DocsUse cases

Let AI agents seal their own work (MCP + SDKs)

Connect Sigill as an MCP server and agents timestamp, seal and verify autonomously, by hash only; add the SDKs for seals embedded in PDFs — every consequential action leaves tamper-evident evidence.

Let AI agents seal their own work (MCP + SDKs)

Agents act at machine speed: they write documents, make decisions, call tools, produce artifacts. The organisations deploying them are starting to ask the obvious governance question — can the agent prove what it did? With Sigill's Model Context Protocol (MCP) server, the answer is built in: any MCP-capable assistant or agent framework gets timestamping and verification as native tools, no integration code required.

Connect it

Add Sigill to the agent's MCP configuration — for example in Claude Code:

claude mcp add --transport http sigill https://api.sigill.ai/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

In ChatGPT or Claude, add https://api.sigill.ai/mcp as a custom connector instead and sign in to Sigill when asked — no key needed; you approve exactly what the assistant may do, and can disconnect it any time under Settings → Connected apps.

That's the whole integration. The agent now has tools to timestamp hashes, create and verify detached seals (CAdES or JAdES) over hashes, seal multi-object AI-evidence records, look up prior proofs, and review your organisation's seal operations, certificates and quota. The MCP server has no document upload or download capability: the agent hashes files locally and sends only the digest, and gets back the timestamp token or detached signature to keep beside the file. For seals embedded in a PDF, put the SDKs in the agent's environment (see below).

What it looks like in practice

  • "Timestamp every file you deliver" — the agent stamps each output's hash as it works, leaving .tsr tokens beside its deliverables.
  • "Before using this file, check its timestamp" — the agent hashes the file it received and verifies it against the .tsr instead of trusting the bytes.
  • "What did we seal last week?" — the agent queries the operation history and reconciles it against its own logs.
  • "Seal the JSON report you just produced" — the agent hashes it, calls sigill_seal_hash with format: "jades", and saves the .jades.json beside the report.
  • "Seal the contract draft you just wrote" — with the SDK available, the agent seals the PDF locally via delegated PAdES; only the digest reaches Sigill.

The MCP announcement post walks through a full session, and sealing Claude Code sessions shows the pattern applied to coding agents specifically.

Agents at scale: pair MCP with the SDKs

MCP is right for interactive assistants and tool-using agents. For agent platforms — where your infrastructure runs many agents and you want evidence produced systematically rather than by the agent's choice — put the SDKs in the harness instead: seal every session log on rotation (JAdES for agent logs), timestamp every artifact at creation, and record AI evidence envelopes for individual model calls. The two approaches compose: the agent timestamps and seals deliberately via MCP while the platform seals everything through the SDKs as a matter of policy.

Why this matters now

Agent output is exactly the evidence class that disputes will be made of: decisions with money attached, generated documents sent to counterparties, autonomous changes to systems. Evidence captured at the moment of action — hashed, timestamped, sealed — is categorically stronger than logs assembled after the fact, because it is independently verifiable and tamper-evident from the second it exists. Giving the agent the sealing tools is the cheapest way to make that the default.