Akashi Notari

io.github.self-realityv1.1.0更新于 Oct 6, 2026

Proof of existence for files: anchor a SHA-256 hash on Base, look up proofs. Paid with x402.

已验证Streamable HTTP可网页运行Developer ToolsSecurity & MonitoringFinance

概览

AI 生成的概览

让助手在 Base 上为文件的 SHA-256 哈希付费锚定,并查询已有的存在性证明。

功能
通过 Streamable HTTP 提供两个 MCP 工具:find_proof 接受哈希或交易哈希,返回该哈希是否已锚定及其首个证明;anchor_hash 接受哈希和可选文件名,在链上写入证明(R12、R36、R37)。付费工具遵循 x402 MCP 传输:未付款时返回 PaymentRequired 对象,客户端签名后结果携带证明与结算信息(R39、R40)。同一服务也可通过普通 HTTP 端点进行锚定和证明查询(R6、R8、R10)。
适用场景
当你需要可验证、带时间戳地证明某个文件在某一时刻已存在,或想查询某个 SHA-256 哈希是否已在 Base 上锚定时使用。它适合能够通过 x402 自动支付小额 USDC 的助手。它不用于普通文件存储或内容获取,因为只记录哈希和可选文件名。
运行要求
远程 Streamable HTTP 端点 需要支持 x402 的客户端和可签名支付 USDC 的 Base 钱包(R26、R23);find_proof 免费。自行部署该 Worker 需要 Node.js 与 pnpm、Cloudflare Workers 环境、带 ETH 的中继钱包密钥、注册表合约地址,最好还有带密钥的 RPC 端点(R62、R68、R71、R74、R87、R89)。
安装前请注意
anchor_hash 会在 Base 上花费真实 USDC;价格从合约读取,官方 x402 客户端默认拒绝超过 1 美元的付款,除非用户提高上限(R58)。该服务持有中继钱包密钥 RELAYER_PRIVATE_KEY,需要 ETH 支付 gas,且并发请求共用同一密钥(R59、R60)。锚定会把哈希、可选文件名和付款地址永久写入公开链上(R25、R54)。已取消的授权不会买到任何东西,重复使用的授权会返回 409(R47、R57)。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Akashi Notari,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "akashi-notari": {
      "type": "http",
      "url": "https://anchor.akashi-notari.com/mcp"
    }
  }
}

README

Anchor Worker

Cloudflare Worker that sells anchors to agents over x402. An agent sends a SHA-256 file hash and a signed USDC payment in one HTTP request; the worker sends one transaction to VerifierRegistryUSDC, which takes the USDC and writes the proof. No facilitator is involved.

API Endpoints

  • POST /anchor → paid. Writes the hash on-chain, returns the transaction hash and a certificate link
  • GET /proof?hash=<sha256 hex> → free. Whether this hash is anchored, and its first proof
  • GET /proof?tx=<transaction hash> → free. The proof written by this transaction
  • POST /mcp → MCP server (Streamable HTTP) with the tools find_proof and anchor_hash
  • GET /openapi.json → OpenAPI description; directories such as x402scan read it before they register /anchor
  • GET /.well-known/x402 → x402 discovery document listing /anchor
  • GET /.well-known/agent-registration.json → ERC-8004 agent registration file
  • GET /llms.txt → the service described for language models
  • GET / → service description and current price
  • GET /health → { ok: true }

POST /anchor

Body: { "hash": "<sha256, 64 hex chars>", "filename": "<optional>" }. A 0x prefix and uppercase are accepted; the hash is stored lowercase without 0x, the same form the web app writes. The filename follows the web app's rules: lowercase a-z 0-9 - _ ., at most 128 characters.

Without a PAYMENT-SIGNATURE header the worker answers 402 with the terms in a PAYMENT-REQUIRED header (x402 v2, base64 JSON) and the same JSON in the body:

json
{  "x402Version": 2,  "accepts": [    {      "scheme": "exact",      "network": "eip155:8453",      "amount": "10000",      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",      "payTo": "<VerifierRegistryUSDC>",      "maxTimeoutSeconds": 120,      "extra": { "assetTransferMethod": "eip3009", "name": "USD Coin", "version": "2" }    }  ]}

The amount is read from price() on the contract, so the quote and the contract always agree. With a valid payment the response is 200 and carries a PAYMENT-RESPONSE header:

json
{  "ok": true,  "status": "confirmed",  "hash": "be44340d151cbfa7a5dc59b579dd6632fb0891b573f8fdc927264309a3b168f0",  "filename": "report.pdf",  "submitter": "<payer address>",  "timestamp": 1790919801,  "timestampIso": "2026-10-02T05:43:21.000Z",  "paid": "10000",  "currency": "USDC",  "chain": "base",  "txHash": "0x...",  "explorerUrl": "https://basescan.org/tx/0x...",  "certificateUrl": "https://akashi-notari.com/certificate/?chain=base&hash=0x..."}

Any x402 client works:

js
import { wrapFetchWithPaymentFromConfig } from '@x402/fetch';import { ExactEvmScheme } from '@x402/evm';
const pay = wrapFetchWithPaymentFromConfig(fetch, {  schemes: [{ network: 'eip155:8453', client: new ExactEvmScheme(account) }],});const res = await pay('https://<worker>/anchor', {  method: 'POST',  headers: { 'content-type': 'application/json' },  body: JSON.stringify({ hash, filename: 'report.pdf' }),});

GET /proof

VerifierRegistryUSDC stores the first anchor of each hash, so a lookup by hash is one contract read (firstAnchor) and a log query on the one block it names. No search over the chain and no explorer key is needed.

json
{  "hash": "be44340d…",  "anchored": true,  "proofs": [ { "hash": "…", "filename": "report.pdf", "submitter": "0x…", "timestamp": 1790919801, "txHash": "0x…", "contract": "0x…" } ],  "searched": ["<VerifierRegistryUSDC>", "<VerifierRegistry>"]}
  • proofs holds the first anchor of the hash on VerifierRegistryUSDC. Later anchors of the same hash exist as events and open with ?tx=
  • The ETH VerifierRegistry the web app writes to stores nothing, so its proofs need an explorer API. When that search fails, the contract moves from searched to unsearched and the rest of the answer still stands. anchored: false with an unsearched entry means "not found where we could look"

MCP

POST /mcp speaks MCP over Streamable HTTP, without sessions: every request stands alone, and GET returns 405.

  • find_proof { hash } or { tx }: free, the same answer as GET /proof
  • anchor_hash { hash, filename? }: paid, following the x402 MCP transport. Without a payment the result is a tool error whose structuredContent is the x402 PaymentRequired object. The client signs it and calls again with the payment in params._meta["x402/payment"]; the result then carries the proof, and the settlement in _meta["x402/payment-response"]

server.json in this folder describes the server for the MCP registry.

Status Codes

  • 400 bad hash, filename or payment header. Checked before the payment is touched; nothing is charged
  • 402 no payment, or the payment cannot be settled. The body's error is an x402 error code such as insufficient_funds
  • 409 payment_already_used: this authorization already bought an anchor. Look it up with /proof
  • 503 the worker has no contract address or relayer key

Notes

  • The transaction either moves the USDC and emits the proof, or reverts and moves nothing
  • The response has status: "confirmed" with the full proof once the transaction is mined. If no RPC endpoint reports it within 30 seconds the response is still 200, with status: "submitted", the txHash and a lookup URL. A payment that was broadcast is never reported as failed
  • The on-chain submitter is the payer, not the relayer
  • If an authorization was already executed on the token (by a facilitator, or by someone who front-ran the relayer), the worker confirms the transfer to the contract in the token's logs and anchors it with anchorPaid. It looks back 1,800 blocks
  • A canceled authorization buys nothing
  • The official x402 client refuses payments above $1 unless its user raises the limit; keep the price at or below $1 for agents to pay without configuration
  • Concurrent requests share one relayer key. A colliding nonce is retried three times; heavy traffic needs a queue
  • Public RPC nodes and the keyless Blockscout API refuse or rate-limit requests from Cloudflare's shared addresses. In production set RPC_URL to a keyed endpoint as a secret. LOGS_API_KEY is only needed to include the ETH contract's proofs in /proof?hash=
  • The recovery of an authorization executed on the token searches 1,800 blocks of token logs, which a free Alchemy key refuses (10 blocks). List a second endpoint in RPC_URL or use a paid key to keep that path working
  • Rate limited to RATE_LIMIT_PER_MIN requests per IP (default 60)

Environment Variables

  • RELAYER_PRIVATE_KEY: secret. The wallet that sends the transactions. It needs ETH for gas and setRelayer(address, true) on the contract
  • REGISTRY_ADDRESS: the deployed VerifierRegistryUSDC
  • CHAIN_ID: 8453 (Base, default) or 84532 (Base Sepolia). These two have built-in defaults for everything below
  • RPC_URL: one or more RPC endpoints, comma-separated, tried in order. The default for Base is a list of public nodes; set a keyed endpoint (Alchemy, Infura) as a secret for production traffic
  • RPC_ORIGIN: sent as the Origin header on RPC calls, for a provider key restricted to an origin allowlist
  • TOKEN_ADDRESS, TOKEN_NAME, TOKEN_VERSION, EXPLORER_URL: optional overrides. TOKEN_NAME and TOKEN_VERSION are the token's EIP-712 domain
  • LEGACY_REGISTRY_ADDRESS: the ETH VerifierRegistry, included in lookups
  • LOGS_API_URL, LOGS_API_KEY, LOGS_FROM_BLOCK: Blockscout-compatible logs API that searches the ETH contract for /proof?hash=, and an optional API key for it. Set LOGS_API_URL empty to use the RPC node
  • AGENT_REGISTRATIONS: JSON array for the registrations field of the agent registration file, e.g. [{"agentId":22,"agentRegistry":"eip155:8453:0x…"}], set once the agent is registered on an ERC-8004 identity registry
  • PUBLIC_URL: the worker's public origin, used in the resource.url it advertises
  • CERTIFICATE_URL, CERTIFICATE_CHAIN: where certificate links point
  • RATE_LIMIT_PER_MIN: default 60

Local Development

bash
cd workers/anchorpnpm installcp dev.vars.template .dev.varspnpm dev

Tests

The end-to-end script deploys a mock USDC and both registries to a local chain, then drives the worker by hand, through the official x402 client and over MCP.

bash
# terminal 1cd contracts/registry && npx hardhat compile && npx hardhat node
# terminal 2cd workers/anchor && pnpm test:e2e

Deployment

bash
# 1. Deploy the contract and allow the relayer (try baseSepolia first)cd contracts/registryRELAYER_ADDRESS=0x... pnpm hardhat run scripts/deploy-usdc.js --network base
# 2. Put the address from constants-usdc.json into wrangler.toml as REGISTRY_ADDRESS
# 3. Set the relayer key and deploycd ../../workers/anchornpx wrangler secret put RELAYER_PRIVATE_KEYnpx wrangler deploy
# 4. Send the relayer a little ETH on Base for gas
# 5. Rebuild and deploy the web app, so the certificate page reads the new contract

来源:workers/anchor/README.md,提交 24f490b

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.1.0最新Oct 6, 2026