{
  "schema": "ecz.website_family_site.v2",
  "site": {
    "name": "ECZ-ID MCP",
    "url": "https://mcp.ecocitizenz.com",
    "brand_contract": "ecz.website_brand_contract.v1",
    "operator": {
      "legal_name": "EcoCitizenz Ltd",
      "ecz_id": "ECZ-GB-RBS1NW",
      "resolver": "https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW",
      "resolver_machine": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json",
      "statement": "The operator's own record is proof about the company that runs this site, not about any visitor or any Passport they hold."
    }
  },
  "family": {
    "slug": "mcp",
    "type_code": "MCP_PASSPORT",
    "family_code": "MCP",
    "product_name": "ECZ-ID MCP Passport™",
    "subject": "MCP server",
    "identifier_pattern": "ECZ-XX-XXXXXX::MCP_PASSPORT-XXXXXX",
    "subject_law": "One MCP Passport is one logical MCP server operated by your organisation.",
    "not_separate_passports": "Versions, endpoints, deployments and registry listings of that server are not separate Passports."
  },
  "free_passport": {
    "price_gbp": 0,
    "price_label": "FREE",
    "includes": [
      "A persistent ECZ-ID for the MCP server.",
      "Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.",
      "A public Resolver record anyone can open, and the same record as machine-readable JSON.",
      "A badge, a QR code and a share link.",
      "Basic bindings to the public places your MCP server already appears.",
      "Lifecycle and current public state, evaluated on demand.",
      "Claim and recovery.",
      "Basic participation in the Digital Entity Graph.",
      "Essential lifecycle evidence, kept in LedgerCore."
    ],
    "distinctions": [
      {
        "title": "DECLARED ≠ VERIFIED",
        "body": "A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check."
      },
      {
        "title": "Identity ≠ Binding",
        "body": "The Passport identifies the MCP server. A binding records a public place it already appears. Adding a binding never creates a second identity."
      },
      {
        "title": "Binding ≠ Authority",
        "body": "A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act."
      },
      {
        "title": "Parent verification ≠ MCP verification",
        "body": "A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the MCP server."
      }
    ],
    "publication_consent_required": true
  },
  "acquisition": {
    "state": "AVAILABLE",
    "states": [
      "AVAILABLE",
      "TEMPORARILY_PAUSED",
      "NOT_YET_LIVE"
    ],
    "start_url": "https://trustops.ecocitizenz.com/start/mcp?source_surface=mcp-machine-descriptor",
    "authority": "https://trustops.ecocitizenz.com",
    "configuration": "Set by Operating Command through ECZ_FAMILY_ACQUISITION_STATE. FREE is the price; the state is whether new activations are open."
  },
  "aec": {
    "name": "AEC — Active Entity Capacity",
    "definition": "One AEC is one actively managed production entity with live bindings and current state.",
    "exists_without_aec": "A free Passport exists and resolves whether or not you use any AEC.",
    "counts_for_this_family": "An MCP server you actively manage in production, with live bindings and current state.",
    "pooled_across": "AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.",
    "device_instances": "Individual IoT device instances are counted separately, in IoT Fleet Capacity, and never consume AEC.",
    "never": [
      "AEC never makes an identity more verified.",
      "AEC never replaces a Passport.",
      "AEC never changes an ECZ-ID. Your ECZ-ID does not change.",
      "Running out of AEC never deletes, revokes or unpublishes an identity."
    ]
  },
  "commercial": {
    "authority": "TrustOps",
    "trustops_origin": "https://trustops.ecocitizenz.com",
    "configure_url": "https://trustops.ecocitizenz.com/start",
    "prices_published_here": false,
    "statement": "Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal."
  },
  "interoperability": {
    "families": [
      "AGENT_PASSPORT",
      "API_PASSPORT",
      "PLUGIN_PASSPORT",
      "SDK_PASSPORT"
    ],
    "systems": [
      {
        "name": "Model Context Protocol (MCP)",
        "what_it_does": "Connects AI applications to tools and data through a defined client–server protocol.",
        "what_ecz_id_adds": "A resolvable identity for the agent and, separately, for each MCP server it uses — each with a named operator.",
        "replaces": false
      },
      {
        "name": "MCP Registry",
        "what_it_does": "Lists MCP servers so that clients can discover them.",
        "what_ecz_id_adds": "A binding from the registry entry to one ECZ-ID with a named operator.",
        "replaces": false
      },
      {
        "name": "OAuth 2.x and OpenID Connect",
        "what_it_does": "Delegate authorisation and authenticate a principal for a session.",
        "what_ecz_id_adds": "A durable public record of the subject and its operator that outlives any token and needs none to read.",
        "replaces": false
      },
      {
        "name": "Agent2Agent (A2A)",
        "what_it_does": "Lets agents discover one another and exchange tasks.",
        "what_ecz_id_adds": "A persistent public identity a counterparty agent can resolve and re-check outside the conversation itself.",
        "replaces": false
      }
    ],
    "boundary": "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  },
  "strengthen": [
    {
      "key": "parent-assurance",
      "name": "Parent VERIFIED and ASSURED",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates.",
      "boundary": "It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.",
      "included_free": "Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.",
      "next_steps": [
        {
          "kind": "TRUSTOPS",
          "label": "Configure in TrustOps",
          "url": "https://trustops.ecocitizenz.com/start#parent-passports"
        }
      ]
    },
    {
      "key": "mcp-trust",
      "name": "MCP Trust",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "A local-first editor extension that shows which MCP servers your workspace uses and what they can reach. Pro adds deeper analysis.",
      "boundary": "It inspects your workspace on your machine and publishes nothing about your servers.",
      "included_free": "MCP Trust Community and the MCP Verifier are free.",
      "next_steps": [
        {
          "kind": "TRUSTOPS",
          "label": "Configure in TrustOps",
          "url": "https://trustops.ecocitizenz.com/start#mcp-kya-agent-trust"
        }
      ]
    },
    {
      "key": "mcp-assurance",
      "name": "MCP Assurance",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Scoped assurance and policy for production MCP servers, from a single production target to enterprise governance.",
      "boundary": "Assurance is a scoped review, not a certification, and it never claims enforcement without a live enforcement adapter.",
      "included_free": null,
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:mcp@ecocitizenz.com?subject=MCP%20Assurance%20%E2%80%94%20ECZ-ID%20MCP%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "pulseguard",
      "name": "PulseGuard",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.",
      "boundary": "It reports state. It is not a safety verdict, and it never changes an identity or its tier.",
      "included_free": "On-demand and event-driven evaluation of your own entities.",
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:mcp@ecocitizenz.com?subject=PulseGuard%20%E2%80%94%20ECZ-ID%20MCP%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "evidencecore",
      "name": "EvidenceCore",
      "prominence": "SECONDARY",
      "phase": "IN_V2_BUILD",
      "adds": "The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it.",
      "boundary": "Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification.",
      "included_free": "Essential evidence references are part of every free Passport.",
      "next_steps": []
    },
    {
      "key": "ledgercore",
      "name": "LedgerCore",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger.",
      "boundary": "An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true.",
      "included_free": "Essential LedgerCore evidence is kept for every identity, free ones included.",
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:mcp@ecocitizenz.com?subject=LedgerCore%20%E2%80%94%20ECZ-ID%20MCP%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "graph",
      "name": "Digital Entity Graph and Graph Intelligence",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view.",
      "boundary": "A relationship in the graph is a published link, not an endorsement of either end.",
      "included_free": "Basic Graph participation and a current one-hop view.",
      "next_steps": [
        {
          "kind": "PRIVATE_OFFER",
          "label": "Discuss a private offer",
          "url": "mailto:mcp@ecocitizenz.com?subject=Digital%20Entity%20Graph%20and%20Graph%20Intelligence%20%E2%80%94%20ECZ-ID%20MCP%20Passport%E2%84%A2"
        }
      ]
    }
  ],
  "operate": [
    {
      "key": "developer-gateway",
      "name": "Developer Gateway",
      "summary": "Integration reference, schemas and machine-readable documentation for ECZ-ID.",
      "url": "https://developers.ecocitizenz.com"
    },
    {
      "key": "mcp-verifier",
      "name": "MCP Verifier",
      "summary": "A free, local-first verifier — CLI, stdio MCP server and GitHub Action — that checks public Resolver posture and never writes truth.",
      "url": "https://developers.ecocitizenz.com/install"
    },
    {
      "key": "trust-mcp",
      "name": "ECZ-ID Trust MCP",
      "summary": "A read-only remote MCP server (com.ecocitizenz/trust-mcp) that looks up public ECZ-ID Business Passport state for MCP clients. It reports state only.",
      "url": "https://developers.ecocitizenz.com/install"
    },
    {
      "key": "resolver",
      "name": "Resolver",
      "summary": "Resolve any ECZ-ID to its public record — free, with no account and no API key.",
      "url": "https://mcp.ecocitizenz.com/developers#how-to-verify"
    },
    {
      "key": "machine-json",
      "name": "Machine-readable record",
      "summary": "Every record as JSON at /api/p/{ecz_id}.json, for policy engines, gateways and agents. Shown here on EcoCitizenz's own record.",
      "url": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json"
    },
    {
      "key": "console",
      "name": "ECZ-ID console",
      "summary": "Sign in to TrustOps to reach the Passports your organisation holds. It is where current commercial configuration lives, too.",
      "url": "https://trustops.ecocitizenz.com/console"
    }
  ],
  "related": [
    {
      "type_code": "AGENT_PASSPORT",
      "product_name": "ECZ-ID Agent Passport™",
      "relationship": "Agents are the clients that call your server. Each agent is a separate subject with its own operator and its own Passport.",
      "acquisition_state": "AVAILABLE",
      "start_url": "https://trustops.ecocitizenz.com/start/agent?source_surface=mcp-machine-related-agent",
      "site": "https://agents.ecocitizenz.com"
    },
    {
      "type_code": "API_PASSPORT",
      "product_name": "ECZ-ID API Passport™",
      "relationship": "Many MCP servers front an API. The API underneath keeps its own identity when the server in front of it changes.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "PLUGIN_PASSPORT",
      "product_name": "ECZ-ID Plugin Passport™",
      "relationship": "Servers are often distributed inside plugins and editor extensions, each identified once across the stores it is listed in.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "SDK_PASSPORT",
      "product_name": "ECZ-ID SDK Passport™",
      "relationship": "Servers are published as packages. The package that distributes a server is identified separately from the running server.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    }
  ],
  "resolver": {
    "human": "https://resolver.ecocitizenz.org/p/{ecz_id}",
    "machine": "https://api.ecocitizenz.com/api/p/{ecz_id}.json",
    "is_proof": false,
    "recheck_before_reliance": true,
    "statement": "A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.",
    "absence": "No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more."
  },
  "boundaries": [
    "An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything.",
    "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  ],
  "not_published_here": [
    "No A2A Agent Card and no agent manifest: this host is a website, not an agent endpoint.",
    "No prices, allowances, SKUs or purchase states: TrustOps is the commercial authority."
  ]
}
