Skip to main content
Trusted MCP adds component attestation and verification on top of the standard MCP protocol, plus end-to-end encrypted communication. Combined with confidential computing (such as Jeddak AICC) and trusted inference services, it guards against untrusted service identities, tampered data, traffic hijacking, and privacy leaks.

Trusted agents

With confidential computing, you can run the agent and its model services (such as confidential Doubao) in a trusted environment, then use Trusted MCP’s end-to-end encrypted communication to build a fully trusted agent. VeADK natively supports connecting to Trusted MCP services, opening a trusted channel within the tool-call chain to secure outbound communication.

Prerequisites

1

Prepare a Trusted MCP service

Obtain a Trusted MCP service address, e.g. wss://your-trusted-mcp.example.com.
2

Prepare the AICC config

Prepare the AICC config file ./aicc_config.json (for the confidential environment and remote attestation); see the official example.

Usage

Turn on x-trusted-mcp: true in the connection parameters, then connect with TrustedMcpToolset:
agent.py

Options

Key TrustedMcpToolset options: For the config file’s format and details, see the Trusted MCP config reference.
Last modified on September 19, 2026