Attestari

ai.attestariv0.2.1Updated Oct 7, 2026

Attestari's verdict on an npm or PyPI package version, asked before an agent installs it.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Attestari returns a verdict on an npm or PyPI package version before an assistant installs it.

What it does
Attestari is a remote MCP server that gives an assistant a verdict on a specific npm or PyPI package version, asked before the agent installs it. It is reached over streamable HTTP at a hosted endpoint, and a PyPI package is also offered for running it locally over stdio. The manifest lists no individual tools.
When to use it
Use it when an assistant installs or upgrades third-party packages and you want a check on a given version first. It fits dependency-review or supply-chain steps in an agent workflow.
Requirements
A remote endpoint or the local PyPI package (Python runtime for stdio). An Attestari API key is required, supplied as the environment variable ATTESTARI_API_KEY, and the manifest states it is for Developer tier and above. Network access to the hosted endpoint.
Before you install
The server requires a secret API key (ATTESTARI_API_KEY), which should be stored and shared carefully. The manifest declares no authentication on the endpoint itself. The verdict is a third-party judgement about a package version, so treat it as one input rather than a guarantee.

Installation

In SourceWeft

  1. Open Attestari in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "attestari": {
      "type": "http",
      "url": "https://mcp.attestari.ai/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.2.1LatestOct 7, 2026