Back to Browse

Vorim MCP Server

by Kzino
Developer ToolsLow Risk9.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI

About

AI agent identity, permissions, trust scores, and tamper-evident audit trails via Vorim AI

Security Report

9.0
Low Risk9.0Low Risk

Valid MCP server (3 strong, 5 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry.

5 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Vorim API key (agid_sk_live_...)Required

Environment variable: VORIM_API_KEY

Vorim API base URLOptional

Environment variable: VORIM_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-kzino-vorim-mcp-server": {
      "env": {
        "VORIM_API_KEY": "your-vorim-api-key-here",
        "VORIM_BASE_URL": "your-vorim-base-url-here"
      },
      "args": [
        "-y",
        "@vorim/mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Vorim AI — MCP Server

npm version smithery badge MIT License

Give every AI agent its own cryptographic identity, scoped permissions, and a tamper-evident audit trail — directly from Claude Desktop, Cursor, or any MCP-compatible client.

What is Vorim AI?

Vorim AI is the identity and trust layer for autonomous AI agents. It gives each agent its own Ed25519 keypair, time-bounded scoped permissions, hash-linked audit events, and a publicly verifiable trust score — so when an agent does something, you can prove who acted, what they were allowed to do, and what happened.

The protocol underneath (VAIP) is open, MIT-licensed, and submitted to IETF as draft-nyantakyi-vaip-agent-identity-01.

This package is the MCP (Model Context Protocol) server that exposes 19 Vorim tools to any MCP-compatible AI client.

Works with Claude Desktop, Cursor, VS Code, Google Antigravity, and any other MCP client.

Quick Start

npm install -g @vorim/mcp-server

Or run directly with npx:

VORIM_API_KEY=agid_sk_live_... npx @vorim/mcp-server

Configuration

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

Cursor

Add to .cursor/mcp.json in your project root:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

VS Code

Add to your VS Code MCP settings with the same format.

Google Antigravity

Add to the workspace config at .agents/mcp_config.json, or the global config at ~/.gemini/config/mcp_config.json:

{
  "mcpServers": {
    "vorim": {
      "command": "npx",
      "args": ["@vorim/mcp-server"],
      "env": {
        "VORIM_API_KEY": "agid_sk_live_..."
      }
    }
  }
}

You can also add it from the UI: Settings → Customizations → Installed MCP Servers → Add MCP.

Get an API Key

  1. Sign up at vorim.ai (free, no credit card)
  2. Go to Settings > API Keys
  3. Create a key with agents:*, audit:*, trust:* scopes

Available Tools (19)

Health

ToolDescription
vorim_pingCheck API health and connectivity

Agent Identity

ToolDescription
vorim_register_agentRegister a new agent with Ed25519 cryptographic identity
vorim_register_ephemeralRegister a did:key ephemeral agent with TTL
vorim_get_agentGet agent details by ID
vorim_list_agentsList all agents with pagination and filtering
vorim_update_agentUpdate agent metadata (name, description, status)
vorim_revoke_agentPermanently revoke an agent

Permissions

ToolDescription
vorim_check_permissionCheck if agent has a permission scope (sub-5ms)
vorim_grant_permissionGrant a permission with optional expiry and rate limits
vorim_list_permissionsList all active permissions for an agent
vorim_revoke_permissionRevoke a specific permission scope

Credential Delegation

ToolDescription
vorim_delegate_credentialDelegate OAuth credentials to an agent
vorim_request_tokenAgent requests a short-lived access token
vorim_list_delegationsList active credential delegations

Audit

ToolDescription
vorim_emit_eventLog an audit event for an agent action
vorim_export_auditExport signed audit bundle with SHA-256 manifest

Trust

ToolDescription
vorim_verify_trustVerify agent trust score (public, no auth required)

Onboarding

ToolDescription
vorim_onboard_startStart device-authorization onboarding for a user with no API key; returns a user code and activation URL
vorim_onboard_checkCheck whether the user approved onboarding and retrieve the issued API key

Example Usage

Once configured, use natural language in Claude, Cursor, or any MCP client:

  • "Register an agent called invoice-processor with read and execute permissions"
  • "Check if agent agid_acme_a1b2 has permission to execute"
  • "Log a tool_call event for the agent: action=process_invoice, result=success"
  • "What's the trust score for agent agid_acme_a1b2?"
  • "Export the audit trail for the last 30 days"
  • "Delegate my GitHub OAuth token to this agent for 24 hours"
  • "Revoke agent agid_acme_a1b2"

Why Use Vorim AI

  • Cryptographic identity — Ed25519 keypairs for every agent. Not a shared service account.
  • Fine-grained permissions — 7 scopes with time bounds and rate limits, sub-5ms checks.
  • Tamper-evident audit trails — SHA-256 hash-linked events, signed export bundles for compliance.
  • Public trust scoring — anyone can verify any agent without auth (no shared secrets).
  • Open protocol — VAIP submitted to IETF, MIT-licensed, freely implementable.
  • Compliance-ready — EU AI Act, US Executive Order 14110, SOC 2, GDPR.

Environment Variables

VariableRequiredDefaultDescription
VORIM_API_KEYYesYour Vorim API key (agid_sk_live_...)
VORIM_BASE_URLNohttps://api.vorim.aiAPI base URL (override for self-hosted)

Links

License

MIT — see LICENSE for details.


Built by Vorim AI. Questions or feedback: kwame@vorim.ai.

Reviews

No reviews yet

Be the first to review this server!