Attestari
ai.attestariv0.2.1Updated Oct 7, 2026
Attestari's verdict on an npm or PyPI package version, asked before an agent installs it.
Overview
AI-generated overview
Attestari returns a verdict on an npm or PyPI package version before an assistant installs it.
- What it does
- Attestari is a remote MCP server that gives an assistant a verdict on a specific npm or PyPI package version, asked before the agent installs it. It is reached over streamable HTTP at a hosted endpoint, and a PyPI package is also offered for running it locally over stdio. The manifest lists no individual tools.
- When to use it
- Use it when an assistant installs or upgrades third-party packages and you want a check on a given version first. It fits dependency-review or supply-chain steps in an agent workflow.
- Requirements
- A remote endpoint or the local PyPI package (Python runtime for stdio). An Attestari API key is required, supplied as the environment variable ATTESTARI_API_KEY, and the manifest states it is for Developer tier and above. Network access to the hosted endpoint.
Before you install
The server requires a secret API key (ATTESTARI_API_KEY), which should be stored and shared carefully. The manifest declares no authentication on the endpoint itself. The verdict is a third-party judgement about a package version, so treat it as one input rather than a guarantee.
Installation
In SourceWeft
- Open Attestari in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"attestari": {
"type": "http",
"url": "https://mcp.attestari.ai/mcp"
}
}
}Tools
0Tool metadata has not been indexed yet.
Version history
1- v0.2.1LatestOct 7, 2026


