Tool Integrity for MCP: Digest Pinning in MCP Hangar v1.2
May 11, 2026 • MCP Hangar Team
v1.2 introduces SHA-256 digest pinning for MCP tool schemas, implementing a preemptive version of SEP-1766 to detect drift and block unauthorized mutations.
v1.2 introduces SHA-256 digest pinning for MCP tool schemas, implementing a preemptive version of SEP-1766 to detect drift and block unauthorized mutations.
v1.2 implements SEP-1763 P1: hook-based event model, wildcard subscriptions, IMutator contract with priority-ordered pipeline, and interceptors/list endpoint.
v1.1 adds per-tool-call cost tracking, SIEM-ready compliance export (Splunk, Datadog, Sentinel), and end-to-end caller identity in every OTEL span.
Security hardening release: SSRF protection, default-deny command allow-list, granular RBAC, WebSocket origin validation, and trusted proxy resolution.
MCP Hangar v1.0 ships identity propagation, compliance-grade audit, Kubernetes enforcement, and sub-millisecond proxy overhead.