MCP servers and tools, vetted.
Joch Marketplace is the curated catalog of MCP servers and tools that your agents can pull. Every entry has a security review, signed artifacts, an SLA, and a clear capability declaration — so you stop discovering tools by name in a wiki.
// Capabilities
Security review
01Every server reviewed for capability scope, network exposure, supply chain, and known CVEs before listing.
Signed artifacts
02Cosign signatures and content-addressed digests; your registry mirror only pulls verified bytes.
Capability declarations
03Each entry declares which tools it exposes, which scopes it needs, and what side effects it can produce.
SLA-backed listings
04Marketplace partners commit to availability and response targets — escalation paths are part of the contract.
// What's included
- Curated MCP server catalog
- Curated tool catalog
- Cosign-signed packages
- Capability + scope declarations
- Security review attestations
- Quarantine and recall channel
- Mirror mode for airgap pulls
- Vendor SLAs and escalation
// Operator's view
Harness this surface today.
Install the open-source core or start on Cloud — same control plane, same audit trail.