Skip to main content

Free Passports

A free identity for every MCP server, and for the organisation behind it.

The MCP Passport gives one logical MCP server one enduring, publicly resolvable ECZ-ID, linked to its operator's Parent record. It is one of seven free Passport families, and every one of them is free.

Passport identity is free. Capacity, monitoring, evidence, assurance and specialist services are separate.

Parent + seven families

The Parent, and the seven free Passport families

An MCP server rarely stands alone: agents call it, an API sits behind it, a plugin or a package distributes it, a workload runs it. Each is its own subject with its own free Passport, and every Passport links to the same Parent.

Included, free

What every free Passport includes

  • A persistent ECZ-ID for the server, agent, API or other subject.
  • Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.
  • A public Resolver record anyone can open, and the same record as machine-readable JSON.
  • A live website badge, a QR code and a share link.
  • Basic bindings to the public places the subject already appears.
  • Lifecycle and current public state, evaluated on demand.
  • Claim and recovery.
  • Basic participation in the Digital Entity Graph.
  • Essential lifecycle evidence, kept in LedgerCore.

Publishing the record is your decision. Nothing becomes public until you consent, and you can withdraw publication later.

How it works

From no ECZ-ID to a record anyone can re-check

  1. Create or claim the identity

    Start in TrustOps with one sign-in. Your organisation's free DECLARED Parent is reused or created, and the MCP server gets its ECZ-ID.

  2. Configure and bind

    Add the public places the server already appears — an MCP Registry listing, the repository it is built from, your documentation. Each binding records where it was learned.

  3. Prove it on the Resolver

    Anyone can open the public record and its JSON, with no account and no API key — and re-check it before relying on it.

  4. Operate

    Publish the ECZ-ID where hosts, agents and reviewers already look — the server's manifest, its README, its registry entry — and manage it from your ECZ-ID console.

  5. Strengthen, only if useful

    Parent verification, monitoring, evidence and specialist products are optional. None is needed to hold a Passport.

Operator · Server · Tool

Accountability a client can resolve, not assume.

MCP tells a client what a server can do. It does not tell the client who stands behind it. ECZ-ID publishes that chain as records anyone can open — the operator, the server, and the tools the server exposes.

  1. Which organisation is accountable?

    Operator

    The organisation that operates the server, published once as its Parent record — with the provenance of each field and the date it was checked.

    Resolved by: Parent record (ECZ-ID Business Passport)

    A named operator is not an approved operator. Parent verification verifies the organisation, never the server.

  2. Which MCP server is this, whatever its URL?

    Server

    One MCP Passport for one logical MCP server. Endpoints, versions, deployments and registry listings are bindings on that record, not new identities, so the identity does not move when the URL does.

    Resolved by: MCP Passport (free)

    A binding shows a declared relationship. It does not grant, prove or imply authority to act.

  3. Who answers for this tool?

    Tool

    Every tool a client finds through tools/list is exposed by a server. The tool resolves through that server's MCP Passport to the operator accountable for both — the chain a reviewer, a host or an agent can follow before a call is made.

    Resolved by: The exposing server's MCP Passport

    Resolving who answers for a tool says nothing about whether the tool is safe. Tool-surface risk is assessed by review, not by identity.

Current public proof

Proof that is current when you check it — and checkable by anyone.

  • Current, not cached

    The Resolver publishes the record's current state, with the time it was read. The badge is drawn from that state when it is requested, never from a copy on this site.

  • Independently re-checkable

    A human page and a machine JSON record for every ECZ-ID, with no account and no API key. A relying party never has to take this site's word — or the operator's — for it.

  • Honest about absence

    No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more.

Current proof comes from the Resolver. Verify current state before relying on it.

The binding chain

How an MCP server is bound to an accountable identity.

Six links, each one something a relying party can open or re-check. The chain runs from the organisation through the server to what it exposes — and it stops short of authorising anything.

  1. Organisation / operator

    Parent record — free DECLARED; VERIFIED and ASSURED optional

    The organisation accountable for the server. One Parent carries every Passport the organisation holds.

  2. MCP Passport

    A free child ECZ-ID under the Parent

    One MCP Passport for one logical MCP server. It links the server to its operator and does not move when the server's URL does.

  3. MCP server

    Bindings, and /.well-known/ecz-mcp.json on the host

    The places the server already appears — the host that serves the endpoint, its repository, its registry entry, its documentation — are recorded as bindings. On the host, the identifier is published at /.well-known/ecz-mcp.json.

  4. Tools and capabilities

    Exposed by the server, discovered through tools/list

    Tools resolve through the server that exposes them. A tool does not receive a separate Passport merely because it is a tool.

  5. Resolver

    The public record, for people and machines

    Anyone opens the current record on the public Resolver, with no account, and re-checks it before relying on it. The identifier is what resolves — not the file.

  6. Graph, Watch and evidence

    Graph Intelligence · Watch · LedgerCore

    Relationships to the agents that call the server and the APIs and packages around it; change signals when the record moves; lifecycle evidence kept with its time.

What the manifest file does, precisely

The ECZ-ID MCP Verifier recognises a URL ending in /.well-known/ecz-mcp.json and classifies the target as an MCP server. It does not fetch or parse the file, and a public Resolver lookup runs only for a valid ECZ-ID. Publish the identifier where a relying party will read it, and expect them to resolve the identifier rather than the file.

Identity is not runtime authorisation

Resolving who operates a server grants no permission to call it or any of its tools. OAuth, your identity provider, MCP authorization and your runtime mediation still decide every call; ECZ-ID replaces none of them.

The full provider journey, step by step

What a free Passport does not claim

The distinctions a Passport never blurs

DECLARED ≠ VERIFIED
A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check.
Identity ≠ Binding
The Passport identifies the MCP server. A binding records a public place it already appears. Adding a binding never creates a second identity.
Binding ≠ Authority
A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act.
Parent verification ≠ MCP verification
A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the MCP server or any tool it exposes.
OBSERVED ≠ ENFORCED
A state the layer has observed is a published fact about a record. Nothing is enforced unless the relying party's own policy, in its own runtime, enforces it.

No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more.

Free identity, separate paid layers

Passport identity is free. Capacity, monitoring, evidence, assurance and specialist services are separate.

Separately, each of the four paid MCP professional services includes a 90-day ECZ-ID Business Passport experience for the buyer's organisation. It is described, with its boundaries, alongside the deliverables.

Optional Parent tiers

Strengthen your Parent: VERIFIED or ASSURED

Your Parent starts DECLARED and free, with your first free Passport. VERIFIED and ASSURED are optional, paid tiers operated by TrustOps. Each is checked before the public record changes.