Conformance evidence

Copy Markdown View Source

This is reproducible test evidence for attesto_mcp_server 0.14.0, not a certification, endorsement, or claim of support for every optional MCP extension.

Tested candidate

  • source fingerprint: c4699bf3fa9509162a50c7d4486c531eeea44b16e6a99f5f84baf1130db732c1
  • official runner: @modelcontextprotocol/conformance 0.2.0-alpha.11
  • runner commit: 74edef34d674f563537be8c6587cebaa58e830ca
  • runner archive SHA-256: 28d22ae3a4541a9a68c208e6a5653486bfacd97df45cf63cd8f0f7f9d5938293
  • expected-failure files or exemptions: none

The fingerprint covers the tracked mix.exs, config, lib, examples, scripts, test, and fixtures files:

git ls-files -z mix.exs config lib examples scripts test fixtures |
  xargs -0 shasum -a 256 |
  shasum -a 256

Official server runner

RequirementsSelectedScoredNot scoredRaw assertionsResult
2026-07-285037/37 passed4 passed, 9 failed161 passed, 30 failedexit 0
2025-11-253330/30 passed3 passed, 0 failed80 passed, 0 failedexit 0

The 30 raw failures belong to nine Tasks-extension scenarios that the runner marks not scored. Tasks are disabled and are not advertised by this release. The unscored JSON Schema and HTTP-header scenarios passed.

To reproduce the runner setup:

RUNNER_DIR="$(mktemp -d "${TMPDIR:-/tmp}/mcp-conformance.XXXXXX")"
ARCHIVE="$RUNNER_DIR.tar.gz"
curl -fsSL \
  "https://github.com/modelcontextprotocol/conformance/archive/74edef34d674f563537be8c6587cebaa58e830ca.tar.gz" \
  -o "$ARCHIVE"
printf '%s  %s\n' \
  28d22ae3a4541a9a68c208e6a5653486bfacd97df45cf63cd8f0f7f9d5938293 \
  "$ARCHIVE" | sha256sum -c -
mkdir -p "$RUNNER_DIR"
tar -xzf "$ARCHIVE" -C "$RUNNER_DIR" --strip-components=1
npx --yes npm@12.0.2 ci --prefix "$RUNNER_DIR"
npx --yes npm@12.0.2 run build --prefix "$RUNNER_DIR"
scripts/run_conformance_fixture.sh "$RUNNER_DIR" 2026-07-28
scripts/run_conformance_fixture.sh "$RUNNER_DIR" 2025-11-25

Official client SDKs

The package fixture also negotiated each scored revision, listed tools, called test_simple_text, validated the response, and closed the connection with the exact released SDK versions below.

Client2025-11-252026-07-28
@modelcontextprotocol/client@2.0.0passedpassed
mcp==2.1.1passedpassed

The entrypoints are scripts/client_smoke_ts.mjs, scripts/client_smoke_python.py, and scripts/run_client_smoke_fixture.sh. They validate authenticated protocol interoperability, not OAuth discovery or token acquisition.

Package gates

  • The default lane passed 597 checks: one doctest and 596 tests, with the 36 database-gated tests skipped. Coverage for this default lane was 80.03%. A separate non-coverage PostgreSQL lane then passed all 36 durable Ecto session-store tests.
  • Dialyzer completed with zero errors and zero skips.
  • Package construction and the Hex advisory audit passed.
  • The installer matrix passed with AttestoMCP 1.3.0 across Attesto 1.15.0 and 2.0.0, AttestoPhoenix 2.14.1, 2.14.2, and 3.0.0, and a generated Phoenix 1.8.13 host.

The frozen runner does not score 2025-06-18. Package-owned HTTP, stdio, lifecycle, revision-filtering, and configuration regressions cover that revision without presenting an official runner score for it.