Aether MCP Server

Connect Claude to the truth layer.

A thin MCP server (one Cloudflare Worker) exposes Aether's real verification engine to Claude Desktop, ChatGPT, and any MCP client. Paste an AI answer, get a signed, trust-scored warrant — no regex, no in-memory state, the attestation key never leaves Base44.

How it works

The Worker is a transport only. When Claude calls verify_claim, the Worker forwards it to your Base44 warrantApi function, which:

  • decomposes the text into atomic claims,
  • runs the proposer / critic / verifier tribunal + red-team,
  • signs the warrant with sf2x_attestation_key (the secret stays in Base44),
  • persists it to the Warrant entity (durable, restart-safe),
  • returns warrant_id + lineage_id + the signed warrant.

A KV cache lets explain_verdict / get_warrant retrieve prior decisions without a second tribunal run. Quota is enforced upstream by warrantApi per API key.

MCP tools

verify_claim

Verify an AI-generated answer for hallucinations. Runs the full tribunal (proposer/critic/verifier + red-team), returns a calibrated trust score, verdict, and a cryptographically signed warrant persisted to Base44.

Input
{ "text": "<AI response>", "domain": "Medicine", "sources": [{ "url": "https://..." }] }
Output
{ "verification_id": "...", "warrant_id": "...", "verdict": "contested", "trust_score": 62, "certified": true, "warrant_signed": true }
explain_verdict

Explain a prior verification decision. Returns the verdict, trust score, and certification status for a given verification id.

Input
{ "verification_id": "<id from verify_claim>" }
Output
{ "verification_id": "...", "verdict": "contested", "trust_score": 62, "certified": true, "certification": "certified" }
get_warrant

Retrieve the full signed warrant — the durable proof artifact with premises, signature, and expiry.

Input
{ "verification_id": "<id from verify_claim>" }
Output
{ "warrant_id": "...", "signed_hash": "...", "premises": [...], "sources": [...], "certified": true }

Deploy (5 steps)

1
Copy the Worker files
Grab the four files in src/mcp-worker/ (worker.js, wrangler.toml, package.json, README.md) into a new GitHub repo.
2
Create the KV namespace
npx wrangler kv namespace create WARRANTS — paste the printed id into wrangler.toml.
3
Set the warrantApi URL
In wrangler.toml, set AETHER_WARRANT_API_URL to your Base44 warrantApi endpoint.
4
Set the two secrets
npx wrangler secret put AETHER_API_KEY (your SF2X_API_KEY) and npx wrangler secret put AETHER_MCP_TOKEN (a long random string).
5
Deploy
npx wrangler deploy — you get a public URL like https://aether-mcp.<your-subdomain>.workers.dev.

Full instructions in src/mcp-worker/README.md.

Connect Claude

Paste your deployed Worker URL + token below. The Claude Desktop config and test command update automatically.

claude_desktop_config.json
{
  "mcpServers": {
    "aether": {
      "url": "https://aether-mcp.YOUR-SUBDOMAIN.workers.dev",
      "headers": {
        "Authorization": "Bearer YOUR_AETHER_MCP_TOKEN"
      }
    }
  }
}
test (tools/list)
curl -X POST https://aether-mcp.YOUR-SUBDOMAIN.workers.dev \
  -H "Authorization: Bearer YOUR_AETHER_MCP_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Security

• Bearer-token auth on the Worker (your AETHER_MCP_TOKEN); the Aether API key is a separate server-side secret.

• SSRF guard rejects non-http(s) and private/internal source URLs before they reach the verifier.

• The attestation key never leaves Base44 — signing happens inside the warrantApi function, not the Worker.

• Quota + rate limits are enforced upstream by warrantApi per API key.

Get an API key

The Worker calls warrantApi with your Aether API key. Generate one in the Portal, then set it as AETHER_API_KEY in the Worker.

See the REST API docs
Aether · The Truth Layer for AI · every AI response verified, scored, and warrant-backed.