Current · Open source
SurfacePin
Pin the surface. Catch the silent drift.
An exact hash of an MCP server’s tools, resources, and prompts. The check is not semantic. When the surface changes and the pin does not, CI fails.
Not a runtime proxy. Lockfile v3 explains a mismatch with a deterministic field-diff: COMPATIBLE|BREAKING|HINT_FLIP. Those labels do not decide pass or fail. HINT_FLIP is a client-hint change, not a safety verdict.
01
Pin
Record an exact hash of the MCP tools, resources, and prompts.
02
Check
Compare the live surface with the pin.
03
Fail
An unexpected change fails CI until the pin is updated.
- Exact hash of tools, resources, and prompts
- Fails CI on unexpected surface change
- MIT · CLI · CI-ready
FAQ
Questions
Is the check semantic?
No. SurfacePin uses an exact hash. A changed character changes the digest. The check is not semantic, and it does not use embeddings or an LLM.
Is SurfacePin a runtime proxy?
No. It is not a runtime proxy, and it does not sit on the MCP request path. Verify from a JSON file is offline. Optional stdio only lists the server when you lock or check.
What is COMPATIBLE|BREAKING|HINT_FLIP?
Explanatory labels on a lockfile v3 field-diff. COMPATIBLE|BREAKING|HINT_FLIP does not change the exit code. A digest mismatch fails CI. A match passes. HINT_FLIP is a client-hint change, not a safety verdict.
Which lists are pinned?
tools/list, resources/list, and prompts/list. Resource templates and initialize.instructions are not pinned.
Which lockfiles still verify?
v1, v2, and v3. New locks are written as v3. Re-lock after upgrading to 1.4 so the digest includes annotations and outputSchema.