Skip to main content
Trusted MCP adds remote attestation and end-to-end encryption to a configured MCP connection. Use it with tool services that support the corresponding trusted protocol

Scope of the trusted connection

VeADK connects to Trusted MCP services through TrustedMcpToolset. With confidential-computing environments such as Jeddak AICC, the client verifies the remote service against its attestation policy and establishes a trusted channel for that MCP connection. Configure protection separately for the agent runtime, model services, and other data destinations

Prerequisites

1

Prepare a Trusted MCP service

Obtain a Trusted MCP service address, e.g. https://your-trusted-mcp.example.com/mcp.
2

Prepare the AICC config

Prepare the AICC config file ./aicc_config.json (for the confidential environment and remote attestation); see the official example.

Usage

Turn on x-trusted-mcp: true in the connection parameters, then connect with TrustedMcpToolset:
agent.py

Options

Key TrustedMcpToolset options: For the config file’s format and details, see the Trusted MCP config reference.

Connection requirements and verification

Configure the model, set TRUSTED_MCP_URL to a Trusted MCP Streamable HTTP endpoint, and prepare the AICC configuration required by your provider. Running python agent.py should list available tools and then print a model response The trusted channel requires both StreamableHTTPConnectionParams and the x-trusted-mcp header with the string value true. Omitting the header or using SSE/stdio parameters does not enable this channel. AICC settings belong to the trusted client configuration, not a TrustedMcpToolset(aicc_config=...) constructor argument. Attestation policies must match the service requirements Successful tool discovery only verifies connectivity and discovery; also check the trusted client’s attestation result. This channel does not protect data in other tools, model services, or logs
Last modified on September 19, 2026