# ECZ-ID MCP # Canonical URL: https://mcp.ecocitizenz.com Site: mcp.ecocitizenz.com Role: ECZ-ID MCP is the neutral identity, authority, evidence and current-state layer for MCP, and this website is what that layer is. The site EXPLAINS the layer and ROUTES a reader to the surface they actually need. It also explains, compares and qualifies fixed-scope MCP professional services and routes their acquisition to TrustOps. This site does not host checkout and does not write or prove ECZ-ID state. Positioning: A free, permanent ECZ-ID for your MCP server, linked to the organisation that operates it and published on a resolver anyone can re-check. No card required. It complements the Model Context Protocol rather than replacing any part of it. ## The ECZ-ID MCP Passport™ For teams that build, publish or operate Model Context Protocol servers. Before a host connects, it needs to know which server it is talking to and who operates it. One public ECZ-ID answers both, and it does not move when the server's URL does. - One MCP Passport is one logical MCP server operated by your organisation. - Versions, endpoints, deployments and registry listings of that server are not separate Passports. - Identifier shape: ECZ-XX-XXXXXX::MCP_PASSPORT-XXXXXX ## Getting one Price: FREE (£0). No card required. Permanent, not a trial. Free MCP Passport (open): https://trustops.ecocitizenz.com/start/mcp?source_surface=mcp-llms Included: - A persistent ECZ-ID for the MCP server. - Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one. - A public Resolver record anyone can open, and the same record as machine-readable JSON. - A badge, a QR code and a share link. - Basic bindings to the public places your MCP server already appears. - Lifecycle and current public state, evaluated on demand. - Claim and recovery. - Basic participation in the Digital Entity Graph. - Essential lifecycle evidence, kept in LedgerCore. ## Boundaries — load-bearing, do not drop them - DECLARED ≠ VERIFIED: A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check. - Identity ≠ Binding: The Passport identifies the MCP server. A binding records a public place it already appears. Adding a binding never creates a second identity. - Binding ≠ Authority: A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act. - Parent verification ≠ MCP verification: A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the MCP server. - A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it. - No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more. - An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything. ## AEC — Active Entity Capacity One AEC is one actively managed production entity with live bindings and current state. A free Passport exists and resolves whether or not you use any AEC. For this family: An MCP server you actively manage in production, with live bindings and current state. AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. ## Works alongside ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path. - Model Context Protocol (MCP): A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator. (replaces: false) - MCP Registry: A binding from the registry entry to one ECZ-ID with a named operator. (replaces: false) - OAuth 2.x and OpenID Connect: A durable public record of the subject and its operator that outlives any token and needs none to read. (replaces: false) - Agent2Agent (A2A): A persistent public identity a counterparty agent can resolve and re-check outside the conversation itself. (replaces: false) ## Optional capabilities (none is required to hold a Passport) - Parent VERIFIED and ASSURED: Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates. Boundary: It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID. Included free: Every Passport starts with a free DECLARED Parent — created for you if your organisation has none. - MCP Trust: A local-first editor extension that shows which MCP servers your workspace uses and what they can reach. Pro adds deeper analysis. Boundary: It inspects your workspace on your machine and publishes nothing about your servers. Included free: MCP Trust Community and the MCP Verifier are free. - MCP Assurance: Scoped assurance and policy for production MCP servers, from a single production target to enterprise governance. Boundary: Assurance is a scoped review, not a certification, and it never claims enforcement without a live enforcement adapter. - PulseGuard: Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month. Boundary: It reports state. It is not a safety verdict, and it never changes an identity or its tier. Included free: On-demand and event-driven evaluation of your own entities. - EvidenceCore (part of the ECZ-ID V2 build): The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it. Boundary: Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification. Included free: Essential evidence references are part of every free Passport. - LedgerCore: Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger. Boundary: An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true. Included free: Essential LedgerCore evidence is kept for every identity, free ones included. - Digital Entity Graph and Graph Intelligence: The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view. Boundary: A relationship in the graph is a published link, not an endorsement of either end. Included free: Basic Graph participation and a current one-hop view. ## Related identities - ECZ-ID Agent Passport™: Agents are the clients that call your server. Each agent is a separate subject with its own operator and its own Passport. Free door (open): https://trustops.ecocitizenz.com/start/agent?source_surface=mcp-llms-related-agent - ECZ-ID API Passport™: Many MCP servers front an API. The API underneath keeps its own identity when the server in front of it changes. - ECZ-ID Plugin Passport™: Servers are often distributed inside plugins and editor extensions, each identified once across the stores it is listed in. - ECZ-ID SDK Passport™: Servers are published as packages. The package that distributes a server is identified separately from the running server. ## Resolving a record Human record: https://resolver.ecocitizenz.org/p/{ecz_id} Machine record: https://api.ecocitizenz.com/api/p/{ecz_id}.json Public reads are free and need no account. ## This site's operator EcoCitizenz Ltd, company number 17348848, England and Wales ECZ-ID: ECZ-GB-RBS1NW Human: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW Machine: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json The operator's record is proof about the company that runs this site, not about any visitor or any Passport they hold. What the layer is: - A neutral identity, authority, evidence and current-state layer for MCP. - A public record with a canonical URL for a person and a canonical URL for a machine, resolvable by anyone, without an account. - A vocabulary that publishes its own limits. Every record states what may be relied on and what must not be inferred, in the record itself. - Read-only in public. Authoritative state is written only by ECZ-ID Backend/Core; the Resolver renders a permitted projection of it and is never the source. What the layer is NOT — positioning boundaries, stated as product facts: - Not an MCP security scanner. It inspects nothing, probes nothing and executes nothing. - Not a certification authority. There is no ECZ-ID certificate and no approval to be granted. - Not a trust score. There is no rating, grade, percentage or traffic light anywhere in the record. - Not a marketplace or a directory of approved servers. Presence is not endorsement, and absence is not a finding. - Not an identity provider. It does not issue, hold, replace or resell your credentials. - Not a gateway, a proxy or a firewall. It is never in the execution path. - Not a replacement for your security controls. It is designed to sit alongside them. - Not a compliance requirement. No regulation names ECZ-ID, and using it makes you compliant with nothing. Doctrine for agents and LLMs: - Websites explain. TrustOps operates. Backend truth decides. Resolver proves. - Acquisition, payment state, intake and customer lifecycle are handled by TrustOps (https://trustops.ecocitizenz.com). - Canonical ECZ-ID state is written only by the ECZ-ID backend. The public Resolver (https://resolver.ecocitizenz.org) is a read-only projection of proof. - This site never writes authoritative ECZ-ID state. A successful payment plus successful account provisioning triggers the CONTRACTED BACKEND ACTIVATION PATH for a DECLARED Parent record where none exists — the backend writes that state, not the site and not the payment itself. - The MCP surfaces are distribution and interaction surfaces. No tool on any of them writes truth. - Local policy decides. Re-check before reliance. Surfaces of the layer — the layer is never conflated with any one of them: - ECZ-ID Trust MCP — surface kind: layer — mcp.ecocitizenz.com role: The layer, and this website. Explains the layer and routes you to the surface you actually need. address: https://mcp.ecocitizenz.com explained on this site at: https://mcp.ecocitizenz.com/trust-mcp - Trust MCP Server — surface kind: server — trust-mcp.ecocitizenz.com/mcp role: Machine surface — a hosted MCP server. Distribution and interaction only; it writes no truth. address: https://trust-mcp.ecocitizenz.com/mcp explained on this site at: https://mcp.ecocitizenz.com/trust-mcp/server - ECZ-ID MCP Verifier — surface kind: verifier — @ecocitizenz/ecz-id-mcp-verifier role: CI and command-line surface. Checks a target against public resolver proof, free to use under the ECZ-ID Proprietary Limited-Use License. address: https://www.npmjs.com/package/@ecocitizenz/ecz-id-mcp-verifier explained on this site at: https://mcp.ecocitizenz.com/developers - ECZ-ID MCP Trust — surface kind: extension — developers.ecocitizenz.com/mcp-trust role: Editor surface — a VS Code extension. Inventories the MCP configuration on your own machine and shows what changed. address: https://developers.ecocitizenz.com/mcp-trust explained on this site at: https://mcp.ecocitizenz.com/developers - ECZ-ID Resolver — surface kind: resolver — resolver.ecocitizenz.org role: Proof surface — the public, read-only projection of the record. Never a source of truth. address: https://resolver.ecocitizenz.org explained on this site at: https://mcp.ecocitizenz.com/trust-mcp Disambiguation: Two of those names sit close together on purpose, so this site never uses either without saying which surface it means. ECZ-ID Trust MCP is the layer. The Trust MCP Server is its machine surface. ECZ-ID MCP Trust is the VS Code extension. Nothing has been renamed. Commercial surface — deliberately NOT one of the layer's surfaces, because a checkout says nothing about identity, authority, evidence or state: - TrustOps — surface kind: commercial — trustops.ecocitizenz.com role: Commercial surface — entitlement and order state. Authoritative for order and payment status; it publishes no proof. address: https://trustops.ecocitizenz.com Trust MCP Server — the machine surface of the layer: - Endpoint: https://trust-mcp.ecocitizenz.com/mcp - Transport: Streamable HTTP, carrying JSON-RPC 2.0. - Protocol revisions: The Trust MCP Server accepts protocol 2026-07-28 and negotiates the session version with the client; a client that offers 2025-11-25 is served on 2025-11-25. - Contract: The ECZ-ID Trust MCP Contract, frozen at milestone MS-032 on 19 August 2026. Frozen means the tool set, the argument schemas and the claims wording do not move without a new contract. - Provider neutrality: The contract is provider-neutral. It names no cloud, no marketplace and no authorisation vendor as a requirement, and a different deployment may substitute its own authorisation server while serving the same contract. - Tools: 7 published — 6 anonymous and read-only, 1 OAuth2-protected. None of them writes truth. - Authorisation: OAuth2 bearer token in the Authorization header, scope RequestToResolve.Create, with RFC 9728 Protected Resource Metadata. The authorisation server is a deployment profile, not part of the contract. - Platform authentication is not ECZ-ID verification. A token proves that a caller was authorised by an authorisation server to make a request. It says nothing about identity, authority, control or reliance, and the server's own challenge message states as much. An authorisation failure is never an ECZ-ID judgement about anybody, and a successful call is never an endorsement of anything. - create_request_to_resolve is the only tool that changes anything, and what it changes is not canonical. It opens a neutral Request-to-Resolve record, which is not authoritative ECZ-ID state. Canonical state is written in ECZ-ID Core and nowhere else; the Resolver publishes a read-only projection of it; this server reads that projection. No tool on this surface writes truth. - resolve_identity — access: anonymous — read-only: yes — answers: Who is this ECZ-ID, what state is it in, where is the proof - get_current_state — access: anonymous — read-only: yes — answers: The narrow current state, nothing else - get_resolver_link — access: anonymous — read-only: yes — answers: The deterministic proof URL. Makes no network call - explain_status — access: anonymous — read-only: yes — answers: What a status means, rendered deterministically. No LLM - find_product — access: anonymous — read-only: yes — answers: The single best next ECZ-ID action for a described situation - get_install_instructions — access: anonymous — read-only: yes — answers: Official install and discovery routes for an ECZ-ID surface - create_request_to_resolve — access: OAuth2 bearer — read-only: no — answers: Creates a neutral request for evidence. Scope RequestToResolve.Create Live proof — a dated transcript of a real public record, never a live feed: - ECZ-ID: ECZ-GB-RBS1NW - Record type: ECZ_ID_PARENT - Captured at: 2026-08-23T02:07:25Z - Human record: https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW - Machine record: https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json - This is a transcript, captured at the time shown. A transcript can become stale. It is not proof. Always verify live. - ECZ-ID identifier format: ^ECZ(-[A-Z0-9]{2,32}){1,4}$ - machine_policy.machines_should_use: state.lifecycle_state, state.reliance_level, binding.state, evidence.public_receipt_state, ledger.public_receipt_state, agent_trust.status - machine_policy.fail_closed_states: REVOKED, SUSPENDED, DEGRADED, MISMATCH, PROOF_UNAVAILABLE, PUBLIC_PROJECTION_UNAVAILABLE, ACTIVE_ABUSE_FLAGGED, UNKNOWN - Those two lists are a recommendation each record makes about itself, not an instruction ECZ-ID enforces. What your system does with a fail-closed state is your policy, made by you, in your own code. What a purchase does: - purchaseBegins: intake_scope_capacity_validation - Purchase does NOT guarantee immediate commencement and does NOT reserve a start date. - Your delivery schedule is confirmed during intake. Commercial boundary (Website Factory V2): - This site publishes NO paid price, allowance, SKU, cadence or purchase state. The canonical commercial master (2026-09-14) puts every one of those in one registry that TrustOps implements, and sets website price propagation to AFTER REGISTRY IMPLEMENTATION. - No page renders a checkout, a payment page or an order review. Every commercial action on this property is a conversation that ends in a written scope, after which TrustOps opens the order. - The ONE amount published anywhere on this site is the £0 of the free MCP Passport. Services (fixed scope, published prices; these four are NOT subscriptions): - https://mcp.ecocitizenz.com/services/readiness-audit — MCP Readiness Audit commitment: One fixed fee, agreed in writing before the audit begins. acquisition: qualification — scope fixed in writing before anything is agreed; TrustOps owns the price, the order and the payment parent record: a free, permanent ECZ-ID Business Passport, created automatically during setup if the organisation does not already hold one, plus 90 days of VERIFIED tier access that does not renew; later field-level evidence is separate, assessed afterwards, never promised - https://mcp.ecocitizenz.com/services/migration-sprint — Stateless Migration Sprint commitment: Two milestones — one on reservation, the balance on acceptance against the agreed criteria. acquisition: qualification — scope fixed in writing before anything is agreed; TrustOps owns the price, the order and the payment parent record: a free, permanent ECZ-ID Business Passport, created automatically during setup if the organisation does not already hold one, plus 90 days of VERIFIED tier access that does not renew; later field-level evidence is separate, assessed afterwards, never promised - https://mcp.ecocitizenz.com/services/ema-id-jag — EMA/ID-JAG Design & Pilot commitment: An initial milestone to start the design, then a written scope after design review. No further milestone is due before that written confirmation. acquisition: qualification — scope fixed in writing before anything is agreed; TrustOps owns the price, the order and the payment parent record: a free, permanent ECZ-ID Business Passport, created automatically during setup if the organisation does not already hold one, plus 90 days of VERIFIED tier access that does not renew; later field-level evidence is separate, assessed afterwards, never promised - https://mcp.ecocitizenz.com/services/enterprise-pilot — Enterprise MCP Pilot commitment: Three milestones — reservation, the implementation milestone defined in the written scope, and acceptance. acquisition: qualification — scope fixed in writing before anything is agreed; TrustOps owns the price, the order and the payment parent record: a free, permanent ECZ-ID Business Passport, created automatically during setup if the organisation does not already hold one, plus 90 days of VERIFIED tier access that does not renew; later field-level evidence is separate, assessed afterwards, never promised FREE MCP PASSPORT — the acquisition floor of this property, and free: - Subject: One MCP Passport is one logical MCP server operated by your organisation. - Versions, regions, replicas and environments of that server are not separate Passports. They are deployments of one server, and they draw on your managed-endpoint allowance rather than on a second identity. - Price: £0. No card required. Permanent: it does not expire, and it does not change if the holder buys, lapses or cancels anything. - Identity is free. A Passport is never metered, issuing one consults no entitlement, and there is no card, no trial clock and no expiry on it. - Canonical record type: MCP_PASSPORT, one of the seven FREE child identity families. - Acquisition door: https://trustops.ecocitizenz.com/start/mcp?source_surface=mcp-not-found — one sign-in, no payment, and no verification required to obtain one. - Reciprocal door for the adjacent Agent family: https://trustops.ecocitizenz.com/start/agent?source_surface=mcp-home-reciprocal. Adjacent Passports are suggested, never issued for you. If the thing you operate is also an agent, an API, an SDK or a workload, you choose whether to give those an identity too. - No allowance number is published. The Passport exists and resolves whether or not the holder uses any AEC. The number of tools your server exposes never consumes capacity, ephemeral replicas never consume any, and public verification of your record never consumes any. - Included artefacts: a public Resolver page, a machine-readable record on a stable schema, current public state with the time it was read, a badge, a QR code and the Publish Kit. - A DECLARED Parent is a truthful self-declaration by the organisation. It is free, and one is created for you during the same flow if you do not already have one. - DECLARED does not mean independently verified. It records what an organisation says about itself, with the date it said it — not the outcome of a check. - A VERIFIED or ASSURED Parent does not verify the MCP server. The parent organisation's identity is verified. The endpoint is not. - An MCP Passport is not ECZ-ID MCP Assurance. The Passport is identity: who this server is, who operates it, and what is published about it. Assurance is separate, ongoing work performed on evidence, with its own scope and its own price. - Holding a Passport inspects nothing. It does not probe your endpoint, read your configuration or execute anything, and it reports no finding about the server it names. - No public ECZ-ID Passport found is not a safety finding. It means the identifier resolves to no published record — nothing more. Most MCP servers have no ECZ-ID yet. AEC — Active Entity Capacity — the superseding capacity model, and NO prices here: - One AEC is one actively managed production entity with live bindings and current state. - A free Passport exists and resolves whether or not you use any AEC. - AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities. - Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC. - AEC never makes an identity more verified. - AEC never replaces a Passport. - AEC never changes an ECZ-ID. Your ECZ-ID does not change. - Running out of AEC never deletes, revokes or unpublishes an identity. - The number of tools inside a server never consumes capacity. - Ephemeral replicas never consume capacity. - Someone verifying your public record never consumes capacity. - Public Resolver reads and public machine-readable records are never metered, never authenticated and never counted against any allowance. - The per-family endpoint ladder this property published until 17 September 2026 (FREE 5 / STARTER 25 / GROWTH 100 / SCALE 500, with list prices) is SUPERSEDED by AEC and must not be treated as current. /capacity is a permanent redirect to /aec. - Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. The parent organisation record — ECZ-ID Business Passport: - A machine-readable business profile for the emerging agent and machine economy. - FREE AND PERMANENT at DECLARED. The ECZ-ID has no duration, no trial clock and no expiry, and holding one has never required a purchase. It is not a coupon. - A paid MCP professional service ADDITIONALLY includes 90 days of VERIFIED Parent access — the paid tier above Declared. That period starts at successful provisioning and activation, does not renew, and carries no automatic charge at day 91. At the end of it the organisation returns to the free, permanent Declared tier and the ECZ-ID does not change. The duration bounds the TIER, never the identity. - Acquisition is FRICTIONLESS — nothing to apply for and no gate of any kind: no KYC, no KYB, no eligibility assessment, no qualification, no identity verification, no assurance and no operator approval. - Where an organisation does not already hold one, a paid engagement's account setup CREATES AND ACTIVATES a DECLARED Parent record automatically. The purchase is not the route to the record; it is one occasion on which the record is created. - Payment does not create Declared, Verified, Assured or BOUND status, does not verify, certify, assure or approve the customer or its MCP implementation, and does not certify or complete the engagement. - The holder may afterwards add profile details and field-level declared, verified, bound or referenced evidence. Those later evidence states are SEPARATE from acquiring the Parent entitlement. - The holder controls optional profile data and bindings through TrustOps. - Backend/Core writes authoritative state; the Resolver renders a read-only permitted projection of it. - Verified, self-declared, bound and referenced information remain distinguishable on the Resolver page. - The public Resolver page is an ADJUNCT to the confidential Production Evidence Pack, never a replacement for it. - Completeness and usefulness depend on the information and bindings the holder maintains. It does not claim to contain everything, does not prove compliance, and does not make its holder the correct choice. Microsoft MCP server certification readiness (included in the MCP Readiness Audit where the agreed scope and available evidence make it relevant): - Microsoft OPERATES an MCP server certification process for its own supported discovery and runtime surfaces. - EcoCitizenz is INDEPENDENT. It is not Microsoft, does not act for Microsoft, is not a Microsoft certification authority, and is not Microsoft-approved or Microsoft-endorsed. - EcoCitizenz does not issue Microsoft certification and does not decide, approve or publish any Microsoft outcome. MICROSOFT ALONE decides its certification, review, approval and publication outcomes. - What is offered is independent readiness assessment, evidence mapping and remediation guidance — an independent readiness matrix covering: Publisher readiness; Package and metadata readiness; Authentication readiness; Functional and documentation consistency; Security and access posture; Telemetry and traceability; Responsible-AI exposure; Ongoing-maintenance exposure. - A readiness assessment is NOT certification, NOT approval, NOT a compliance attestation, NOT a security guarantee and NOT proof that certification will be obtained. Microsoft acceptance is never guaranteed. - Unknown or unavailable evidence is recorded as an EVIDENCE GAP or as OWNER CONFIRMATION REQUIRED. It is never silently converted into a failure. - Primary sources (retrieved 2026-07-25): https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-certification ; https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-server-certification Protocol revision — MCP 2026-07-28: - MCP 2026-07-28 is a published stable specification release. It introduces a stateless protocol core, per-request version and capability metadata, server/discover, subscriptions/listen, Multi Round-Trip Requests, versioned extensions, authorization changes, caching metadata and formal feature deprecation. Ecosystem adoption varies, and clients and servers may continue to support and negotiate earlier protocol versions. - Publication is not a mandatory certification requirement, not a shutdown deadline, and not evidence that existing MCP servers stop working. Earlier protocol revisions, including 2025-11-25, remain in real use. - Readiness findings are reported against the protocol revision an implementation actually targets; migration exposure to 2026-07-28 is mapped as its own clearly labelled view: Stateless-core assumptions; Removed handshake; Removed protocol-level sessions; Routing and version metadata; Extensions; Tasks; MCP Apps; Authorization hardening. - Primary sources (retrieved 2026-07-28): https://github.com/modelcontextprotocol/modelcontextprotocol/releases/tag/2026-07-28 ; https://modelcontextprotocol.io/specification/2026-07-28/changelog - The Audit's economics are unchanged by this: one fixed fee, no later milestone, one MCP implementation, no customer-code modification. Ongoing ECZ-ID MCP packages (separate continuation products, operated by TrustOps; acquired at https://trustops.ecocitizenz.com/start): - ECZ-ID MCP Verifier™ — FREE. Resolve a Passport, inspect what a page actually asserts, and see the basis of each field. Best for: Anyone checking a provider before they rely on it. - ECZ-ID MCP Assurance™ — priced by TrustOps. Operated work on the evidence you publish: keeping declarations, bindings and references accurate as your MCP surfaces change, with the lifecycle operations that hold them true. Best for: Providers whose customers re-check them, and who would rather not maintain that evidence themselves. - ECZ-ID MCP Assurance Plus™ — priced by TrustOps. The same operated evidence work across more MCP surfaces and targets, within the entitlements the canonical product defines. Best for: Providers operating several surfaces or targets who want one team maintaining the evidence for all of them. - ECZ-ID MCP Policy™ — priced by TrustOps. Publish machine-readable buyer-side acceptance policy for MCP surfaces — what your organisation will and will not accept from what it consumes, stated under your own authority. Best for: Buying organisations consuming third-party MCP surfaces. These packages are a continuation route after delivery. They are not part of the fixed-price professional services above, and buying an engagement never enrols a customer in one. Package boundary: These packages are operated work on EVIDENCE, and they are a different axis from identity: your ECZ-ID and your Resolver record are free and permanent, and stay so whether or not you ever buy one of these. Nothing here is an endpoint allowance either — that is AEC, which is a third axis again. These packages keep a published projection current and re-checkable. These packages are not certification, not compliance approval and not a security guarantee; the Verifier does not certify the party being checked, and MCP Policy is buyer-side policy that does not replace an identity provider, a gateway or a firewall. The engagements above are fixed-scope with a written scope and defined milestones — they are not subscriptions, never convert into one, and agreeing an engagement never enrols you in one. Primary routes: - https://mcp.ecocitizenz.com/ — overview: the layer, its named surfaces, a real resolvable record, and the three routes in - https://mcp.ecocitizenz.com/free-mcp-passport — the FREE MCP Passport — a permanent, unmetered ECZ-ID for one logical MCP server, with an operator relationship, a public Resolver record, machine-readable current state, a badge, a QR code and the Publish Kit. No card, no trial clock, no expiry. It publishes identity and asserts nothing about the server's safety, assurance or approval - https://mcp.ecocitizenz.com/aec — AEC — ECZ-ID Active Entity Capacity. One pool across an organisation's whole estate, measured in actively managed production entities. The Passport exists and resolves without it, AEC never makes an identity more verified, and no price or allowance is published here — TrustOps owns those. /capacity redirects here permanently - https://mcp.ecocitizenz.com/trust-mcp — what the layer is, what it records, and the things it is deliberately not - https://mcp.ecocitizenz.com/trust-mcp/server — the Trust MCP Server — endpoint, transport, protocol revisions, the published tool set and the one protected tool - https://mcp.ecocitizenz.com/developers — developer entry point — the ECZ-ID MCP Verifier, the GitHub Action, the ECZ-ID MCP Trust extension, the MCP Config Check, and how to verify - https://mcp.ecocitizenz.com/providers — for MCP server operators — publishing an ECZ-ID, and what a record does and does not say. Not a directory, not a listing and not a ranking - https://mcp.ecocitizenz.com/providers/faq — provider questions, answered in full - https://mcp.ecocitizenz.com/enterprise — governance — fail-closed states, procurement evidence, and the boundary with your own security controls - https://mcp.ecocitizenz.com/scanner — MCP Config Check — paste an MCP client configuration and read findings in your own browser. Nothing is uploaded, nothing is inspected, probed or executed, and it reports findings rather than a score, a grade or a verdict about anyone else - https://mcp.ecocitizenz.com/products — every product an MCP Passport holder can add, grouped by what it does — assurance bundles, policy, capacity, monitoring, evidence, Parent tiers and fixed-scope engagements. Each card carries the purchase state TrustOps published: a free start, a real purchase, or a named reason it cannot be bought yet - https://mcp.ecocitizenz.com/pricing — what everything costs in GBP with no VAT charged, read from the TrustOps commercial registry, and the four rules that make the numbers mean what they say. The MCP Passport itself is free and permanent. A published price is never an offer to sell: only offers TrustOps marks purchasable carry a purchase control - https://mcp.ecocitizenz.com/passport-everywhere — where an ECZ-ID travels: the share page and machine record we serve, the badge and QR, and the places you publish it yourself — each marked as something we serve or a pattern you implement, with an empty PLANNED column rather than an invented roadmap - https://mcp.ecocitizenz.com/identity-over-time — what was true when you checked, what changed, and whether it is still the same logical entity. Passport identifies, Graph relates, PulseGuard revalidates, LedgerCore preserves — and a free Passport includes no ongoing monitor - https://mcp.ecocitizenz.com/after-your-passport — the journey after issuance: publish the proof, bind native identities, inspect relationships, identify genuinely separate adjacent subjects, and open the console - https://mcp.ecocitizenz.com/services — service comparison and acquisition - https://mcp.ecocitizenz.com/resources — briefings and reference material, free to download - https://mcp.ecocitizenz.com/resources/rufroot-stateless-mcp — RufRoot & Stateless MCP Security Briefing: evidence-led PDF on CVE-2026-59726, the stateless MCP 2026-07-28 request model and per-request authorisation controls (free download; the briefing is a resource, not a certification or a guarantee) - https://mcp.ecocitizenz.com/resources/eu-ai-act-article-50 — EU AI Act Article 50: AI Agent Transparency & Evidence Briefing: primary-source-referenced PDF on the transparency obligations applicable from 2 August 2026, the provider and deployer split, the machine-to-machine distinction and re-checkable accountability evidence (free download; educational resource, not legal advice, not a certification and not a compliance determination) - https://mcp.ecocitizenz.com/method — delivery method - https://mcp.ecocitizenz.com/deliverables — Production Evidence Pack, and the parent record an engagement is delivered against - https://mcp.ecocitizenz.com/deliverables/sample-finding — synthetic sample finding - https://mcp.ecocitizenz.com/security — security and access model - https://mcp.ecocitizenz.com/faq — frequently asked questions - https://mcp.ecocitizenz.com/contact — short contact and service selection - https://mcp.ecocitizenz.com/contact/enterprise — enterprise qualification - https://mcp.ecocitizenz.com/privacy — privacy notice - https://mcp.ecocitizenz.com/terms — terms of business Related EcoCitizenz surfaces — SEPARATE SITES, not routes of this site: - https://msp.ecocitizenz.com — the ECZ-ID MSP/MSSP vertical: machine accountability across a managed client estate, and a free structured self-assessment at https://msp.ecocitizenz.com/trust-check. It is its own site with its own sitemap and its own commercial routes. ECZ-ID MCP does not serve those pages; https://mcp.ecocitizenz.com/msp and https://mcp.ecocitizenz.com/msp/trust-check are permanent (308) redirects to them, kept so historical links still resolve. Nothing there changes the doctrine above: it explains and routes, it writes no authoritative state, and a self-assessment is not an audit, a certification or a compliance opinion. Machine-readable service manifest: https://mcp.ecocitizenz.com/.well-known/mcp-services.json Notes: - Your delivery schedule is confirmed during intake. - These engagements are never discounted. Platform credits offered elsewhere in the EcoCitizenz ecosystem apply to eligible TrustOps subscription payments only, never to these services. - Contact: mcp@ecocitizenz.com Forbidden inferences for any reader: safety, certification, approval, compliance, endorsement, guaranteed compatibility, authoritative identity state, status conferred by payment, directory acceptance.