qeaas-mcp
QRNG-seeded random bytes, seeds, and ML-KEM-768 keys with signed provenance receipts.
- 1.0.0
- Version
- remote
- Transport
- 6
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 6 tools scanned
- metadata: scanned
No findings.
Tools (6)
random
DRBG-derived random bytes (base64), anonymous and rate-limited. Capped at 64 bytes/request; powers the public dice player.
dice
Rejection-sampled dice rolls (no modulo bias), anonymous and rate-limited. Echoes the DRBG bytes drawn for transparency.
random_bytes
Canonical developer endpoint: DRBG-derived bytes in hex or base64 with a signed provenance receipt. Requires X-API-Key; 32..4096 bytes; per-key rate limit + daily quota.
verify
Verify the provenance of an issued value from its request_id and/or receipt. Provenance only -- never a value-confirmation oracle. Anonymous, rate-limited.
kem_keypair
Generate an ML-KEM-768 (Kyber, post-quantum) keypair seeded from the QRNG->DRBG chain. Public key always returned; secret key only for the demo flow (loud demo-only note). Requires X-API-Key.
kem_encapsulate
Encapsulate against a supplied ML-KEM-768 public key to produce a ciphertext (and, for the demo, the shared secret). Requires X-API-Key.