---
title: "Trooth command-line tool 0.12.0: MCP tool fingerprints, more of the public record, and a hardware key for the log: Trooth changelog - Trooth"
description: "Trooth now fingerprints the tools Model Context Protocol (MCP) servers list and enters every change in its log, the public record adds federal contracting, patents, state registers, merger review and the domain's registration, and every checkpoint of the log is also signed by a key held in hardware."
canonical_url: "https://trooth.co/changelog/2026-10-07-cli-0-12-0-mcp-tools"
markdown_url: "https://trooth.co/changelog/2026-10-07-cli-0-12-0-mcp-tools.md"
generated_from: "the rendered page, converted to Markdown when this was requested"
agent_index: "https://trooth.co/llms.txt"
---

[Back to changelog](https://trooth.co/changelog)

New

October 7, 20262 minute read

# Trooth command-line tool 0.12.0: MCP tool fingerprints, more of the public record, and a hardware key for the log

Trooth now fingerprints the tools Model Context Protocol (MCP) servers list and enters every change in its log, the public record adds federal contracting, patents, state registers, merger review and the domain's registration, and every checkpoint of the log is also signed by a key held in hardware.

## What changed

Once a day Trooth reads the tool list of each MCP server it follows, with no credentials, fingerprints each tool's description and its whole definition, and signs and logs a statement naming the list whenever it changes, so the log holds each server's history of tool changes. trooth mcp-tools checks those fingerprints, the statement and its log entry, and with --live compares them with what the server lists now. The public record reading adds federal contractor registrations and exclusions from SAM.gov, patent applications from the USPTO, entries with the exact legal name in the New York, Colorado, Connecticut and Oregon business registers, FTC early termination notices under the Hart-Scott-Rodino Act, the domain's registration, the changes those sources record, and every subject the reading names. Every checkpoint of the log now carries a second signature by a key generated inside AWS Key Management Service, which never leaves its hardware; trooth log checkpoint says whether it is there.

## Why it changed

An agent decides what a tool does from the description its server lists, and a server can change that description after it was reviewed without telling anyone. A fingerprint in a public log makes the change visible. A log key held only in software can be copied; a key that never leaves a hardware module cannot.

## Who is affected

- **Affected:** Anyone connecting an agent to an MCP server, anyone relying on a company's public record, and anyone watching the log.
- **Availability:** npm, as trooth 0.12.0; on Trust Profiles, in the Identity section. No account.
- **Release stage:** Available.
- **Areas:** CLI, API.

## What to do

**No action required.** Nothing is required. Run trooth mcp-tools with a server's address and --live to see whether it still lists the tools Trooth recorded.

## Versions and migration

- **trooth:** `0.12.0`

## Dates

- **Announced:** October 7, 2026, the day this entry was written. Entries are never backdated.
- **Released:** October 7, 2026.

## What this does not fix

A fingerprint says what a server listed, not what a tool does. A name match in SAM.gov, a state register or a merger notice is not an identification. SAM.gov is read for a few names a day, and only once Trooth holds its key; the USPTO likewise. The witnesses still follow the software key, and one person administers both keys; Trooth has no second approver, and docs/KEY-CEREMONY.md says what stands in its place.

## Read more

- [MCP tool fingerprints in the CLI reference](https://trooth.co/docs/cli#mcp-tools)
- [The hardware key ceremony](https://github.com/troothllc/trooth-cli/blob/main/docs/KEY-CEREMONY.md)

On this page

- What changed
- Why it changed
- Who is affected
- What to do
- Versions and migration
- Dates
- What this does not fix
- Read more

[New](https://trooth.co/changelog?type=new)[CLI](https://trooth.co/changelog?area=cli)[API](https://trooth.co/changelog?area=api)

[Back to changelog](https://trooth.co/changelog)

## Related changes

- [OCT.07NewTrooth command-line tool 0.11.0: witnesses for the log, and a signed public recordCLI +1](https://trooth.co/changelog/2026-10-07-cli-0-11-0-witnesses)
- [OCT.07NewTrooth command-line tool 0.10.0: what a company published outside its own siteCLI +1](https://trooth.co/changelog/2026-10-07-cli-0-10-0-public-record)
- [OCT.06NewTrooth command-line tool 0.9.0: a public log of every signed readingCLI +1](https://trooth.co/changelog/2026-10-06-cli-0-9-0-log)
- [OCT.06NewTrooth command-line tool 0.8.0: bundles, statement v3, schemas and librariesCLI +1](https://trooth.co/changelog/2026-10-06-cli-0-8-0-bundles)
- [OCT.06NewTrooth command-line tool 0.7.0: check a signed reading yourselfCLI](https://trooth.co/changelog/2026-10-06-cli-0-7-0-verify)
- [OCT.05NewAgents can read your own workspace record after sign-inAPI +1](https://trooth.co/changelog/2026-10-05-signed-in-agent-access)

## Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

## Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

Email address

[RSS](https://trooth.co/changelog/rss.xml)[CLI only](https://trooth.co/changelog/rss.xml?area=cli)[Needs action](https://trooth.co/changelog/rss.xml?action=required)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://trooth.co/#org",
      "name": "Trooth",
      "legalName": "Trooth, LLC",
      "alternateName": [
        "Trooth, LLC",
        "Trooth Network",
        "trooth.co"
      ],
      "url": "https://trooth.co",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://trooth.co/#logo",
        "url": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "contentUrl": "https://trooth.co/brand/trooth-mark_black-on-white_1024.png",
        "width": 1024,
        "height": 1024,
        "caption": "Trooth"
      },
      "image": {
        "@id": "https://trooth.co/#logo"
      },
      "description": "Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust. The Trooth Network keeps one current Machine-Readable Trust Profile per company, each fact sourced. Trooth signs what it witnessed; company declarations are unsigned.",
      "foundingDate": "2025-12-16",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "777 Brickell Ave, Suite 500, PMB 1174",
        "addressLocality": "Miami",
        "addressRegion": "FL",
        "postalCode": "33131",
        "addressCountry": "US"
      },
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "email": "hello@trooth.co",
        "url": "https://trooth.co/contact"
      },
      "sameAs": [
        "https://x.com/Troothllc",
        "https://github.com/troothllc",
        "https://www.crunchbase.com/organization/trooth",
        "https://www.wikidata.org/wiki/Q141292994",
        "https://www.youtube.com/@Troothllc",
        "https://www.trustpilot.com/review/trooth.co"
      ]
    },
    {
      "@type": "WebSite",
      "@id": "https://trooth.co/#website",
      "url": "https://trooth.co",
      "name": "Trooth",
      "alternateName": "Trooth Network",
      "inLanguage": "en",
      "publisher": {
        "@id": "https://trooth.co/#org"
      },
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://trooth.co/network?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@type": "ItemList",
      "@id": "https://trooth.co/#sitelinks",
      "name": "Trooth sitelinks",
      "itemListElement": [
        {
          "@type": "SiteNavigationElement",
          "position": 1,
          "name": "Join Trooth for free",
          "url": "https://trooth.co/signup"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 2,
          "name": "Company, Trooth",
          "url": "https://trooth.co/network/company/trooth"
        },
        {
          "@type": "SiteNavigationElement",
          "position": 3,
          "name": "Trooth Network",
          "url": "https://trooth.co/network"
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://trooth.co/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Changelog",
      "item": "https://trooth.co/changelog"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Trooth command-line tool 0.12.0: MCP tool fingerprints, more of the public record, and a hardware key for the log",
      "item": "https://trooth.co/changelog/2026-10-07-cli-0-12-0-mcp-tools"
    }
  ]
}
```
