> ## Documentation Index
> Fetch the complete documentation index at: https://docs.veadk.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Trusted MCP

Trusted MCP adds component attestation and verification on top of the standard MCP protocol, plus end-to-end encrypted communication. Combined with confidential computing (such as Jeddak AICC) and trusted inference services, it guards against untrusted service identities, tampered data, traffic hijacking, and privacy leaks.

## Trusted agents

With confidential computing, you can run the agent and its model services (such as confidential Doubao) in a trusted environment, then use Trusted MCP's end-to-end encrypted communication to build a fully trusted agent. VeADK natively supports connecting to Trusted MCP services, opening a trusted channel within the tool-call chain to secure outbound communication.

## Prerequisites

<Steps>
  <Step title="Prepare a Trusted MCP service">
    Obtain a Trusted MCP service address, e.g. `wss://your-trusted-mcp.example.com`.
  </Step>

  <Step title="Prepare the AICC config">
    Prepare the AICC config file `./aicc_config.json` (for the confidential environment and remote attestation); see the [official example](https://github.com/volcengine/AICC-Trusted-MCP/blob/main/README.md).
  </Step>
</Steps>

## Usage

Turn on `x-trusted-mcp: true` in the connection parameters, then connect with `TrustedMcpToolset`:

```python title="agent.py" lines theme={null}
import asyncio

from veadk import Agent
from veadk.utils.mcp_utils import get_mcp_params
from veadk.tools.mcp_tool.trusted_mcp_toolset import TrustedMcpToolset

mcp_url = "<Trusted MCP server address>"

# Open the trusted channel
connection_params = get_mcp_params(mcp_url)
connection_params.headers = {"x-trusted-mcp": "true"}

# Initialize the trusted toolset and attach it to the agent
toolset = TrustedMcpToolset(connection_params=connection_params)
agent = Agent(tools=[toolset])

response = asyncio.run(agent.run("What's the weather in Beijing?"))
print(response)
```

## Options

Key `TrustedMcpToolset` options:

| Option | Location | Default | Description |
| - | - | - | - |
| `x-trusted-mcp` | Header | `true` | Whether to enable Trusted MCP and open the trusted channel |
| `aicc_config` | File path | `./aicc_config.json` | AICC config file path, for attestation and policy in the confidential-computing environment |

For the config file's format and details, see the [Trusted MCP config reference](https://github.com/volcengine/AICC-Trusted-MCP/blob/main/README.md).
