← Discover MCPs and Agents
A
MCPAI & MLMCP Registry

AI Act Radar

EU AI Act obligations and updates from ten official sources, incl. the national layer.

Links

README

From the repo.

aiactradar-examples

Reference webhook receivers for AI Act Radar. Each subdirectory is a self-contained, runnable example for one platform.

What every receiver does

  1. Reads the raw request body (signature is over the bytes, not the parsed JSON).
  2. Verifies X-AIAR-Timestamp is within 300 seconds of now.
  3. Verifies X-AIAR-Signature (v1=<hex>) using HMAC-SHA-256 over <timestamp>.<raw_body> in constant time.
  4. Checks an idempotency key (event.id) before doing real work — retries are normal.
  5. Returns 2xx within 5 seconds; otherwise the dispatcher retries with exponential backoff.

The verification is identical across platforms; only the platform glue differs.

Examples

FolderPlatformNotes
cloudflare-workers/Cloudflare WorkersWeb Crypto API, KV for idempotency
vercel-edge/Vercel Edge FunctionsWeb Crypto API, Vercel KV for idempotency
aws-lambda/AWS Lambda + API GatewayNode crypto module, DynamoDB for idempotency
express-node/Plain Express on NodeNode crypto, in-process LRU (replace for prod)
fastify-typescript/Fastify + TSTyped body parser, raw-body capture
deno-deploy/Deno DeployDeno KV for idempotency

Try it without signing up

Each example has a test.sh that signs a sample event with a local secret and posts it to the running receiver. You can run the full loop on your laptop in under five minutes:

cd cloudflare-workers
cp .dev.vars.example .dev.vars   # set AIA_SECRET to anything
npm install && npm run dev       # starts http://localhost:8787
# in another terminal:
bash test.sh                     # posts a signed sample event

Going to production

  • Store AIA_SECRET in your platform's secret manager. Never commit it.
  • Rotate the secret in the AI Act Radar dashboard at least every 90 days.
  • Subscribe to the dispatcher's webhook health channel — bounced deliveries surface there before customers notice.
  • Idempotency stores need a TTL of at least 7 days; the dispatcher retries up to 24h.

License

MIT.


AI Act Radar is operated by ligea GmbH, Karlsruhe. Information only — not legal advice.

Config for your environment

Use the endpoint URL below in your config. No API key — you connect directly.

Tool

OS

Config file: ~/.cursor/mcp.json

{
  "mcpServers": {
    "mcp-server": {
      "url": "https://mcp.aiactradar.com/mcp/v1"
    }
  }
}

Paste into mcpServers in the config file. Restart Cursor after saving.

If this MCP is also published on mcpchannel.ai, you can subscribe from Browse and use the gateway config there instead.