# verify_audit_chain

Return an envelope's append-only audit-event hash chain together with a server-computed integrity verdict: every event_hash is recomputed from its canonical material, and the prev_event_hash linkage and per-envelope seq contiguity are checked. Evidence only, never PDF bytes. The raw events are included verbatim so the caller can independently re-derive the verdict instead of trusting chain.valid.

Agent View of the PolicyLayer registry record for `verify_audit_chain`. HTML page: https://policylayer.com/tools/com-free-sign-signing/verify-audit-chain

## Facts

- Tool: `verify_audit_chain`
- Server: FreeSign — Free e-signature (`https://free-sign.com/mcp`) — https://policylayer.com/tools/com-free-sign-signing.md
- Homepage: https://github.com/https://free-sign.com/mcp
- Risk category: Read (Low risk)
- Registry record: grade C, identity unverified
- Server auth posture: open
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 1 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `envelope_id` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "verify_audit_chain",
    "arguments": {
      "envelope_id": "<envelope_id>"
    }
  }
}
```

## Why verify_audit_chain is rated Low

This tool retrieves and verifies historical audit data without modifying it, generating no side effects. It provides transparency by returning raw events for independent validation rather than requiring trust in computed verdicts. This is a read-only verification function with minimal risk if misused—an agent could request verification of any envelope but cannot affect system state or data integrity.

From the tool's own definition: "Tool returns audit-event hash chain and integrity verdict with raw events for independent verification. Explicitly states 'Evidence only, never PDF bytes.' No creation, modification, deletion, code execution, or financial operations performed."

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call verify_audit_chain to retrieve information from FreeSign — Free e-signature without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches FreeSign — Free e-signature:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "verify_audit_chain": {}
  }
}
```

## Other tools on FreeSign — Free e-signature (4)

- `get_ots_proof` — Read — https://policylayer.com/tools/com-free-sign-signing/get-ots-proof.md
- `get_receipt` — Read — https://policylayer.com/tools/com-free-sign-signing/get-receipt.md
- `verify_document_hash` — Read — https://policylayer.com/tools/com-free-sign-signing/verify-document-hash.md
- `create_signing_envelope` — Write — https://policylayer.com/tools/com-free-sign-signing/create-signing-envelope.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-free-sign-signing · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-free-sign-signing
