Akashi Notari

io.github.self-realityv1.1.0更新於 Oct 6, 2026

Proof of existence for files: anchor a SHA-256 hash on Base, look up proofs. Paid with x402.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & MonitoringFinance

概覽

AI 產生的概覽

讓助理在 Base 上為檔案的 SHA-256 雜湊付費錨定,並查詢既有的存在證明。

功能
透過 Streamable HTTP 提供兩個 MCP 工具:find_proof 接受雜湊或交易雜湊,回傳該雜湊是否已錨定及其第一筆證明;anchor_hash 接受雜湊與可選檔名,在鏈上寫入證明(R12、R36、R37)。付費工具遵循 x402 MCP 傳輸:未付款時回傳 PaymentRequired 物件,用戶端簽署後結果會帶有證明與結算資訊(R39、R40)。同一服務也可透過一般 HTTP 端點進行錨定與證明查詢(R6、R8、R10)。
適用情境
當你需要可驗證、帶時間戳地證明某個檔案在某個時刻已存在,或想查詢某個 SHA-256 雜湊是否已在 Base 上錨定時使用。它適合能透過 x402 自動支付小額 USDC 的助理。它不用於一般檔案儲存或內容取得,因為只記錄雜湊與可選檔名。
執行需求
遠端 Streamable HTTP 端點 需要支援 x402 的用戶端,以及可簽署支付 USDC 的 Base 錢包(R26、R23);find_proof 免費。自行部署此 Worker 需要 Node.js 與 pnpm、Cloudflare Workers 環境、帶 ETH 的中繼錢包金鑰、註冊表合約位址,最好還有帶金鑰的 RPC 端點(R62、R68、R71、R74、R87、R89)。
安裝前請注意
anchor_hash 會在 Base 上花費真實 USDC;價格由合約讀取,官方 x402 用戶端預設會拒絕超過 1 美元的付款,除非使用者調高上限(R58)。此服務持有中繼錢包金鑰 RELAYER_PRIVATE_KEY,需要 ETH 支付 gas,且並行請求共用同一把金鑰(R59、R60)。錨定會把雜湊、可選檔名與付款位址永久寫入公開鏈上(R25、R54)。已取消的授權不會買到任何東西,重複使用的授權會回傳 409(R47、R57)。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Akashi Notari,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "akashi-notari": {
      "type": "http",
      "url": "https://anchor.akashi-notari.com/mcp"
    }
  }
}

README

Anchor Worker

Cloudflare Worker that sells anchors to agents over x402. An agent sends a SHA-256 file hash and a signed USDC payment in one HTTP request; the worker sends one transaction to VerifierRegistryUSDC, which takes the USDC and writes the proof. No facilitator is involved.

API Endpoints

  • POST /anchor → paid. Writes the hash on-chain, returns the transaction hash and a certificate link
  • GET /proof?hash=<sha256 hex> → free. Whether this hash is anchored, and its first proof
  • GET /proof?tx=<transaction hash> → free. The proof written by this transaction
  • POST /mcp → MCP server (Streamable HTTP) with the tools find_proof and anchor_hash
  • GET /openapi.json → OpenAPI description; directories such as x402scan read it before they register /anchor
  • GET /.well-known/x402 → x402 discovery document listing /anchor
  • GET /.well-known/agent-registration.json → ERC-8004 agent registration file
  • GET /llms.txt → the service described for language models
  • GET / → service description and current price
  • GET /health → { ok: true }

POST /anchor

Body: { "hash": "<sha256, 64 hex chars>", "filename": "<optional>" }. A 0x prefix and uppercase are accepted; the hash is stored lowercase without 0x, the same form the web app writes. The filename follows the web app's rules: lowercase a-z 0-9 - _ ., at most 128 characters.

Without a PAYMENT-SIGNATURE header the worker answers 402 with the terms in a PAYMENT-REQUIRED header (x402 v2, base64 JSON) and the same JSON in the body:

json
{  "x402Version": 2,  "accepts": [    {      "scheme": "exact",      "network": "eip155:8453",      "amount": "10000",      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",      "payTo": "<VerifierRegistryUSDC>",      "maxTimeoutSeconds": 120,      "extra": { "assetTransferMethod": "eip3009", "name": "USD Coin", "version": "2" }    }  ]}

The amount is read from price() on the contract, so the quote and the contract always agree. With a valid payment the response is 200 and carries a PAYMENT-RESPONSE header:

json
{  "ok": true,  "status": "confirmed",  "hash": "be44340d151cbfa7a5dc59b579dd6632fb0891b573f8fdc927264309a3b168f0",  "filename": "report.pdf",  "submitter": "<payer address>",  "timestamp": 1790919801,  "timestampIso": "2026-10-02T05:43:21.000Z",  "paid": "10000",  "currency": "USDC",  "chain": "base",  "txHash": "0x...",  "explorerUrl": "https://basescan.org/tx/0x...",  "certificateUrl": "https://akashi-notari.com/certificate/?chain=base&hash=0x..."}

Any x402 client works:

js
import { wrapFetchWithPaymentFromConfig } from '@x402/fetch';import { ExactEvmScheme } from '@x402/evm';
const pay = wrapFetchWithPaymentFromConfig(fetch, {  schemes: [{ network: 'eip155:8453', client: new ExactEvmScheme(account) }],});const res = await pay('https://<worker>/anchor', {  method: 'POST',  headers: { 'content-type': 'application/json' },  body: JSON.stringify({ hash, filename: 'report.pdf' }),});

GET /proof

VerifierRegistryUSDC stores the first anchor of each hash, so a lookup by hash is one contract read (firstAnchor) and a log query on the one block it names. No search over the chain and no explorer key is needed.

json
{  "hash": "be44340d…",  "anchored": true,  "proofs": [ { "hash": "…", "filename": "report.pdf", "submitter": "0x…", "timestamp": 1790919801, "txHash": "0x…", "contract": "0x…" } ],  "searched": ["<VerifierRegistryUSDC>", "<VerifierRegistry>"]}
  • proofs holds the first anchor of the hash on VerifierRegistryUSDC. Later anchors of the same hash exist as events and open with ?tx=
  • The ETH VerifierRegistry the web app writes to stores nothing, so its proofs need an explorer API. When that search fails, the contract moves from searched to unsearched and the rest of the answer still stands. anchored: false with an unsearched entry means "not found where we could look"

MCP

POST /mcp speaks MCP over Streamable HTTP, without sessions: every request stands alone, and GET returns 405.

  • find_proof { hash } or { tx }: free, the same answer as GET /proof
  • anchor_hash { hash, filename? }: paid, following the x402 MCP transport. Without a payment the result is a tool error whose structuredContent is the x402 PaymentRequired object. The client signs it and calls again with the payment in params._meta["x402/payment"]; the result then carries the proof, and the settlement in _meta["x402/payment-response"]

server.json in this folder describes the server for the MCP registry.

Status Codes

  • 400 bad hash, filename or payment header. Checked before the payment is touched; nothing is charged
  • 402 no payment, or the payment cannot be settled. The body's error is an x402 error code such as insufficient_funds
  • 409 payment_already_used: this authorization already bought an anchor. Look it up with /proof
  • 503 the worker has no contract address or relayer key

Notes

  • The transaction either moves the USDC and emits the proof, or reverts and moves nothing
  • The response has status: "confirmed" with the full proof once the transaction is mined. If no RPC endpoint reports it within 30 seconds the response is still 200, with status: "submitted", the txHash and a lookup URL. A payment that was broadcast is never reported as failed
  • The on-chain submitter is the payer, not the relayer
  • If an authorization was already executed on the token (by a facilitator, or by someone who front-ran the relayer), the worker confirms the transfer to the contract in the token's logs and anchors it with anchorPaid. It looks back 1,800 blocks
  • A canceled authorization buys nothing
  • The official x402 client refuses payments above $1 unless its user raises the limit; keep the price at or below $1 for agents to pay without configuration
  • Concurrent requests share one relayer key. A colliding nonce is retried three times; heavy traffic needs a queue
  • Public RPC nodes and the keyless Blockscout API refuse or rate-limit requests from Cloudflare's shared addresses. In production set RPC_URL to a keyed endpoint as a secret. LOGS_API_KEY is only needed to include the ETH contract's proofs in /proof?hash=
  • The recovery of an authorization executed on the token searches 1,800 blocks of token logs, which a free Alchemy key refuses (10 blocks). List a second endpoint in RPC_URL or use a paid key to keep that path working
  • Rate limited to RATE_LIMIT_PER_MIN requests per IP (default 60)

Environment Variables

  • RELAYER_PRIVATE_KEY: secret. The wallet that sends the transactions. It needs ETH for gas and setRelayer(address, true) on the contract
  • REGISTRY_ADDRESS: the deployed VerifierRegistryUSDC
  • CHAIN_ID: 8453 (Base, default) or 84532 (Base Sepolia). These two have built-in defaults for everything below
  • RPC_URL: one or more RPC endpoints, comma-separated, tried in order. The default for Base is a list of public nodes; set a keyed endpoint (Alchemy, Infura) as a secret for production traffic
  • RPC_ORIGIN: sent as the Origin header on RPC calls, for a provider key restricted to an origin allowlist
  • TOKEN_ADDRESS, TOKEN_NAME, TOKEN_VERSION, EXPLORER_URL: optional overrides. TOKEN_NAME and TOKEN_VERSION are the token's EIP-712 domain
  • LEGACY_REGISTRY_ADDRESS: the ETH VerifierRegistry, included in lookups
  • LOGS_API_URL, LOGS_API_KEY, LOGS_FROM_BLOCK: Blockscout-compatible logs API that searches the ETH contract for /proof?hash=, and an optional API key for it. Set LOGS_API_URL empty to use the RPC node
  • AGENT_REGISTRATIONS: JSON array for the registrations field of the agent registration file, e.g. [{"agentId":22,"agentRegistry":"eip155:8453:0x…"}], set once the agent is registered on an ERC-8004 identity registry
  • PUBLIC_URL: the worker's public origin, used in the resource.url it advertises
  • CERTIFICATE_URL, CERTIFICATE_CHAIN: where certificate links point
  • RATE_LIMIT_PER_MIN: default 60

Local Development

bash
cd workers/anchorpnpm installcp dev.vars.template .dev.varspnpm dev

Tests

The end-to-end script deploys a mock USDC and both registries to a local chain, then drives the worker by hand, through the official x402 client and over MCP.

bash
# terminal 1cd contracts/registry && npx hardhat compile && npx hardhat node
# terminal 2cd workers/anchor && pnpm test:e2e

Deployment

bash
# 1. Deploy the contract and allow the relayer (try baseSepolia first)cd contracts/registryRELAYER_ADDRESS=0x... pnpm hardhat run scripts/deploy-usdc.js --network base
# 2. Put the address from constants-usdc.json into wrangler.toml as REGISTRY_ADDRESS
# 3. Set the relayer key and deploycd ../../workers/anchornpx wrangler secret put RELAYER_PRIVATE_KEYnpx wrangler deploy
# 4. Send the relayer a little ETH on Base for gas
# 5. Rebuild and deploy the web app, so the certificate page reads the new contract

來源:workers/anchor/README.md,提交 24f490b

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.1.0最新Oct 6, 2026