MCP already has OAuth 2.1. It tells you who the user is.
But OAuth proves session auth โ it doesn't prove this specific user authorized this exact request, over this exact payload, right now.
No per-request non-repudiation. No audit trail.
Introducing mcp-identity ๐
Milo doesn't understand why he's back. ๐ฅบ
As a puppy, Milo made the long journey from Georgia to New York in search of the one thing every rescue dog dreams of - a family to call his own. It didn't take long for someone to fall in love with his sweet face, and before he knew it, he was heading home.
We thought his story had its happy ending.
But recently, Milo was returned to us.
Now, this handsome Boxer mix sits in his kennel wondering where the people he loved went. Every day, he watches visitors walk by... his tail wagging with hope. He stretches up to greet anyone willing to stop, soaking up every pet and happily accepting a treat from a friendly hand. Despite the heartbreak he's endured, Milo's heart remains wide open.
At around 60 pounds, Milo is a big boy with an even bigger capacity for love. He's strong, playful, and full of enthusiasm for life, so he'll do best with an adopter who can handle his larger-than-life personality. He enjoys meeting people, does well with children ages 6 and up, and may be able to share his home with another dog after a successful meet-and-greet.
What breaks our hearts most is knowing Milo already had a home once. He already believed he was chosen forever.
Now he needs someone to prove that forever wasn't a promise he was never meant to keep.
๐ Milo #G29839 is waiting at North Shore Animal League America in Port Washington, NY. If you've been looking for a loyal best friend with a heart of gold, Milo is waiting for you.ย
#GetYourRescueOn
Use it when your MCP server does anything a user might later dispute:
โ financial ops
โ data deletion
โ external messages
โ autonomous agent actions
Strict: unsigned = 401
Permissive: unsigned = logged UNVERIFIED
pip install mcp-identity
MCP already has OAuth 2.1. It tells you who the user is.
But OAuth proves session auth โ it doesn't prove this specific user authorized this exact request, over this exact payload, right now.
No per-request non-repudiation. No audit trail.
Introducing mcp-identity ๐
One HTTP header. X-MCP-Identity-Attestation.
Every request signed with ed25519 over the exact payload. Your server verifies in milliseconds.
Works alongside OAuth โ additive, not a replacement.
https://t.co/Gqpqgo1zXR
Everyone is asking if the Hormuz is open but nobody is asking what it used to look like when it was open.
So I made https://t.co/STZyTfawho to satisfy my curiosity.
People live here. And yet I kept seeing the same headline โ another tanker standoff, another risk premium spike, another red arrow on a map I couldn't picture.
Enjoy it.
Everyone is asking if the Hormuz is open but nobody is asking what it used to look like when it was open. So I made https://t.co/H0AW2WdI9X to satisfy my curiosity. Enjoy it.
The beach used to fill with families in the afternoon, kids running between the water and the vendors selling tea and bread, a fisherman casting nets while mothers watched from the shade. Today the strait has been closed for one day and only 9 ships made it through instead of the 107 that used to come, so the families are still here but the fishermen are not, and the water is too quiet to hear the engines anymore.
https://t.co/STZyTfb46W
There's a 24/7 AI radio station reporting on the Iran war live right now.
Two hosts. Updating every few minutes. You join mid-broadcast like tuning into NPR.
I built it. It's free. https://t.co/dnCW4fCxgH
Also has a live map, threat index, and for $9/mo โ a morning brief + alert if fighting reaches a country you have family in. built with @Replit