zkzkMCP
SDK & API reference

Maturity and limitations

What is working today and what remains prototype-only.

zkMCP is a working hackathon infrastructure prototype, not a finished authorization platform.

Implemented and validated locally

  • real MCP tools/list proxying
  • real MCP tools/call interception
  • Compact private-policy commitment
  • resource membership checks
  • private numeric limits
  • trusted approval boundary
  • nullifier-based replay protection
  • real proof generation and verification
  • finalized local Midnight transactions
  • upstream tool execution only after authorization
  • privacy-safe receipt metadata
  • typed errors and local evlog observability
  • recorded and live documentation playground

Not yet implemented

  • published npm packages
  • general policy DSL
  • policy rotation and revocation
  • multiple simultaneous policy sets
  • signed/scoped/expiring production approvals
  • delegated agent identities
  • multi-party authorization
  • production secret storage
  • authorization for MCP resources/prompts
  • optimized concurrent proving
  • fully validated preview/preprod deployment
  • remote production prover architecture

Documentation should treat these as future work rather than implied capabilities.

On this page