pcrzero-mcp
by Scytalex-LLC
README.md
# PCRZERO — MCP server
Issue and verify **signed receipts for agent actions** from any MCP-speaking agent.
PCRZERO adjudicates an attestation document against a policy and hands back a
cryptographically signed receipt pair — durable, independently checkable proof that
this decision was made, by these keys, over this document. Anyone can verify a receipt,
offline, without an account and without trusting us.
- **Website:** [pcrzero.com](https://pcrzero.com)
- **Sign up / API keys:** [pcrzero.com/signup](https://pcrzero.com/signup)
- **API:** `api.pcrzero.com`
## Install
Add the server to your MCP client. The package runs over stdio — your agent host
launches it; nothing listens on a port.
**Claude Code**
```bash
claude mcp add pcrzero -e PCRZERO_API_KEY=<your-key> -- npx -y @scytalex-llc/pcrzero-mcp
```
**Claude Desktop / any JSON-configured MCP client**
```json
{
"mcpServers": {
"PCRZERO": {
"command": "npx",
"args": ["-y", "@scytalex-llc/pcrzero-mcp"],
"env": { "PCRZERO_API_KEY": "<your-key>" }
}
}
}
```
No key yet? **Leave `env` out.** `verify_receipt` and `get_keyset` work with no API key
and no account — only the paid tool needs one.
Requires Node 22 or later.
## The three tools
| Tool | Cost | What it does |
| --- | --- | --- |
| `issue_receipt` | **Metered** — bills one `receipt_verifications` unit per call | Adjudicates an attestation document against a policy on the live API and returns the verdict with a signed receipt pair. A `fail` verdict bills exactly like a `pass`: you are paying for the adjudication, not for the answer you wanted. The only tool here that spends. |
| `verify_receipt` | **Free, and it stays free** | Checks a PCRZERO receipt pair against the signing keyset: whether the signature holds, and whether the receipt says what it appears to say. Offline by default — supply `keyset` and this call touches the network not at all; omit it and the server fetches the public keyset once. `keyset_source` in the result tells you which happened, every time. |
| `get_keyset` | Free | Returns the current PCRZERO signing keyset — key ids, public halves, each key’s status. Public and unauthenticated. The same document an outside party fetches to check a receipt without trusting us. |
Current pricing is published at [pcrzero.com](https://pcrzero.com) — it is deliberately
not baked into this README or into any tool description.
## Auth, exactly
`PCRZERO_API_KEY` in the server’s environment, via your MCP client configuration. It is
sent as `Authorization: Bearer` on `issue_receipt` calls and used nowhere else: the key
never appears in tool results, error text, or logs — not even redacted. With no key
configured, `issue_receipt` refuses cleanly (`auth_missing`) and the two free tools keep
working.
API errors pass through verbatim (`code`, `message`, `request_id`). This server never
rewrites, retries, or softens a billing refusal.
## Verify without trusting us
A PCRZERO receipt is checkable by anyone holding the public keyset — including people
who are not our customers and never will be. Call `get_keyset` once (or fetch
`https://api.pcrzero.com/v1/keys` yourself), pin it, and `verify_receipt` runs entirely
offline from then on. If we disappeared tomorrow, every receipt ever issued would still
verify.
## Transport & scope
stdio only. No listen socket, no state, no receipt storage, no key-management tools —
key management is a human path at [pcrzero.com](https://pcrzero.com) by design.
---
Proprietary — © Scytalex LLC. The receipt verification path is free to use for anyone,
forever.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessSyncing