Skip to content
RowAttest
Methodology Verify a report API & MCP GitHub Log in Create account

API & MCP

RowAttest MCP server

RowAttest runs an eight-stage isolation test against your staging Supabase and issues a signed attestation. The MCP server gives your AI assistant the same six actions a RowAttest API key has: list your projects, start a run, follow it, and read the findings and the signed report. Projects are connected on the website only. The server cannot connect projects, change settings, or pay for anything.

Endpoint

URL
https://app.rowattest.com/mcp
Transport
Streamable HTTP. The endpoint accepts POST; GET answers 405.
Authentication
Authorization: Bearer rak_… — a RowAttest API key, created on the API keys page in the app.
Accept header
Clients send Accept: application/json, text/event-stream. Standard MCP clients do this on their own.

Open handshake, keyed tools

initialize, tools/list and server/discover answer without a key, so clients and directories can see what the server offers before a key is configured. Every tools/call needs a key. Without a valid one the server answers 401 with:

This request needs a valid RowAttest API key in the Authorization header.

Connect your assistant

Claude Code:

claude mcp add --transport http rowattest https://app.rowattest.com/mcp --header "Authorization: Bearer rak_your_key"

Clients that read an mcpServers block (Cursor and others):

{
  "mcpServers": {
    "rowattest": {
      "url": "https://app.rowattest.com/mcp",
      "headers": { "Authorization": "Bearer rak_your_key" }
    }
  }
}

The API keys page in the app shows ready-to-paste settings for Claude Code, Cursor and mcp-remote.

The six tools

list_projects

Lists the Supabase projects connected to this account with id, name, connection state and whether each is ready to run. Call this first to get a project_id.

Input: none

run_review

Starts an authorization test run on a connected project and returns the run_id and status. If the project already has a run waiting to start, returns that run instead of starting another. Runs that do not fail count against the monthly allowance.

Input: project_id

get_run_status

Returns a run's status (queued, running, complete or failed), its current stage, timestamps and, when a signed report exists, its verify_url.

Input: run_id

wait_for_run

Waits up to timeout_seconds (1 to 60) for a run to finish, then returns the same information as get_run_status. Call it again while the status is still queued or running.

Input: run_id, timeout_seconds (optional)

get_findings

Returns the cells that did not pass in a complete run that has a signed report — verdict, surface, operation, boundary, identity, layer outcomes and notes — plus tenancy flags and blocking findings. For a complete run with no signed report, while one can still be bought on the run page, it returns the run's unverified result instead: the verdict, surface, operation and principal of each cell that did not pass, the run page's finding lines, the counts, the coverage lines and the access model summary. The list of cells is empty when every tested cell passed. Contains no fix suggestions: the engine records only what it observed.

Input: run_id

get_report

Returns the full signed report of a complete run as the exact stored JSON, with its verify_url and report_sha256 (sha256 of the canonical signed bytes, the fingerprint shown on the verify page). Use get_findings for the compact view.

Input: run_id

A typical session: list_projects → run_review → wait_for_run until the status is complete or failed → get_findings, and get_report when a signed report exists.

What a key can and cannot do

Create a key on the API keys page. A key can list your projects, start runs, follow them, and read findings and the signed report. It cannot connect projects, change settings, or pay for anything. Keys and agents never hold your project's credentials.

Allowance

Runs started through MCP count against the account's monthly allowance, the same as runs started in the dashboard or through the REST API. Failed runs do not count.

Unsigned and signed

Free runs show their results on the run page and through the API, labelled as unverified; get_findings returns that unverified result. Buying the signed report for a run adds the signed PDF, a public verify link, and the signed JSON, which get_report returns. Anyone can check a signed report at its verify link on rowattest.com/verify.

Requests without a key

Requests that need a key but carry no valid one are rate-limited. The privacy policy describes what is recorded for that and for how long.

Also available

  • REST API with the same actions: OpenAPI description at https://app.rowattest.com/api/v1/openapi.json.
  • Official MCP Registry entry: com.rowattest/rowattest.
  • Source and security policy: github.com/rowattest.
  • Questions: info@rowattest.com.
← Back to RowAttest
Privacy Policy Terms of Use Cookie Policy Credential handling Methodology App API description GitHub

© 2026 RW Digital Ventures LLC · info@rowattest.com