git clone https://github.com/keyhalve/keyhalve-mcp && cp keyhalve-mcp/*.md ~/.claude/agents/Subagents overview
# KeyHalve verify-MCP Free, public, no-account [MCP](https://modelcontextprotocol.io) server that lets any AI verify KeyHalve-sealed documents — from **any** platform on the rail (ValidPay, CheckBooks, …). *Seal = the door (a platform's paid MCP). Verify = the room (this one, free forever).* - **Endpoint:** `https://mcp.keyhalve.com/mcp` (Streamable HTTP, stateless) - **Tools:** `keyhalve_verify` · `keyhalve_status` · `keyhalve_explain` — all read-only, no auth ## The blindness rule This server **never receives decryption keys.** A verify URL carries the holder's key share in the `#key=` fragment; `parseInput` discards any fragment **before any other logic runs**, and the response says so. Verification here covers everything provable *without* the key: | Check | Meaning | |---|---| | status | active / revoked (with reason) on the issuing platform | | ciphertext integrity | SHA-256 of the served ciphertext = commitment recorded at issuance (v2) | | rail attestation | Ed25519-verified against the **pinned** rail key; dual-sign content binding when present | | time lock | validity window judged client-side (Patent D semantics) | | issuer trust | fail-closed: `declared` at best, never proof | Reading the sealed contents still happens **only in the holder's browser** — exactly like the web verifier. The overall verdict fails closed: any failed check → `FAILED — DO NOT TRUST`. ## Design notes - **Zero runtime dependencies.** WebCrypto only; the whole protocol layer is hand-auditable. Same reasoning as the pinned-key rail client in `keyhalve-website`. - **Stateless.** No sessions, no SSE, no KV, no cookies; every POST gets `application/json`. Request bodies are never logged. - **Tenant-neutral.** Platforms come from the same manifest data as the web verifier (`TENANT_MANIFEST` in `src/verifier.ts`); onboarding a platform = one data entry. - **Fail closed.** Unreachable rail, malformed share, partial dual-sign binding, unknown id prefix — all report NOT verified, never a soft pass. ## Develop / deploy ``` npm ci npm run typecheck && npm test # 32 tests npm run dev # wrangler dev ``` Deploys are **manual** (`deploy.yml` via workflow_dispatch, same discipline as rail/console). Needs the `CLOUDFLARE_API_TOKEN` repo secret; the route `mcp.keyhalve.com` is a custom domain on the business CF account (same account as the watchdog scheduler). ## Directory submissions (Mike-gated) Submitting to the Claude Connectors Directory / ChatGPT App Directory is an outward-facing step — prepared separately, goes out only on Mike's go. ## Listings Directory-listing assets live in this repo — reuse them, don't invent copy: - `llms-install.md` — AI-agent install steps (Cline's AI-driven install; also the canonical per-client snippets). - `glama.json` — Glama claim file (maintainers; their live schema is maintainers-only). - `assets/icon-400.png` — 400×400 icon (white split-circle glyph on Ink #0E1116, from the brand kit). - Descriptions must stay byte-consistent with `src/tools.ts` and pass the approved-claims register (no "split key", no "tamper-proof", no issuer-identity claims).
What people ask about keyhalve-mcp
What is keyhalve/keyhalve-mcp?
+
keyhalve/keyhalve-mcp is subagents for the Claude AI ecosystem with 0 GitHub stars.
How do I install keyhalve-mcp?
+
You can install keyhalve-mcp by cloning the repository (https://github.com/keyhalve/keyhalve-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is keyhalve/keyhalve-mcp safe to use?
+
keyhalve/keyhalve-mcp has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.
Who maintains keyhalve/keyhalve-mcp?
+
keyhalve/keyhalve-mcp is maintained by keyhalve. The last recorded GitHub activity is from today, with 0 open issues.
Are there alternatives to keyhalve-mcp?
+
Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.
Deploy keyhalve-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/keyhalve-keyhalve-mcp)<a href="https://claudewave.com/repo/keyhalve-keyhalve-mcp"><img src="https://claudewave.com/api/badge/keyhalve-keyhalve-mcp" alt="Featured on ClaudeWave: keyhalve/keyhalve-mcp" width="320" height="64" /></a>More Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
The agent engineering platform.
Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.