vc_issue
Composes and signs a W3C Verifiable Credential 2.0 with an eddsa-jcs-2022 Data Integrity proof over a fresh ephemeral did:key (generated per call, not reused). Returns the signed credential, an OCG Standard §23 vc-2.0 input-attestation block ready to embed in a ChainGraph chain's policy_parameter...
This record as markdown: /tools/postoaklabs-ainumbers-mcp-apps/vc-issue.md
What vc_issue does on Ainumbers Mcp Apps
AI agents use vc_issue to create or update resources in Ainumbers Mcp Apps, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Ainumbers Mcp Apps environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
claims | object | Yes | Claim key-value pairs for credentialSubject (required, at least one entry). |
pointer | string | — | RFC 6901 JSON pointer where the attestation's claims sit in a consuming chain's policy_parameters. Default: "/subject_claims". |
subject_id | string | — | Credential subject id (DID or any identifier string). Default: "did:example:subject". |
valid_from | string | — | ISO 8601 validFrom. Default: now. |
valid_until | string | — | ISO 8601 validUntil. |
credential_type | string | — | Type appended to VerifiableCredential (e.g. "MembershipCredential"). |
Parameters from the server's own tool schema.
Why vc_issue is rated Medium
This tool creates and modifies cryptographic artifacts (signed verifiable credentials) that are intended for embedding in policy parameters of blockchain-like systems (ChainGraph chains). While it does not directly move funds, it creates authoritative cryptographic bindings that could be used to establish claims, permissions, or attestations in downstream financial/governance systems.
From the tool's definition Composes and signs a W3C Verifiable Credential 2.0 with an eddsa-jcs-2022 Data Integrity proof; returns a signed credential ready to embed in a ChainGraph chain's policy_parameters
Attacks that exploit this kind of access
The rule that runs vc_issue safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Ainumbers Mcp Apps, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For vc_issue, this is the rule to start with:
vc_issue stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Ainumbers Mcp Apps, apply this rule, and every vc_issue call is checked against it from then on.
Questions about vc_issue
Composes and signs a W3C Verifiable Credential 2.0 with an eddsa-jcs-2022 Data Integrity proof over a fresh ephemeral did:key (generated per call, not reused). Returns the signed credential, an OCG Standard §23 vc-2.0 input-attestation block ready to embed in a ChainGraph chain's policy_parameters at the given pointer, and an OCG receipt of the issuance activity. The signature proves the claims were not altered after signing and that the did:key holder produced it -- it is not, by itself, identity assurance. It is categorised as a Write tool in the Ainumbers Mcp Apps MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
vc_issue accepts 6 parameters: claims, pointer, subject_id, valid_from, valid_until, credential_type. Required: claims. The full parameter table on this page comes from the server's own tool schema.
Register the Ainumbers Mcp Apps MCP server in PolicyLayer and add a rule for vc_issue: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Ainumbers Mcp Apps. Nothing to install.
vc_issue is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the vc_issue rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for vc_issue. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
vc_issue is provided by the Ainumbers Mcp Apps MCP server (postoaklabs/ainumbers-mcp-apps). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Ainumbers Mcp Apps, and thousands of servers like it.
This server
Across the catalogue