eu.qeaas/qeaas-mcp

qeaas-mcp

QRNG-seeded random bytes, seeds, and ML-KEM-768 keys with signed provenance receipts.

1.0.0
Version
remote
Transport
6
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 6 tools scanned
  • metadata: scanned

No findings.

Tools (6)

  • random

    DRBG-derived random bytes (base64), anonymous and rate-limited. Capped at 64 bytes/request; powers the public dice player.

  • dice

    Rejection-sampled dice rolls (no modulo bias), anonymous and rate-limited. Echoes the DRBG bytes drawn for transparency.

  • random_bytes

    Canonical developer endpoint: DRBG-derived bytes in hex or base64 with a signed provenance receipt. Requires X-API-Key; 32..4096 bytes; per-key rate limit + daily quota.

  • verify

    Verify the provenance of an issued value from its request_id and/or receipt. Provenance only -- never a value-confirmation oracle. Anonymous, rate-limited.

  • kem_keypair

    Generate an ML-KEM-768 (Kyber, post-quantum) keypair seeded from the QRNG->DRBG chain. Public key always returned; secret key only for the demo flow (loud demo-only note). Requires X-API-Key.

  • kem_encapsulate

    Encapsulate against a supplied ML-KEM-768 public key to produce a ciphertext (and, for the demo, the shared secret). Requires X-API-Key.