mcpbeat Sign in

WhitePact MCP Server

by guruprasath-annadurai Your server? Claim it
answering

WhitePact is answering right now. Last checked 4 min ago. 350 installs a week from pypi. It exposes 27 tools. Last commit 31 Aug 2026.

AI governance MCP server: trust scoring, guardrails, bias/hallucination detection, compliance.

Installs per day peak 910 · avg 88 · -37% w/w
a month agotoday
Uptime history 37 days of history · worst day 0%
37 days agonow
50.0%
Uptime 24h
92 of 184 checks
27
Tools
read from the server
491 ms
Response time
average over 24h
350
Installs / week
npm and PyPI

What the code does

We read the source, 18 h ago · tools taken from the live server · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Page executes code built at runtime [пакет] src/responsibleai/dashboard/static/billing.html:70, [пакет] src/responsibleai/dashboard/static/cost.html:119, [пакет] src/responsibleai/dashboard/static/eval.html:195 и ещё 13
      grid.innerHTML = Object.keys(d).map(function (tier) {

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 4 min ago.

run in your terminal
claude mcp add whitepact --transport http https://whitepact-mcp-http.onrender.com/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "whitepact": {
      "url": "https://whitepact-mcp-http.onrender.com/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.whitepact]
url = "https://whitepact-mcp-http.onrender.com/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "whitepact": {
      "url": "https://whitepact-mcp-http.onrender.com/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "whitepact": {
      "url": "https://whitepact-mcp-http.onrender.com/mcp"
    }
  }
}

This one needs environment variables set before it will start: RAI_MCP_LOG_LEVEL (Logging level: DEBUG | INFO | WARNING.). The author declared them in the registry entry; get the values from the project itself.

This endpoint answered with an authorization challenge. The server is running, and it signs you in through your browser: there is no API key to paste.

This server publishes 1 more address. The block above uses the one we reach during checks; the full list is under Endpoints below, and the author may intend a particular one for your client.

Available tools 27

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

rai
rai_audit_summary
Return a governance capability summary including supported tools, frameworks, and available attack vectors. Full audit log access requires the REST endpoint.
rai_benchmark
Evaluate pre-collected model responses against a standard benchmark suite. Suites: truthfulqa (factual accuracy), bbq (bias in questions), hellaswag (reasoning). Call rai_benchmark_prompts first to get the question set, collect responses, then pass them here.
rai_benchmark_prompts
Return the question set for a benchmark suite. Use to collect model responses before calling rai_benchmark. Suites: truthfulqa, bbq, hellaswag.
rai_bias_evaluate
Evaluate demographic bias across six probe dimensions: gender, racial, age, religious, occupational, and cultural. Provide paired response samples for each demographic group. Returns per-probe bias scores (0=no bias, 1=maximum divergence), confidence intervals, intersectional amplification, and an overall bias grade.
rai_budget_check
Evaluate current AI spending against monthly budget limits. Returns consumption percentage, alert status, per-team and per-model breakdown, and projected month-end spend. Used by LLMOps Engineers and Finance to prevent budget overruns.
rai_check_trust
Check the public, independently-verifiable Trust Index score, certification status, and reported-incident history for a named AI model or tool BEFORE invoking it. Unlike every other rai_* tool, which evaluates output the caller itself produced, this one looks up a public record about a THIRD PARTY'S model or tool — built for agents and agent frameworks (LangChain, LangGraph, Google ADK) deciding whether to trust something before calling it. Free, no auth required, exact model+provider match. Queries the hosted ResponsibleAI Trust Index (configurable via the RAI_TRUST_API_BASE environment variable). Returns 'known: false' for anything never assessed — that is not an error, just an absence of data; self-assessment is free at POST /api/trust-index/assess.
rai_compare_models
Compare two AI models across all six trust dimensions. Returns scores for each, delta analysis, and a recommendation on which model is more trustworthy.
rai_compliance
Evaluate AI governance compliance against NIST AI RMF, EU AI Act, or ISO 42001. Returns compliance score, findings per control, and remediation recommendations.
rai_cost_estimate
Estimate the USD cost of a model API call from token counts.
rai_drift_check
Detect trust score drift between a baseline evaluation and a current evaluation. Returns drift delta per dimension, overall drift severity (NONE/LOW/MEDIUM/HIGH/CRITICAL), and whether an alert threshold was breached.
rai_eu_ai_act_classify
Classify an AI system into an EU AI Act risk tier: UNACCEPTABLE, HIGH, LIMITED, or MINIMAL. Evaluates deployment context, capabilities, and affected populations against Annex III and Annex VI criteria. Returns risk tier, applicable articles, required conformity assessment actions, and a compliance roadmap. Used by AI Compliance Managers.
rai_executive_summary
Generate a board-ready executive AI governance summary. Synthesises trust grades, compliance posture, cost intelligence, risk incidents, and drift trends into a C-suite-readable report with RAG (Red/Amber/Green) status indicators. Used by CAIO for quarterly board reporting.
rai_hallucination
Detect hallucination risk in AI-generated text. Analyses hedging language, self-consistency across candidate responses, and unsupported factual claims.
rai_health
Check the status and module availability of the ResponsibleAI governance engine.
rai_incident_log
Create a structured governance incident record. Used by Security Engineers and AI Risk Analysts to log AI safety events (PII leaks, jailbreak attempts, bias triggers, hallucination incidents) for audit trail and SIEM integration.
rai_iso42001_gap
Perform an ISO/IEC 42001:2023 AI Management System gap analysis. Evaluates maturity across all 10 clauses: Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement, plus AI-specific annexes. Returns gap findings, maturity scores per clause, and a prioritised remediation roadmap. Used by AI Compliance Managers.
rai_model_route
Recommend the optimal AI model for a task based on complexity analysis and cost-quality tradeoff. Returns recommended model, alternative, estimated cost per 1K tokens, and estimated savings vs GPT-4o. Used by LLMOps Engineers for intelligent model routing.
rai_org_status
Return a structured governance status snapshot for an organisation. Summarises active models, trust grade distribution, compliance coverage, open risks, and MCP tool usage. Used by CAIO and AI Governance Engineers for dashboards.
rai_passport_generate
Generate a verifiable AI Passport for a model — a tamper-evident governance card containing trust scores, compliance status, bias summary, and a cryptographic verification hash. Used by Procurement/Legal for third-party AI vendor risk assessment.
rai_pii_report
Generate a detailed PII audit report for a document or corpus. Classifies findings by PII category (email, phone, SSN, credit card, IP, address), counts occurrences, computes a privacy risk score, and provides GDPR/CCPA remediation guidance. Used by Privacy Engineers for compliance evidence collection.
rai_policy_check
Evaluate text or a model response against a governance policy. Checks for: prohibited topics, required disclaimers, output length limits, language restrictions, and custom keyword blocklist. Returns pass/fail per policy rule with remediation guidance.
rai_redteam_analyze
Analyse model responses to red team attack payloads. Returns a security report with vulnerability findings, severity breakdown, and an overall security score.
rai_redteam_payloads
Return adversarial attack payloads to probe an AI model for security vulnerabilities. Categories: prompt_injection, jailbreak, data_leakage, role_confusion, delimiter_attack.
rai_scan
Scan text for PII (email, phone, SSN, credit card, IP address) and harmful content (hate speech, violence, self-harm). Returns findings and a redacted copy.
rai_stream_scan
Scan a list of text chunks (as would arrive from an LLM streaming response) for PII and harmful content. Simulates the StreamingScanner guardrail without a live stream. Returns per-chunk scan results and an aggregated summary with stop recommendation.
rai_trust_score
Compute a composite AI Trust Score (0-100) across six governance dimensions: fairness, privacy, security, robustness, compliance, authenticity. Returns score, letter grade (A-F), and risk tier (LOW/MEDIUM/HIGH/CRITICAL).
rai_webhook_status
Check webhook delivery health and generate a structured status report. Takes delivery statistics and returns health grade, failure analysis, dead-letter queue status, and recommended remediation actions. Used by Security Engineers feeding SIEM systems and Platform Engineers debugging webhook pipelines.

Endpoints

URLTransportStateLatencyChecked
https://whitepact-mcp-http.onrender.com/mcp streamable-http sign-in 316 ms 4 min ago
https://whitepact-mcp-http.onrender.com/sse sse answering 287 ms 4 min ago

Alternatives to WhitePact

same job, measured the same way
Vectordecisions MCP Server
by nikitadatar

AI Governance MCP Server - GATRI trust scoring, kill-switch, EU AI Act compliance for Claude

37 installs/wk local only
MCP Agentcore
by geiant

AI governance MCP server for EU AI Act compliance and jurisdiction verification

3 tools answering
Tork Governance
by torkjacobs

AI agent governance for MCP: PII detection, policy enforcement, compliance, and kill switch.

45 installs/wk local only
Federated AI Commons
by toby-self

MCP server for a federated AI-commons governance simulation with a verified compliance oracle.

65 installs/wk local only
Compliance Auditor MCP
by firasmosbehi

City hiring-compliance MCP server with regulation search and full audit risk scoring.

answering
csoai-governance-crosswalk-mcp
by csoai-org

Csoai Governance Crosswalk MCP server. Tools: query crosswalk, crosswalk bridge, compliance gap anal

687 installs/wk local only
Eu AI Act Compliance MCP
by csoai-org

Eu Ai Act Compliance MCP Server by MEOK AI Labs

376 installs/wk local only
EU Audit Trail
by jellewas

Tamper-evident audit trail MCP server for EU AI Act & GDPR compliance.

72 installs/wk local only

WhitePact — questions

Answers built from our own checks of this server.

What can WhitePact do?
It exposes 27 tools, read directly from the server on our last check. Among them: rai_audit_summary, rai_benchmark, rai_benchmark_prompts, rai_bias_evaluate, rai_budget_check, rai_check_trust and 21 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is WhitePact working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 92 of 184 checks got a reply (50.0%), average response time 491 ms. The bar chart above shows every period we have measured.
How do I connect WhitePact?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address. You sign in through your browser once and the client keeps the session: no key to copy, and it refuses anonymous clients.
How do you sign in to WhitePact?
No API key is involved. WhitePact answers our knock with an OAuth challenge, so you authorise it once in your browser and the client keeps the session. That is also why we see no tool list: it will not describe itself to an anonymous client, and that is the server working as intended, not a fault.
How fast is WhitePact?
It answers our handshake in 491 ms on average, which is faster than 29% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
How many people use WhitePact?
The pypi package rai-governance-platform was installed 350 times in the last week. Week over week that is -37%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is WhitePact open source?
Yes — it is published under the MIT licence, written in Python, 1 stars on GitHub and 7 open issues. The source link is on this page, so you can read exactly what it does with your data before you connect it.