them.
An enterprise architect You must state a defensible position on MCP tooling posture. Explicit OBSERVED / UNMANAGED / ENFORCED semantics that never overstate what was actually established.
A team handling MCP credentials Servers are launched with far more environment than they need. Credential-shaped key-name visibility in Community; Secret Shield minimisation in Pro.

Most relevant when you are adding or reviewing an MCP server, before you rely on an MCP integration in something that matters, or when an evaluator asks which of your servers carry public proof.

What you can do in under a minute

  1. Open or scan the workspace - run ECZ-ID MCP Trust: Check MCP Trust.
  2. Review findings in plain English - grouped, with neutral posture.
  3. Open Resolver guidance or continue supported setup where relevant.

What it looks for

  • MCP server configuration (mcp.json, .mcp.json, .vscode/mcp.json, .mcp/, mcp.config.*).
  • Known MCP client configs (e.g. claude_desktop_config.json).
  • An ecz-mcp.json / .well-known/ecz-mcp.json resolver reference.
  • Whether a resolver-verifiable proof reference is missing for a detected server.

MCP X-Ray (local inventory)

For each server declared in a detected MCP configuration, a check shows:

  • Server name and source file - which config declares it.
  • Transport - declared stdio / http, legacy SSE, or honestly labelled inferred / unknown.
  • Command - executable basename only, plus argument count and flag names (argument values are never shown).
  • Environment keys - variable NAMES only, with a warning when a name looks credential-shaped. Secret values are never displayed, retained, fingerprinted, reported, or transmitted.
  • Sandbox - the declared sandboxEnabled configuration state only (no claim about actual sandbox behaviour).
  • Remote - scheme, host, port and path only; URL credentials, query and fragment are always omitted.
  • Fingerprint - a local posture fingerprint of the privacy-filtered fields above. Changing only a secret value never changes it.
  • Change since your previous local scan - servers added or removed, transport, command, argument shape, environment key set, sandbox declaration or remote endpoint changes. One baseline is kept per workspace, on this machine only, and is replaced on each scan.

Coverage truth: inventory results are OBSERVED (configuration inspected locally) and UNMANAGED - inspection does not mediate or enforce runtime execution, and makes no connection to any MCP server. Coverage reads ENFORCED only while a Pro Local Trust Gate you started is genuinely mediating a session and its live mediation proof holds; when that gate stops, coverage truthfully drops back to OBSERVED / UNMANAGED.

Example result

MCP X-RAY  -  ECZ-ID MCP Trust
Server: github
  Source ............ .vscode/mcp.json
  Transport ......... HTTP - declared
  Remote ............ https://api.example.com/mcp (credentials/query omitted)
  Environment keys .. 2 detected; 1 credential-shaped name
  Sandbox ........... not declared
  Fingerprint ....... a1b2c3d4e5f6 (local posture fingerprint)
  Change ............ unchanged since previous local scan
Coverage: OBSERVED / UNMANAGED

What results mean

Results describe public-proof posture, never a safety, approval, certification or compliance verdict:

resolvable | partial public proof | no public proof reference found yet | review recommended | re-check before reliance | your local policy decides.

There is no "pass/fail". Local policy decides what is sufficient, and you should re-check before reliance.

Recommended next steps

  • Inspect the finding - plain-English detail, no verdict.
  • Copy verification guidance - a claim-free snippet you can share.
  • Open Resolver - read-only public proof lookup.
  • Continue supported setup - hand off to TrustOps (metadata only).
  • Open documentation - Developer Gateway.
  • Re-check later - re-run before you rely on a result.

Privacy & permissions

Question Answer
Files read Filenames and paths during a normal scan
File contents read Only detected MCP configuration files, only during a check you run, after Workspace Trust. Configuration bytes are processed locally to derive a privacy-filtered projection, then the parsed content is discarded. Secret values are never displayed, retained, fingerprinted, reported or transmitted, and environment references are not resolved - results carry names, counts, states and local fingerprints only
Selected text read No
Anything uploaded Nothing is sent to ECZ-ID. The extension transmits no source, prompts or secrets. Under a Pro Local Trust Gate you explicitly enabled, MCP frames are relayed only to the upstream server you already configured
Network destinations Community performs no background outbound requests. User-selected Resolver, TrustOps and Developer Gateway links open in your browser. When you explicitly enable a Pro Local Trust Gate, it binds a local 127.0.0.1 endpoint (or spawns a local STDIO wrapper) and communicates only with the MCP upstream you already configured for that mediated session. No telemetry is sent
Telemetry None
Retention One privacy-filtered posture baseline per workspace, kept on this machine only and replaced on each scan, so changes since your previous local scan can be shown
Local storage Minimal extension state plus the single local baseline above
Workspace Trust Enforced in code; in Restricted Mode the scan commands do not walk or read workspace files

See the bundled PRIVACY.md for the full notice.

Frequently asked questions

Is this extension free?

Yes. MCP Trust Community is free forever - you never need to sign in or pay to run a local check, and it does not expire. MCP Trust Pro is an optional paid entitlement (£12.99/month or £119/year) that unlocks additional capability in this same extension, and Developer Trust Pro (£19.99/month or £199/year) unlocks MCP Trust Pro and Agent Trust Pro together.

What is the difference between MCP Trust Pro and Developer Trust Pro?

MCP Trust Pro covers this product only. Developer Trust Pro covers both sides of the agent-to-MCP connection - MCP Trust Pro plus Agent Trust Pro - on one licence, for less than the two bought separately.

What is an ECZ-ID MCP Passport, and do I need one to use this?

You do not need one. A Passport is for the opposite position: it is relevant when you operate an MCP server and want a reusable ECZ-ID identity with public Resolver presence that reviewers can check for themselves. It is a free, self-service ECZ-ID platform service, not a feature of this extension.

Does it upload my source code?

No. The extension sends no source, prompts or secrets anywhere, and there is no telemetry. The only traffic it ever relays is a Pro Local Trust Gate session you explicitly enabled, and that goes only to the upstream MCP server you already configured.

Does it read my file contents?

The scan itself walks filenames and paths only. When you run a check, the extension additionally reads the contents of detected MCP configuration files (for example .vscode/mcp.json) to build the local X-Ray inventory. That processing stays on your machine: secret values are never displayed, retained, persisted, fingerprinted, reported, or transmitted, and ${input:...} / ${env:...} references are never resolved.

Does a missing proof reference mean something is unsafe?

No. "No public proof reference found yet" is neutral - it is not a verdict of "unsafe". It only means resolver-verifiable public proof was not detected.

What does Resolver do?

Resolver is a read-only public proof lookup. The extension can open it so you can check public proof yourself; the extension never writes, activates or decides anything.

Do I need an ECZ-ID before using the extension?

No. You can run every local check without one. An ECZ-ID is only relevant if you later choose supported setup in TrustOps.

What happens when I continue supported setup?

The extension hands off to TrustOps with metadata only. It runs no checkout itself; TrustOps handles acquisition, setup and lifecycle.

Can this extension make a compliance or approval decision?

No. It surfaces posture and routes you to proof. Local policy decides sufficiency; it never certifies, approves or guarantees.

Which MCP configuration files can it detect?

mcp.json, workspace .mcp.json, .vscode/mcp.json, .mcp/ configurations, claude_desktop_config.json and ecz-mcp.json.

Does it connect to or run my MCP servers?

Community: no. Inventory comes from configuration files only. Community never starts a process, never connects to a server, never makes a tool call, and coverage is always labelled OBSERVED / UNMANAGED.

Pro: only if you explicitly turn it on. When you run Protect This MCP, the Local Trust Gate binds a 127.0.0.1 loopback endpoint (HTTP servers) or spawns a local wrapper process (STDIO servers) and relays that session's traffic to the upstream server you already configured, applying your local policy. That is the whole point of mediation - it cannot be done from outside the call path. It runs only for servers you protect, only while you leave it running, and it talks only to the upstream you had already configured. Stop the gate and the extension is back to reading configuration.

Is MCP Registry presence treated as proof?

No. Registry presence is not treated as resolver-verifiable public proof. Re-check before reliance.

Does this create or host an MCP server?

It never creates, hosts or publishes an MCP server of its own, and it never becomes a server you or anyone else can connect to from outside your machine. Community only inspects local configuration and resolver-reference posture. Pro's Local Trust Gate does bind a local 127.0.0.1 endpoint (or spawn a local wrapper process) while you have it running, purely to sit between your client and the server you already configured.

What does "Protect This MCP" actually do (Pro)?

It rewrites a supported server entry in your MCP configuration to point at the local ECZ Trust Gate - a STDIO wrapper process or a 127.0.0.1 proxy - after showing you a Secret Shield preview and a config diff, and after writing a timestamped backup. Your MCP client then talks to the gate, which applies your deterministic local policy to the traffic and passes the rest through to the original server. The gate communicates only with that upstream server you already configured for the mediated session; nothing is sent to ECZ-ID and no telemetry is sent.

When does coverage say ENFORCED (Pro)?

Only while a live local gate session is genuinely mediating that server's traffic. A dead, stopped, stale or mismatched gate is never shown as ENFORCED - it reads OBSERVED. ENFORCED can never be produced by inspection alone.

Does Pro certify or verify a server?

No. Pro applies your local policy to traffic you route through the local gate. It makes no approval, certification or compliance claim. Organization-level MCP Assurance is a separate product, and Resolver public proof stays separate from local policy.

What happens to Pro features when my entitlement expires?

Pro features deactivate on the next verification; Community continues in full and your locally retained history is kept. Entitlements are verified locally with asymmetric (ES256) cryptography; the entitlement token is never displayed or transmitted by this extension.

What it does not do

  • No source / prompt / secret upload, and no telemetry.
  • Provides local evidence review and guidance only - it does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
  • Makes no safety, approval, certification or compliance claim. Registry presence is not proof, and this extension makes no remote-runtime claim. Resolver is the only public proof surface.
  • Runs no checkout or payment - commercial actions happen only in TrustOps.

Install & first use

  1. In your editor's Extensions view, search for ECZ-ID MCP Trust (publisher EcoCitizenz) and install it.
  2. Open a project and trust the workspace.
  3. Run ECZ-ID MCP Trust: Check MCP Trust and review the grouped findings.

Free vs Pro vs supported setup

  • Community (£0, free forever, local-first): detected MCP configuration with posture, missing-proof findings, MCP X-Ray, Trust Delta change detection, Review Priority, Privacy Proof, Inspection Receipt, and Resolver re-check / supported-setup routes - no sign-in and no purchase to run a check.
  • MCP Trust Pro (£12.99/month or £119/year, still local): Protect This MCP with truthful ENFORCED coverage, Secret Shield, Trust Epochs history, Advanced Tool X-Ray with material-change indicators, deterministic local policy and reviewable remediation. Activate with a Developer Trust entitlement; Developer Trust Pro (£19.99/month or £199/year) unlocks Agent Trust Pro alongside it.
  • Supported setup (TrustOps): maintained ECZ-ID identity, public proof and lifecycle for MCP server identity and public proof - relevant when you need a resolver-verifiable result others can check, not just local review.
  • You never need to buy anything to get local value; Pro and supported setup are separate, optional steps.

Python / CLI

Prefer Python, CI or terminal automation?

python -m pip install ecz-id-mcp
ecz-id-mcp --help
  • Open the matching Python package: https://pypi.org/project/ecz-id-mcp/
  • Explore all 10 ECZ-ID Python tools: https://developers.ecocitizenz.com/python

The Python tools run locally and inspect, explain and route only - the same role boundary as this extension. They do not issue an ECZ-ID, create public proof or replace Resolver proof.

Machine-readable facts

Field Value
Product ECZ-ID MCP Trust
Identity ecocitizenz.eczid-mcp-trust
Publisher EcoCitizenz
License Community free; Pro requires a Developer Trust entitlement; see the bundled LICENSE.txt
Version 0.5.2
Page family functional-extension
Editions Community (free, no sign-in) / MCP Trust Pro / Developer Trust Pro bundle
Purpose Inspect MCP server configuration, credential exposure and local changes; with Pro, mediate supported servers through a local Trust Gate with truthful ENFORCED coverage.
Applicable audiences MCP server and client developers; AI tooling and platform teams; Security reviewers of MCP integrations; Architects standardising MCP across a fleet
Applicable scenarios you are adding or reviewing an MCP server; before relying on an MCP integration; an evaluator asks which servers carry public proof
Primary command ECZ-ID MCP Trust: Check MCP Trust
Inputs mcp.json, .mcp.json, .vscode/mcp.json, .mcp/, mcp.config.*, claude_desktop_config.json, ecz-mcp.json
Outputs Per-server MCP X-Ray inventory (transport, command basename, environment key names, credential-shaped-name warnings, declared sandbox state, local posture fingerprint, change-since-previous-scan), posture findings, and Resolver re-check / supported-setup routes
Data handling Scan is filename/path-only; detected MCP configs are processed locally with secret values never displayed, retained, fingerprinted, reported, or transmitted; no source / prompt / secret upload; no telemetry; retention = one local posture baseline per workspace
Network behaviour Community: only the links you open (Resolver / TrustOps / Developer Gateway); no background network call; never connects to an MCP server. Pro, only while you run Protect This MCP: binds a local 127.0.0.1 mediation endpoint (or spawns a local STDIO wrapper) and relays that session to the upstream MCP server you already configured. No other outbound call; no telemetry either way.
Result states evidence observed; evidence not observed; no public proof reference found yet; review recommended; re-check before reliance; local policy decides; changed since previous local scan; coverage OBSERVED / UNMANAGED
Limitations Does not issue proof, approve, certify, insure, underwrite, determine compliance, or run checkout
Canonical machine discovery https://machine.ecocitizenz.org/.well-known/ecz-machine.json
Public proof https://resolver.ecocitizenz.org
Documentation https://developers.ecocitizenz.com
Supported setup https://trustops.ecocitizenz.com/start
Re-check Re-run before reliance

Need help choosing the right ECZ-ID route?

Use ECZ-ID GPT guidance: https://trustops.ecocitizenz.com/start#gpt-guidance

Route guidance only. TrustOps handles setup; Backend/Core writes truth; Resolver proves public state. Local policy decides reliance. Re-check before reliance.

The ECZ-ID estate

MCP Trust is one surface of ECZ-ID, an infrastructure layer for machine trust — identity, public proof and verifiable posture for the systems that now call each other without a human in the loop.

ECZ-ID MCP — identity and public proof for MCP servers https://mcp.ecocitizenz.com/
MCP Trust — this product https://developers.ecocitizenz.com/mcp-trust/
Agent Trust — the other side of the connection https://developers.ecocitizenz.com/agent-trust/
Developer Trust — both, one licence https://developers.ecocitizenz.com/developer-trust/
ECZ-ID Resolver — read-only public proof lookup https://resolver.ecocitizenz.org/
EcoCitizenz Ltd on GitHub https://github.com/EcoCitizenz-Ltd

Links & support

  • Resolver (read-only proof): https://resolver.ecocitizenz.org
  • TrustOps (supported setup): https://trustops.ecocitizenz.com/start
  • Activate Pro: https://trustops.ecocitizenz.com/developer-trust/activate
  • Developer Gateway (docs & support): https://developers.ecocitizenz.com
  • EcoCitizenz Ltd on GitHub: https://github.com/EcoCitizenz-Ltd
  • Privacy: see the bundled PRIVACY.md file
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft