Trustmesh
БесплатноНе проверенAgentic AI fraud prevention for African mobile money. 6 CAMARA APIs via Nokia Network as Code with hash-chained audit. Africa Ignite Hackathon 2026 (GSMA + Noki
Описание
Agentic AI fraud prevention for African mobile money. 6 CAMARA APIs via Nokia Network as Code with hash-chained audit. Africa Ignite Hackathon 2026 (GSMA + Nokia).
README
AI-Orchestrated Network Trust Scores for Africa's Mobile Money Economy
TrustMesh is an agentic AI fraud-prevention platform that orchestrates 6 CAMARA APIs through Nokia's Network as Code to produce a real-time composite trust score for every mobile money transaction — with tamper-evident audit certificates regulators can independently verify.
Africa Ignite Hackathon 2026 — GSMA + Nokia Theme 6 (Open Innovation) · Team
akhona_3761
The problem
Across Africa, mobile money fraud costs around $4 billion every year. Roughly 70% of it involves a SIM swap, device change, or stolen identity — signals operators already have, but no one stitches together at the moment of risk.
Mama Thandi runs a spaza shop in Khayelitsha. Last month a customer asked her to send R10 000 — the SIM had been swapped four hours earlier. The transfer cleared. The money was gone. TrustMesh exists so that the next R10 000 doesn't.
How it works
Transaction → Orchestrate 6 CAMARA APIs → Composite trust score (0–100)
→ Decision: APPROVE / FLAG / BLOCK
→ LLM-explained reasoning
→ Hash-chained audit certificate
| Signal | Weight | Source |
|---|---|---|
| SIM Swap | 30% | CAMARA SIM Swap API |
| Device Swap | 20% | CAMARA Device Swap API |
| KYC Match | 20% | CAMARA KYC Match API |
| Number Verification | 10% | CAMARA Number Verification (OIDC) |
| Location Verification | 10% | CAMARA Location Verification API |
| Device Status | 10% | CAMARA Device Status API |
Every decision is locally validated against domain-specific intents and recorded in a hash-chained audit chain. The audit certificate from a USSD call is the same certificate a regulator inspects via REST — provable consistency across channels.
Four channels, same engine
| Channel | Audience | Status |
|---|---|---|
| REST API | Fintechs, mid-market lenders | Live |
| USSD | Spaza shops, anyone with a feature phone | Live (Africa's Talking) |
| OIDC | User-bound number verification flows | Live |
| MCP | AI agents (Claude Desktop, Cursor) | Live (3 tools) |
# REST
curl -X POST http://localhost:8000/api/v1/trust-score \
-H "Content-Type: application/json" \
-d '{"msisdn": "+99999991000", "amount": 10000, "type": "p2p"}'
# USSD (Africa's Talking simulator)
*384*1#
# MCP (in Claude Desktop config)
{
"mcpServers": {
"trustmesh": {
"command": "python",
"args": ["/path/to/trustmesh/scripts/run_mcp_server.py"]
}
}
}
Quick start
git clone https://github.com/labrat-akhona/trustmesh.git
cd trustmesh
uv sync
cp .env.example .env # then fill in keys
uv run pytest # 116 tests should pass
uv run uvicorn trustmesh.main:app --reload
# Dashboard (separate terminal)
cd frontend && npm install && npm run dev # → http://localhost:5173
Demo mode (offline, no network needed)
Set MOCK_NAC_MODE=true in your .env. The orchestrator returns deterministic
fixtures captured from the Nokia sandbox. Useful for live demos where network
reliability matters more than fresh data.
Test against the Nokia sandbox
# Fraud scenario (returns score ~27, BLOCK)
curl -X POST http://localhost:8000/api/v1/trust-score \
-H "Content-Type: application/json" \
-d '{"msisdn": "+99999991000", "amount": 10000, "type": "p2p"}'
# Legitimate scenario (returns score ~71, APPROVE)
curl -X POST http://localhost:8000/api/v1/trust-score \
-H "Content-Type: application/json" \
-d '{"msisdn": "+99999991001", "amount": 500, "type": "p2p"}'
Privacy & compliance
- POPIA-compliant by design. Phone numbers are never logged at INFO level — only truncated SHA-256 hashes (
phone_hash=ab12cd34). - CAMARA Number Verification cache-only architecture. OIDC flow is user-bound per spec; tokens never persist beyond cache TTL.
- Audit certificates are cryptographic. Hash-chained, tamper-evident, third-party verifiable via
/api/v1/audit/verify. - No PII in cross-channel data. MCP server, REST decisions feed, and operator dashboard return audit metadata only.
Project status
| Build phase | Apr 24 – May 10 2026 |
| Showcase round | May 11–12 2026 (live online pitch) |
| Tests passing | 126 / 126 |
| Channels live | 4 (REST, USSD, OIDC, MCP) |
| Latest tag | v0.4.0-prototype |
Roadmap
| Phase | Status |
|---|---|
| Phase 1 — Core engine + REST API | ✅ Shipped |
| Phase 2 — OIDC Number Verification | ✅ Shipped |
| Phase 2.5 — Semantic LLM governance (semantix-ai) | ✅ Shipped |
| Phase 2.7 — MCP Server | ✅ Shipped |
| Phase 4 — USSD via Africa's Talking | ✅ Shipped |
| Phase 6 — React operator dashboard | ✅ Shipped |
| Phase 7 — Demo video + final polish | 🔜 May 7–10 |
| Phase 5 — WhatsApp via Twilio | 🔮 Future work |
Stack
FastAPI · Pydantic v2 · network-as-code SDK · claude-sonnet-4-20250514 · semantix-ai · Africa's Talking · mcp Python SDK · React 18 · TypeScript · Vite · Tailwind · TanStack Query · pytest · ruff · mypy
Why this matters
Mobile money is the rails of African commerce. When those rails leak, real people lose real savings — and the leak isn't a technology problem we don't know how to solve, it's a coordination problem between data the operator already has.
TrustMesh is the coordination layer. One trust engine. Four channels. Three integration tiers — from spaza shop owners on USSD, to fintechs on REST, to operators on a regulator-ready dashboard.
Built for Africa, by someone in Africa, on infrastructure designed for the continent.
License
MIT
Author
Akhona Eland — Cape Town, South Africa github.com/labrat-akhona · [email protected]
Built solo for the Africa Ignite Hackathon 2026.
Установка Trustmesh
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/labrat-akhona/trustmeshFAQ
Trustmesh MCP бесплатный?
Да, Trustmesh MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Trustmesh?
Нет, Trustmesh работает без API-ключей и переменных окружения.
Trustmesh — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Trustmesh в Claude Desktop, Claude Code или Cursor?
Открой Trustmesh на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectCompare Trustmesh with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
