gocertius in namespace io.github
Local package path declaredCredentials listedRepository declared by sourceUpdated 2026-09-08
io.github.g-digital-by-Garrigues/gocertius · Registry status: active
No name of its own reaches this register for this entry. The heading therefore carries the trailing segment of the identifier; the identifier itself is listed below as a coordinate.
At a glance
MCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents.
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declaredMCP-Register · 2026-08-06
- Required secrets declared
- Credentials listedMCP-Register · 2026-09-09
- Declared version and change
2.0.0· Source-reported change date 2026-09-08MCP-Register · 2026-09-09- Repository as declared
- github.com/g-digital-by-Garrigues/GoCertius_MCPMCP-Register · 2026-08-06
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers with declared required secrets6,067
- Locally executed MCP servers17,056
- MCP servers with a repository URL30,107
- Local MCP servers with a repository URL16,152
- MCP servers over stdio only13,710
- MCP servers as an npm package only10,186
6 of 12 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- Credentials listed
- Registry record changed
- 2026-09-08
- Setup
- Template available
- Registry name
io.github.g-digital-by-Garrigues/gocertius- Package coordinate
npm:@g-digital/mcp-gocertius- Declared version
2.0.0- Source-reported listing date
- 2026-09-08
- Source-reported change date
- 2026-09-08
- First seen by tracevero
- 2026-08-06
- Vendor's website
- https://github.com/g-digital-by-Garrigues/GoCertius_MCP
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | Credentials listed yes Original data – Required secret variables (raw): MCP_AUTH_USER_KEY Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-09-09 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio Source: MCP-Register · collected on 2026-08-06 · derived |
| Path argument present | no Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/g-digital-by-Garrigues/GoCertius_MCP Source: MCP-Register · collected on 2026-08-06 · derived |
| Declared version | 2.0.0 Source: MCP-Register · collected on 2026-09-09 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | MCP server for GoCertius: certified evidence, dossiers, notifications and chats via AI agents. Source: MCP-Register · collected on 2026-08-26 · self-declared |
|---|---|
| Environment variables (raw) | MCP_ALLOW_INSECURE_FILE_URL, MCP_ALLOW_UNVERIFIED_BEARER, MCP_ALLOWED_HOSTS, MCP_ALLOWED_ORIGINS, MCP_API_BASE_URL, MCP_AUTH_USER_KEY, MCP_HTTP_HOST, MCP_HTTP_MAX_BODY_BYTES, MCP_HTTP_PUBLIC, MCP_SVC_CLIENT_ID, MCP_SVC_CLIENT_SECRET, MCP_SVC_INTROSPECT_URL, PORT Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Required secret variables (raw) | MCP_AUTH_USER_KEY Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Transports (raw) | stdio Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Repository (raw) | https://github.com/g-digital-by-Garrigues/GoCertius_MCP Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Package registries (raw) | npm Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-09-08 Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Last changed in the registry (raw) | 2026-09-08 Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | @g-digital/mcp-gocertius Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 2.0.0 Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Runtime hints (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | MCP_ALLOWED_HOSTS=Comma-separated allowed Host headers. Empty = Host validation disabled (default). When set, requests with a Host outside the list are rejected. · MCP_ALLOWED_ORIGINS=Comma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all. · MCP_ALLOW_INSECURE_FILE_URL=Set to "true" to allow plain http:// fileUrl downloads in evidence_create (default https-only). Private/internal addresses are rejected regardless (resolution-time check; see the documented DNS TOCTOU limitation in the hosted-deployment runbook). · MCP_ALLOW_UNVERIFIED_BEARER=Escape hatch for MCP_HTTP_PUBLIC=true WITHOUT inbound-token introspection: set to "true" ONLY when an upstream gateway already verifies Bearer tokens. The server logs a prominent warning and forwards tokens upstream unverified. · MCP_API_BASE_URL=Upstream API root. Required: your user key is exchanged for a session token against this host, and the server will not start without it. · MCP_AUTH_USER_KEY=Long-lived GoCertius user key, exchanged automatically for a short-lived session token. Use it for headless or automated access instead of an account password. (See https://www.gocertius.io for credential acquisition.) · MCP_HTTP_HOST=Interface the HTTP transport binds to. Default 127.0.0.1 (localhost only). Set 0.0.0.0 to expose on all interfaces (containers do this automatically). · MCP_HTTP_MAX_BODY_BYTES=Maximum accepted POST /mcp request-body size in bytes (default 16777216 = 16 MiB — sized so base64 file uploads within the documented tool limits fit). Oversized requests get a 413 JSON-RPC error before/while reading — closes a memory-exhaustion DoS vector in public deployments. Note: base64 file sources are capped by this limit BEFORE MCP_FILE_MAX_BYTES applies. · MCP_HTTP_PUBLIC=Set to "true" for public/multi-tenant deployments. Activates Host validation and refuses to start unless (1) MCP_ALLOWED_ORIGINS or MCP_ALLOWED_HOSTS is set AND (2) inbound Bearer introspection is configured (MCP_SVC_INTROSPECT_URL + MCP_SVC_CLIENT_ID/SECRET) or MCP_ALLOW_UNVERIFIED_BEARER=true is set explicitly (fail-closed). · MCP_SVC_CLIENT_ID=Client ID this server presents to the introspection endpoint above (its resource-server credentials). Only needed alongside MCP_SVC_INTROSPECT_URL; it does not authenticate you to GoCertius. · MCP_SVC_CLIENT_SECRET=Client secret this server presents to the introspection endpoint above (its resource-server credentials). Only needed alongside MCP_SVC_INTROSPECT_URL; it does not authenticate you to GoCertius. (See https://www.gocertius.io for credential acquisition.) · MCP_SVC_INTROSPECT_URL=RFC 7662 token introspection URL for inbound Bearer verification in HTTP mode. Opt-in, and required when MCP_HTTP_PUBLIC=true. Leave empty for stdio (local) use. · PORT=HTTP port when running in hosted (HTTP) mode; ignored in stdio mode Source: MCP-Register · collected on 2026-09-09 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"@g-digital/mcp-gocertius","version":"2.0.0","transport":"stdio","environment":[{"name":"MCP_ALLOW_INSECURE_FILE_URL","description":"Set to \"true\" to allow plain http:// fileUrl downloads in evidence_create (default https-only). Private/internal addresses are rejected regardless (resolution-time check; see the documented DNS TOCTOU limitation in the hosted-deployment runbook).","required":false,"secret":false},{"name":"MCP_ALLOW_UNVERIFIED_BEARER","description":"Escape hatch for MCP_HTTP_PUBLIC=true WITHOUT inbound-token introspection: set to \"true\" ONLY when an upstream gateway already verifies Bearer tokens. The server logs a prominent warning and forwards tokens upstream unverified.","required":false,"secret":false},{"name":"MCP_ALLOWED_HOSTS","description":"Comma-separated allowed Host headers. Empty = Host validation disabled (default). When set, requests with a Host outside the list are rejected.","required":false,"secret":false},{"name":"MCP_ALLOWED_ORIGINS","description":"Comma-separated allowed browser Origins (DNS-rebinding defense). Empty = reject any request carrying an Origin header; non-browser clients (CLI/SDK) send no Origin and are always allowed. Use '*' to allow all.","required":false,"secret":false},{"name":"MCP_API_BASE_URL","description":"Upstream API root. Required: your user key is exchanged for a session token against this host, and the server will not start without it.","required":true,"secret":false},{"name":"MCP_AUTH_USER_KEY","description":"Long-lived GoCertius user key, exchanged automatically for a short-lived session token. Use it for headless or automated access instead of an account password. (See https://www.gocertius.io for credential acquisition.)","required":true,"secret":true},{"name":"MCP_HTTP_HOST","description":"Interface the HTTP transport binds to. Default 127.0.0.1 (localhost only). Set 0.0.0.0 to expose on all interfaces (containers do this automatically).","required":false,"secret":false},{"name":"MCP_HTTP_MAX_BODY_BYTES","description":"Maximum accepted POST /mcp request-body size in bytes (default 16777216 = 16 MiB — sized so base64 file uploads within the documented tool limits fit). Oversized requests get a 413 JSON-RPC error before/while reading — closes a memory-exhaustion DoS vector in public deployments. Note: base64 file sources are capped by this limit BEFORE MCP_FILE_MAX_BYTES applies.","required":false,"secret":false},{"name":"MCP_HTTP_PUBLIC","description":"Set to \"true\" for public/multi-tenant deployments. Activates Host validation and refuses to start unless (1) MCP_ALLOWED_ORIGINS or MCP_ALLOWED_HOSTS is set AND (2) inbound Bearer introspection is configured (MCP_SVC_INTROSPECT_URL + MCP_SVC_CLIENT_ID/SECRET) or MCP_ALLOW_UNVERIFIED_BEARER=true is set explicitly (fail-closed).","required":false,"secret":false},{"name":"MCP_SVC_CLIENT_ID","description":"Client ID this server presents to the introspection endpoint above (its resource-server credentials). Only needed alongside MCP_SVC_INTROSPECT_URL; it does not authenticate you to GoCertius.","required":false,"secret":false},{"name":"MCP_SVC_CLIENT_SECRET","description":"Client secret this server presents to the introspection endpoint above (its resource-server credentials). Only needed alongside MCP_SVC_INTROSPECT_URL; it does not authenticate you to GoCertius. (See https://www.gocertius.io for credential acquisition.)","required":false,"secret":true},{"name":"MCP_SVC_INTROSPECT_URL","description":"RFC 7662 token introspection URL for inbound Bearer verification in HTTP mode. Opt-in, and required when MCP_HTTP_PUBLIC=true. Leave empty for stdio (local) use.","required":false,"secret":false},{"name":"PORT","description":"HTTP port when running in hosted (HTTP) mode; ignored in stdio mode","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} Source: MCP-Register · collected on 2026-09-09 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/io-github-g-digital-by-garrigues-gocertius)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-09 | Declared version: 1.5.1 → 2.0.0 |
|---|---|
| 2026-09-09 | Required secrets declared: no → yes |
| 2026-09-09 | Last changed in the registry (raw): 2026-07-22 → 2026-09-08 |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-g-digital-by-garrigues-gocertius