Signed evidence record · csoai/mcp-contract-parity
csoai/mcp-contract-parity
CURRENT. This is the newest signed record in this series. Every version stays published: all versions.
The signed numbers, verbatim
Every field of the signed payload, copied as signed. Nothing on this page is computed, rounded or totalled.
read_state | EXHAUSTED |
|---|---|
n_planned | 5828 |
n_attempted | 5828 |
dimension_states.AUTH | {"CONSISTENT": 931, "INCONSISTENT": 23, "SINGLE_SURFACE": 4465, "UNCHECKABLE": 409} |
dimension_states.PAYMENT | {"CONSISTENT": 112, "INCONSISTENT": 4, "SINGLE_SURFACE": 572, "UNCHECKABLE": 5140} |
dimension_states.PROTOCOL | {"CONSISTENT": 459, "INCONSISTENT": 33, "SINGLE_SURFACE": 5064, "UNCHECKABLE": 272} |
dimension_states.TOOLS | {"CONSISTENT": 905, "INCONSISTENT": 233, "SINGLE_SURFACE": 4532, "UNCHECKABLE": 158} |
dimension_states.VERSION | {"CONSISTENT": 3163, "INCONSISTENT": 2644, "SINGLE_SURFACE": 21, "UNCHECKABLE": 0} |
own_result.VERSION | CONSISTENT |
own_result.TOOLS | CONSISTENT |
own_result.AUTH | CONSISTENT |
own_result.PAYMENT | CONSISTENT |
own_result.PROTOCOL | SINGLE_SURFACE |
Limits the record states about itself
signed payload: not_a_grade— The signature proves these bytes were signed by the board key; it does not prove any claim inside beyond what the record's own instrument measured.run.population_note— endpoints the 25 Sep 2026 census probe saw RESPOND (top-20% and first-party plans), plus AUTH_REQUIRED endpoints whose registry entry advertises x402 or an A2A card, plus the endpoints of registry entries named in an external watch list. Counts are over attempted endpoints of this plan: not frame totals, not population totals, never summed with other censuses.timing.caveat— live answers and surface documents were read up to ~5.5 h apart. Where the registry version changed in between (HOLD window W2), the row uses the hold re-probe read inside the surface window. A service that changed without a registry version change in that interval can still show a live-vs-document INCONSISTENT; registry changes after the W2 read (11:25:23Z) are not observed.what_it_does_not_show— runtime auth enforcement beyond the discovery boundary (initialize + tools/list); tools/call is never sentwhat_it_does_not_show— backend behaviour, tool correctness, safety, or quality of any service or vendorwhat_it_does_not_show— which surface is right: an INCONSISTENT row says two public statements disagree, not which one is truewhat_it_does_not_show— anything from documentation prose, except a registry description's literal mention of x402 (payment presence only)what_it_does_not_show— anything about endpoints not in the plan or not attemptedwhat_it_does_not_show— simultaneity: live answers and documents were read hours apart (see timing); a deploy in between can show as INCONSISTENT
Identity
| record | record.json |
|---|---|
| record sha256 | 45e3fd63fc98ad251a4f9fe5fdb705ed7fbc28321d5c205d10114a21730cc323 (recomputed from the bytes; equals the signed artifact.sha256) |
| record schema | csoai.mcp-contract-parity/0.1 |
| as_of | 2026-09-25T12:24:52Z |
| signed document | record.signed.json · sha256 58458051bb7b1db6a5d32f22ee08ad345434c8e57df74e4d62deab713904d5fa |
| signature | VERIFIED under did:web:csoai.org#board-attestation-1; payload sha256 59dacc84e9f70c656c90567b37fe0201e01fe9c33b5567e5a705c374b43952f0; signed_at 2026-09-25T12:25:41.808Z; tamper control rejected |
| pinned at | Hugging Face dataset csoai/mcp-contract-parity, revision 0a4dc496d588398b8a5f1b8fc619a91cc3be0bbf |
Files the signature pins
hold.jsonl.gz | ec0a40f009eb571f766ccb71fa8b54cf1b6569d67ac2c68cb246a82f1b62f105 |
rows.jsonl.gz | 92b0fae322d9711b3ea1700401caacc27b9f59a7dee872f3c14404018691edca |
Timestamp (OpenTimestamps)
PENDING_CALENDAR_COMMITMENT. Calendars accepted the digest and promised future Bitcoin inclusion. This is a submitted request, not a Bitcoin attestation.
- proof:
record.json.ots—PENDING_CALENDAR_COMMITMENT
Verify it yourself
Free, no account, no key. The first command asks the site's verifier door; the second checks that the record bytes are the ones the signature pins; the third checks the timestamp with the OpenTimestamps client.
curl -sL 'https://huggingface.co/datasets/csoai/mcp-contract-parity/resolve/0a4dc496d588398b8a5f1b8fc619a91cc3be0bbf/record.signed.json' -o signed.json curl -s -X POST https://councilof.ai/api/verify -H 'content-type: application/json' --data-binary @signed.json # expect "state": "VALID" (Ed25519 over the canonical payload, pinned board key) curl -sL 'https://huggingface.co/datasets/csoai/mcp-contract-parity/resolve/0a4dc496d588398b8a5f1b8fc619a91cc3be0bbf/record.json' | sha256sum # must print 45e3fd63fc98ad251a4f9fe5fdb705ed7fbc28321d5c205d10114a21730cc323 curl -sL 'https://huggingface.co/datasets/csoai/mcp-contract-parity/resolve/0a4dc496d588398b8a5f1b8fc619a91cc3be0bbf/record.json' -o record.json curl -sL 'https://huggingface.co/datasets/csoai/mcp-contract-parity/resolve/0a4dc496d588398b8a5f1b8fc619a91cc3be0bbf/record.json.ots' -o record.json.ots ots verify -f record.json record.json.ots
The record's own verification instructions, verbatim:
signature— record.signed.json: canonicalise payload (JSON, keys sorted, no whitespace, UTF-8); sha256 must equal signature.payload_sha256; payload.artifact.sha256 must equal sha256(record.json); verify sig_ed25519 with #board-attestation-1 in https://csoai.org/.well-known/did.jsontimestamp— record.json.ots: OpenTimestamps over sha256(record.json); PENDING calendar commitment at publication