XXupra
Products

KYA for Agents and MCP

Make agent systems verifiable before they transact.

Xupra KYA gives agents and MCP servers a hosted certificate, public verification API, live MCP trust handshake, wallet binding, registry listing, and optional blockchain proof.

The official MCP Registry makes MCP servers discoverable. KYA adds the commercial trust layer: who operates the system, what endpoint is certified, which key and wallet are bound, and whether another agent should trust it before calling or paying it.

Xupra does not force one payment rail. Stripe, x402, crypto, invoice, direct contracts, and future Xupra payment services can all sit behind the same KYA verification model.

Hosted certificate

https://xupracorp.com/kya-registry/sample-certificate

Active
Issuer
did:web:xupracorp.com
Subject
Example AI Inc.
Asset
Payment MCP endpoint
Endpoint
https://example.ai/mcp
Operational key
agent-ed25519
Wallet binding
verified wallet reference
KYA level
KYA-L2
Risk class
MCP-R1
Status
active
Anchor
certificate hash proof

What we offer

A verifiable trust layer, not a replacement registry.

KYA sits above discovery. It makes counterparties easier to inspect before a tool call, data exchange, wallet-signing request, or payment-related workflow.

Hosted KYA certificate

A signed public record for one operator and one reviewed agent, MCP server, endpoint, package, repository, or agent card.

Operator and asset binding

Xupra records who operates the asset, what endpoint or manifest belongs to it, which public key is certified, and which wallet can be associated with it.

MCP trust handshake

A live verification path lets a verifier prepare a nonce challenge and confirm that the remote system still controls the certified operational key.

Blockchain proof

The public chain receives hashes and timestamps, not private customer evidence. It is the tamper-evidence layer for certificates and later ledger roots.

KYA registry listing

Approved assets can be published to the Xupra KYA Registry with certificate, API, endpoint, and metadata links for counterparties.

Commercial event records

When a seller wants it, Xupra can record hashed commercial references as internal KYA evidence without storing private payment data.

Agent vs MCP

They are connected, but they are not the same thing.

The distinction matters because agent-to-agent transactions need both sides: the endpoint being called and the actor deciding to trust it.

MCP server

The server or endpoint exposes tools, resources, prompts, and context. It is what another application or agent connects to.

Agent

The actor deciding what to do. It may call an MCP server, delegate work, request data, trigger payment, or verify another agent before using it.

KYA

The trust layer between them. KYA binds the operator, MCP endpoint, agent identity, public key, wallet reference, policy, and certificate status.

How the system works

Trust before transaction. Proof after transaction.

KYA combines hosted certificate lookup, policy evaluation, optional live challenge-response, and evidence records. The certificate tells another agent what was reviewed. The MCP handshake proves the live peer still controls the certified key.

01

Discover the MCP or agent surface

Xupra starts from a public MCP registry entry, remote endpoint, agent card, package, repository, or company website.

02

Probe the endpoint

Xupra can connect from our side to the company's MCP endpoint to record reachability, response headers, latency, and available public tool metadata where allowed.

03

Review and issue

After agreement and payment, Xupra runs the review, records evidence privately, signs the hosted certificate, and publishes the public verification record.

04

Verify before transaction

A buyer agent fetches the certificate, checks policy, validates status and signature, then uses MCP challenge-response for stronger live proof.

Trust infrastructure

AWS signs and hosts the private trust boundary. Blockchain anchors public hashes.

Customer evidence, surveys, private review notes, and payment references stay off-chain. The chain is used for public proof that a certificate or ledger root existed at a point in time.

AWS KMS

Signs the canonical certificate payload with a controlled Xupra issuer key.

AWS archive

Stores signed certificate artifacts and publication manifests outside the public UI.

Public API

Serves active status, certificate JSON, issuer metadata, badge, and MCP handshake tools.

Polygon anchor

Records hashes for public tamper evidence once the certificate is anchored.

Verification endpoints

A certificate humans can inspect and agents can verify.

The sample certificate shows the public fields. Live certificates expose the same shape through a hosted page and machine-readable API.

https://xupracorp.com/kya-registry/sample-certificate

https://xupracorp.com/.well-known/kya-registry.json

https://xupracorp.com/api/kya-registry/v1/mcp

kya_prepare_handshake / kya_verify_handshake / kya_evaluate_policy