Let AI agents seal their own work (MCP + SDKs)
Connect Sigill as an MCP server and agents timestamp, seal and verify autonomously, by hash only; add the SDKs for seals embedded in PDFs — every consequential action leaves tamper-evident evidence.
Let AI agents seal their own work (MCP + SDKs)
Agents act at machine speed: they write documents, make decisions, call tools, produce artifacts. The organisations deploying them are starting to ask the obvious governance question — can the agent prove what it did? With Sigill's Model Context Protocol (MCP) server, the answer is built in: any MCP-capable assistant or agent framework gets timestamping and verification as native tools, no integration code required.
Connect it
Add Sigill to the agent's MCP configuration — for example in Claude Code:
claude mcp add --transport http sigill https://api.sigill.ai/mcp \
--header "Authorization: Bearer YOUR_API_KEY"
In ChatGPT or Claude, add https://api.sigill.ai/mcp as a custom connector instead and sign in to Sigill when asked — no key needed; you approve exactly what the assistant may do, and can disconnect it any time under Settings → Connected apps.
That's the whole integration. The agent now has tools to timestamp hashes, create and verify detached seals (CAdES or JAdES) over hashes, seal multi-object AI-evidence records, look up prior proofs, and review your organisation's seal operations, certificates and quota. The MCP server has no document upload or download capability: the agent hashes files locally and sends only the digest, and gets back the timestamp token or detached signature to keep beside the file. For seals embedded in a PDF, put the SDKs in the agent's environment (see below).
What it looks like in practice
- "Timestamp every file you deliver" — the agent stamps each output's hash as it works, leaving
.tsrtokens beside its deliverables. - "Before using this file, check its timestamp" — the agent hashes the file it received and verifies it against the
.tsrinstead of trusting the bytes. - "What did we seal last week?" — the agent queries the operation history and reconciles it against its own logs.
- "Seal the JSON report you just produced" — the agent hashes it, calls
sigill_seal_hashwithformat: "jades", and saves the.jades.jsonbeside the report. - "Seal the contract draft you just wrote" — with the SDK available, the agent seals the PDF locally via delegated PAdES; only the digest reaches Sigill.
The MCP announcement post walks through a full session, and sealing Claude Code sessions shows the pattern applied to coding agents specifically.
Agents at scale: pair MCP with the SDKs
MCP is right for interactive assistants and tool-using agents. For agent platforms — where your infrastructure runs many agents and you want evidence produced systematically rather than by the agent's choice — put the SDKs in the harness instead: seal every session log on rotation (JAdES for agent logs), timestamp every artifact at creation, and record AI evidence envelopes for individual model calls. The two approaches compose: the agent timestamps and seals deliberately via MCP while the platform seals everything through the SDKs as a matter of policy.
Why this matters now
Agent output is exactly the evidence class that disputes will be made of: decisions with money attached, generated documents sent to counterparties, autonomous changes to systems. Evidence captured at the moment of action — hashed, timestamped, sealed — is categorically stronger than logs assembled after the fact, because it is independently verifiable and tamper-evident from the second it exists. Giving the agent the sealing tools is the cheapest way to make that the default.