Back to Browse

Veris MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Provenance-first web + SEC EDGAR data for AI agents: every fact carries its verifiable source.

About

Provenance-first web + SEC EDGAR data for AI agents: every fact carries its verifiable source.

Security Report

4.2
Use Caution4.2High Risk

veris is a well-architected web provenance and financial data MCP server with clean code structure and appropriate security controls. Authentication is optional but properly gated (API keys for hosted instances); permissions align well with its purpose (web fetching, SEC EDGAR access, file caching). Minor code quality concerns around error handling and input validation are present but do not constitute security vulnerabilities. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Optional Brave Search API key; falls back to keyless DuckDuckGo if unset.Required

Environment variable: BRAVE_API_KEY

SEC fair-access User-Agent ('Name email@domain') for EDGAR; a default ships.Optional

Environment variable: SEC_USER_AGENT

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jakeyoung1-veris": {
      "env": {
        "BRAVE_API_KEY": "your-brave-api-key-here",
        "SEC_USER_AGENT": "your-sec-user-agent-here"
      },
      "args": [
        "-y",
        "veris-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

veris

npm version license · npx -y veris-mcp

Provenance-first web access for AI agents. Clean content plus verifiable source metadata, in one call.

Today an AI agent reading the web gets a wall of text. It does not get: when the page was published, whether the content changed since last time, who wrote it, the canonical source, or the license terms. veris attaches all of that to every read.

web_read("https://example.com/article")
  → clean markdown
  + { publishedAt, modifiedAt, author, canonicalUrl, contentHash, license, fetchedAt }

That metadata is not a nice-to-have. It is the foundation the rest of the AI-web economy needs: freshness, change-detection, citation, and — eventually — paying the people who wrote the content.


Why this exists

The web is being scraped by AI with no attribution and no payment. Publishers are responding by blocking bots and locking content. AI gets worse; publishers lose. The fix is a layer between agents and publishers that reads cleanly, tracks provenance, and (later) settles payment.

veris is the agent-side of that layer — the SDK every agent imports to consume the web responsibly. Think "Plaid for the AI web": you don't own the publishers, you own the integration developers reach for.

Roadmap (one codebase, three stages)

StageWhatStatus
1. Clean + provenancesearch / read / research with verifiable source metadata
2. Finance verticalSEC EDGAR filings with authoritative, official provenance
3. Settlementlicense-aware access + micropayment + attribution🔜 seams in policy.ts + cache.ts

The Stage 3 seams already exist in the code (policy.ts, cache.ts) so growth is additive, not a rewrite.

Tools

Web

ToolDoes
web_search(query, n?)Ranked results as structured JSON. Brave (with key) or keyless DuckDuckGo.
web_read(url, fresh?)URL → clean markdown + provenance block. 24h cache.
web_research(query, n?)Search + read top N + bundle with per-source citations.

Finance — SEC EDGAR (free, official, no API key)

ToolDoes
finance_filings(query, formType?, limit?)Ticker / name / CIK → recent SEC filings: form, official filing & report dates, accession, direct document URL.
finance_filing_read(url or query, formType?)Read a filing by URL, or auto-read the latest matching form for a company. Clean text + provenance.
finance_financials(query)Revenue, net income, total assets, cash, diluted EPS from SEC XBRL — each figure stamped with the exact filing it came from.

Why EDGAR first? Filings carry authoritative dates and identifiers straight from the SEC — provenance isn't guessed, it's official. Free, structured, no auth. One call gets an agent the latest 10-K with a verifiable source:

finance_filing_read({ query: "NVDA", formType: "10-K" })
  → NVIDIA CORP — 10-K (filed 2026-02-25)
    clean text + { source, filed date, contentHash, wordCount }

Watch — change detection & alerts

ToolDoes
watch_manage(action, target?, formType?)Add/remove/list watches: a company's SEC filings (ticker + optional form like 8-K) or any URL (content-hash watch).
watch_check()Check all watches; returns only what's NEW (new filings / changed pages) and rolls baselines forward. Run it on a schedule → alert feed.

Install

npx -y veris-mcp        # zero-install, always latest

Or from source:

git clone https://github.com/jakeyoung1/veris && cd veris
npm install && npm run build

Optional env:

export BRAVE_API_KEY=your_key                      # better search; https://search.brave.com/app/keys
export SEC_USER_AGENT="Your Name you@email.com"    # SEC fair-access policy (recommended)

Without a Brave key, search falls back to keyless DuckDuckGo automatically. SEC requires a Name email@domain style User-Agent — veris ships a default, but set your own contact.

Use in Claude Code

Add to your MCP config (.mcp.json):

{
  "mcpServers": {
    "veris": {
      "command": "npx",
      "args": ["-y", "veris-mcp"],
      "env": { "BRAVE_API_KEY": "optional", "SEC_USER_AGENT": "Your Name you@email.com" }
    }
  }
}

Restart Claude Code, then ask it to web_research something.

Remote server (HTTP)

Run veris as a remote MCP server (Streamable HTTP) and connect from any MCP client by URL:

npx -y veris-mcp http                            # http://127.0.0.1:8787/mcp
VERIS_HTTP_HOST=0.0.0.0 npx -y veris-mcp http    # expose it (put TLS in front)
EnvDoes
VERIS_PORT / PORTPort (default 8787)
VERIS_HTTP_HOSTBind host (default 127.0.0.1)
VERIS_API_KEYSComma-separated keys. If set, /mcp requires Authorization: Bearer <key> (or x-api-key). Unset = open.
VERIS_RATE_LIMITRequests/min/IP (default 60)

Self-hosting is free, forever. VERIS_API_KEYS exists so a hosted instance can be metered.

Docker

docker build -t veris .
docker run -p 8787:8787 veris

Works as-is on Fly.io / Render / Railway — anything that runs a Dockerfile.

Design notes

  • Provenance from raw HTML. We fetch the page ourselves and pull dates/author/canonical from <meta>, JSON-LD, and Open Graph before readability strips them.
  • Content hash. sha256 of extracted text — detects whether a page changed and enables dedupe across agents (the basis for a shared web index).
  • Provider interface. Swap search backends without touching tool code.
  • Cache → ledger. The same keyed store that caches reads today records read events for settlement tomorrow.

License

MIT

Reviews

No reviews yet

Be the first to review this server!