Caf MCP Server

MCP server for Caf - Brazilian identity + Trust Platform. KYC/KYB, face authentication + liveness, document validation + OCR, and orchestrated onboarding flows. Direct competitor to Unico / IDwall / Certta; their Trust Platform chains multi-step identity verifications with policy rules. Its 9 documented tools cover check, trust, platform.

People connecting security tools to Claude, Cursor, VS Code, or another MCP client. The project is written in JavaScript.

One of 127 MCP servers published from codespar/mcp-dev-latam. Stars and repository activity are shared across all of them. See all 127 →

VERIFIED ACTIVE

LAST COMMIT 2026-08-12 · VERIFIED 2026-08-25

MIT · JavaScript servers · how we verify → /methodology

01 · Install Caf

before you install - you'll need

CAF_API_KEY

Environment variables documented in the project's README - it lists which are required and which have defaults.

Claude Code

claude mcp add codespar-mcp-dev-latam-packages-identity -- npx -y @codespar/mcp-caf

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "codespar-mcp-dev-latam-packages-identity": {
      "command": "npx",
      "args": [
        "-y",
        "@codespar/mcp-caf"
      ]
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as local process (stdio) - runs on your machine with your user's permissions

license MIT - declared in the repository

npm package @codespar/mcp-caf - published under the repo owner's npm scope (@codespar)

registry namespace io.github.codespar is GitHub-verified and matches the repo owner

03 · What Caf can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

What you can build

With this server connected, an agent can post /v1/checks/person, post /v1/checks/company, post /v1/biometrics/face, and post /v1/biometrics/liveness.

Capability map

Tools grouped from the project's README - what Caf lets an agent do.

Trust

2 tools - e.g. POST /v1/trust/flows; GET /v1/trust/flows/{flow_id}

trust_platform_start · trust_platform_get

read & search

2 tools - e.g. GET /v1/datasources; GET /v1/checks/{check_id}

list_datasources · get_check_result

Person

1 tool - e.g. POST /v1/checks/person

person_check

Company

1 tool - e.g. POST /v1/checks/company

company_check

auth & access

1 tool - e.g. POST /v1/biometrics/face

face_authentication

Liveness

1 tool - e.g. POST /v1/biometrics/liveness

liveness_check

Document

1 tool - e.g. POST /v1/checks/document

document_check

04 · Who maintains Caf

mcp-caf is maintained by codespar. We track 127 MCP servers from codespar - 127 actively maintained, 269 combined GitHub stars, oldest repo from Mar 2026. Full record: all servers from codespar.

  1. mcp-asaas MCP server for Asaas - billing automation, Pix, boleto, credit card, subscriptions ★ 269
  2. mcp-omie MCP server for Omie - ERP, customers, products, orders, invoices, financials ★ 269
  3. mcp-sendgrid MCP server for SendGrid - global transactional + marketing email (Twilio-owned) ★ 269
  4. mcp-evolution-api MCP server for Evolution API - WhatsApp messaging, instances, contacts ★ 269
  5. mcp-stripe-acp Stripe ACP - AI agent checkout, payment delegation, products, invoices ★ 269
  6. mcp-mercado-bitcoin MCP server for Mercado Bitcoin - Brazilian crypto exchange, trading, orderbook, withdrawals ★ 269

05 · Facts

category
security - actively maintained as of 2026-08-25.
registry
io.github.codespar/mcp-caf (active, first published 2026-06-20 · 2 versions)
packages
npm:@codespar/mcp-caf

06 · Caf FAQ

Is Caf still maintained?

Yes - as of 2026-08-25, its last commit was 2026-08-12. We re-verify nightly.

What can Caf do?

With this server connected, an agent can post /v1/checks/person, post /v1/checks/company, post /v1/biometrics/face, and post /v1/biometrics/liveness.

How do I install Caf?

Run `npx -y @codespar/mcp-caf`. The README documents one environment variable (CAF_API_KEY) to set first. You can also paste the ready-made client config above.

Does Caf run locally?

Yes - it's a stdio server: it runs on your machine (via npx) with your user's permissions. Your data stays local unless the server itself calls external APIs.

07 · Alternatives to Caf

More security MCP servers · Izipay · Niubiz · Rede · Worldpay · Argus Decision MCP

More JavaScript MCP servers · Certta · Jumio · Onfido · Persona · Unico · see all