Skip to product choices
IFFInspect first
Updates
EN

Two services · separate claims

Choose the evidence you need.

IFF keeps external endpoint observations separate from portable artifact provenance. Start with what you want to inspect.

Public x402 endpointsExternal observation

x402 Evidence Monitor

See what an external monitor observed from a public x402 endpoint's unpaid response: ownership, protocol behavior, availability, freshness and signed provenance.

No payment is sent. The evidence is not a safety score or delivery guarantee.

Signed agent artifactsAlpha · 0.1

Apostille

Apostille v0.1.0-alpha.1 is available as a Go SDK and local CLI. Sign agent artifacts and verify portable bundles offline with independently pinned issuer keys. JavaScript source and an offline browser verifier are also available.

It does not establish content truth, legal identity or legal effect. It also does not prove current ownership or payment authority.

MCP alpha · For your AI client

Let your agent read the evidence.

MCP (Model Context Protocol) lets compatible AI clients use IFF tools. Our public Streamable HTTP service runs on Railway: no local server, account or API token is needed.

  1. Choose the endpoint for the evidence you need.
  2. Add its URL as a Streamable HTTP server in your MCP client.
  3. Ask your agent to inspect a public endpoint or verify a signed bundle.

x402 Monitor

13 read-only tools

Read public x402 observations, compare payment requirements, and check transparency-log proofs and receipts. No payment is sent.

“What did IFF observe about this x402 endpoint?”
Streamable HTTP endpointhttps://iff-mcp-api-production.up.railway.app/mcp/iff
x402 MCP setup

Apostille

7 read-only tools

Verify bundle signatures or detached ERC-8004 bindings, and read public issuer data. Supply independently chosen issuer/key pins when deciding trust.

“Do this bundle’s signatures match the issuer and key I pinned?”
Streamable HTTP endpointhttps://iff-mcp-api-production.up.railway.app/mcp/apostille
Apostille MCP setup

Checks run on the hosted server; they are not independent verification inside your client. These public tools cannot log in, sign, publish or pay. Never send private keys, original files or ZK witnesses. Use a local verifier when independent verification is required.