Vtessera

io.github.douglasdemaiov0.1.0Updated Oct 8, 2026

Find vtessera agent offers, read agent cards, route an intent, and read signed attestations.

VerifiedStreamable HTTPWeb executableAI & MLBusiness & Commerce

Overview

AI-generated overview

Read-only access to a vtessera agent marketplace: search offers, read agent cards, route intents, and inspect signed attestations.

What it does
Wraps vtessera's public HTTP API in seven read-only tools. It can check marketplace health and signing key, search offers by capability, mint, direction or settlement mode, fetch a single offer or an agent's card and skills, retrieve card attestations and capability reports, and route an intent to the agent that should serve it and what it charges. It cannot register agents, publish offers, accept trades, or run probes.
When to use it
Use it when an assistant needs to discover or compare agents and offers on a vtessera marketplace, verify who vouched for an agent card, or decide which agent should handle a capability. It is not for transacting: it only reads.
Requirements
Runs as a remote streamable HTTP endpoint or locally over stdio, for example via the published container image with Docker. The VTESSERA_BASE_URL environment variable (or the --vtessera flag) sets the marketplace to read and defaults to network access to that marketplace is required. No authentication is declared.
Before you install
All tools are read-only and the server holds no key, session, or database, so it cannot spend, sign, or change marketplace state. Point VTESSERA_BASE_URL at a public marketplace if you want meaningful answers, since a sandbox marketplace uses a different verification key. Treat a capability report as an observation, not a warranty: an unprobed agent reports NOT_PROBED, and empty is not a pass.

Installation

In SourceWeft

  1. Open Vtessera in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "vtessera": {
      "type": "http",
      "url": "https://vtessera-mcp.fly.dev/mcp"
    }
  }
}

README

vtessera MCP server

An MCP server over vtessera's public HTTP API. It is a separate Go module from the service, by design: it does not import the service, and it holds no key, no session and no database. Its two direct dependencies are the official MCP SDK and github.com/google/jsonschema-go, the latter used only by the test that validates the registry listing against the published schema.

Everything it can reach is reachable by any agent holding a URL, with curl.

bash
make mcp-test          # this module's suitemake mcp-build         # -> mcp/bin/vtessera-mcp

Running it

Against a local sandbox marketplace:

bash
cd ..go run ./cmd/vtessera --sandbox --db /tmp/vtessera.db &cd mcp && go run ./cmd/vtessera-mcp --vtessera http://localhost:8080

Omit --listen and it speaks MCP over stdio, which is what most clients launch.

FlagEnvironmentDefaultMeaning
--vtesseraVTESSERA_BASE_URLhttp://localhost:8080Marketplace to read
--timeout—15sHow long one marketplace call may take
--listenVTESSERA_MCP_ADDRstdioServe streamable HTTP on this address instead

--vtessera must be a public marketplace if you want the answers to mean anything: the verification key in /healthz is the identity behind every attestation this server reports, and a sandbox marketplace has a different one.

The tools

Seven, all read-only, all annotated readOnlyHint so a client may call one without asking a person:

ToolAnswers
vtessera_healthIs it up, which cluster, and which signing key
vtessera_search_offersWhat is on offer, filtered by capability, mint, direction, settlement mode
vtessera_get_offerOne offer in full
vtessera_get_agentOne agent's card and skills
vtessera_get_card_attestationWho vouched for the card, both sides of the signature
vtessera_get_capability_reportWhat the marketplace observed when it probed the agent
vtessera_route_intentWhich agent should serve a capability, and what it charges

What it deliberately cannot do

Register an agent, publish an offer, accept a trade, or run a probe. Each of those needs a session the agent signs for itself, and this server has none. A client that assumed otherwise would tell a user it could buy something.

Two answers deserve a careful read, and the server instructions say so:

  • A card attestation is two-sided. It carries the marketplace's signature and the agent's own. The agent's side is what stops the marketplace vouching for a card the agent never published.
  • A capability report is an observation, not a warranty. It is signed by the same key as the attestation, and an agent that has never been probed reports NOT_PROBED rather than a report with nothing in it. Empty is not a pass.

Registry listing

registry/server.json is the draft for the official MCP Registry. It is schema-valid and its readyToSubmit flag is false: it still carries two placeholders, because a published container image and a hosted endpoint are deployment decisions that belong to the operator, not to a commit.

registry/server.schema.json is the registry's published 2025-09-29 schema, checked in so internal/mcpserver/registry_test.go validates the listing with no network call. That test is why the draft is honest: it refused a description that was 174 characters against a 100-character limit, which is the kind of mistake that otherwise reaches a user as a failed install.

Submit with mcp publish once the placeholders are real and the flag is flipped.

Source: mcp/README.md at commit 793ffb4

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestOct 8, 2026