Skip to main content
Glama
Scytalex-LLC

pcrzero-mcp

by Scytalex-LLC

PCRZERO — MCP server

Issue and verify signed receipts for agent actions from any MCP-speaking agent. PCRZERO adjudicates an attestation document against a policy and hands back a cryptographically signed receipt pair — durable, independently checkable proof that this decision was made, by these keys, over this document. Anyone can verify a receipt, offline, without an account and without trusting us.

Install

Add the server to your MCP client. The package runs over stdio — your agent host launches it; nothing listens on a port.

Claude Code

claude mcp add pcrzero -e PCRZERO_API_KEY=<your-key> -- npx -y @scytalex-llc/pcrzero-mcp

Claude Desktop / any JSON-configured MCP client

{
  "mcpServers": {
    "PCRZERO": {
      "command": "npx",
      "args": ["-y", "@scytalex-llc/pcrzero-mcp"],
      "env": { "PCRZERO_API_KEY": "<your-key>" }
    }
  }
}

No key yet? Leave env out. verify_receipt and get_keyset work with no API key and no account&nbsp;— only the paid tool needs one.

Requires Node&nbsp;22 or later.

Related MCP server: agent-receipts-mcp

The three tools

Tool

Cost

What it does

issue_receipt

Metered — bills one receipt_verifications unit per call

Adjudicates an attestation document against a policy on the live API and returns the verdict with a signed receipt pair. A fail verdict bills exactly like a pass: you are paying for the adjudication, not for the answer you wanted. The only tool here that spends.

verify_receipt

Free, and it stays free

Checks a PCRZERO receipt pair against the signing keyset: whether the signature holds, and whether the receipt says what it appears to say. Offline by default&nbsp;— supply keyset and this call touches the network not at all; omit it and the server fetches the public keyset once. keyset_source in the result tells you which happened, every time.

get_keyset

Free

Returns the current PCRZERO signing keyset&nbsp;— key ids, public halves, each key’s status. Public and unauthenticated. The same document an outside party fetches to check a receipt without trusting us.

Current pricing is published at pcrzero.com&nbsp;— it is deliberately not baked into this README or into any tool description.

Auth, exactly

PCRZERO_API_KEY in the server’s environment, via your MCP client configuration. It is sent as Authorization: Bearer on issue_receipt calls and used nowhere else: the key never appears in tool results, error text, or logs&nbsp;— not even redacted. With no key configured, issue_receipt refuses cleanly (auth_missing) and the two free tools keep working.

API errors pass through verbatim (code, message, request_id). This server never rewrites, retries, or softens a billing refusal.

Verify without trusting us

A PCRZERO receipt is checkable by anyone holding the public keyset&nbsp;— including people who are not our customers and never will be. Call get_keyset once (or fetch https://api.pcrzero.com/v1/keys yourself), pin it, and verify_receipt runs entirely offline from then on. If we disappeared tomorrow, every receipt ever issued would still verify.

Transport & scope

stdio only. No listen socket, no state, no receipt storage, no key-management tools&nbsp;— key management is a human path at pcrzero.com by design.


Proprietary&nbsp;— © Scytalex LLC. The receipt verification path is free to use for anyone, forever.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Gives AI agents verifiable, tamper-evident receipts for their actions — attest_action signs a cryptographic receipt for what the agent did (email sent, payment made, form filed), verify_receipt checks it offline, get_identity returns the agent's did:key. Sign locally, verify anywhere, zero backend.
    3
    111 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Provides tools to issue, verify, and export cryptographically signed receipts for AI agent actions, enabling tamper-proof audit trails for compliance with regulations like the EU AI Act.
    4
    64 npm
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Issues accountable identities for AI agents before they interact with tools, with tools for identity management and receipt export.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to create cryptographically verifiable receipts of their delegated work, with capabilities for multi-party approval and offline verification.
    11
    54 npm
    Apache 2.0