Skip to main content
Glama

costwright — MCP server

Static worst-case token-budget analysis for LLM-agent workflows. Point it at a Python repo using LangGraph / CrewAI / OpenAI-Agents-SDK and it reports — by pure AST analysis, without running the code — the worst-case budget ceiling of every workflow graph: which units are certifiable / default-dependent / non-certifiable / runaway, and which LLM calls have no token cap. Optionally issues an Ed25519-signed budget certificate logged to a public transparency log. Wraps the hosted costwright API; backed by a Lean 4 cost-soundness theorem.

Use it before deploying an agent workflow to catch missing token caps and while True: runaway drivers — the budget version of a type check.

Tools

Tool

What it does

Key?

costwright_check(repo_path, policy?)

Static budget analysis of a local repo. Returns pass/fail + counts of certifiable/default-dependent/non-certifiable/runaway units.

yes

costwright_certify(repo_path, policy?, label?)

Issues a signed, logged budget certificate. Returns cert_id + signature + verify_url.

yes

costwright_verify(cert_id)

Verify a certificate by id (valid/expired/revoked, signature check).

public

costwright_pubkey()

Active Ed25519 public keys for offline verification.

public

Related MCP server: cycles-mcp-server

Setup

{
  "mcpServers": {
    "costwright": {
      "command": "npx",
      "args": ["-y", "costwright-mcp"],
      "env": { "COSTWRIGHT_API_KEY": "your_rapidapi_key" }
    }
  }
}

The key is sent as X-RapidAPI-Key (RapidAPI channel) by default; set COSTWRIGHT_DIRECT=1 to send it as Authorization: Bearer for the direct channel. verify and pubkey work with no key.

check/certify build a .py-only gzip archive of repo_path client-side (excluding venv, node_modules, tests, etc.) and send it for analysis — your source is uploaded to the hosted API. See https://eleata.io/privacy/. MIT licensed.

Install Server
A
license - permissive license
A
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    A
    maintenance
    TACIT (Tracked Agent Capabilities In Types) is a safety harness for AI agents. Instead of calling tools directly, agents write code in Scala 3 with capture checking: a type system that statically tracks capabilities and enforces that agent code cannot forge access rights, cannot perform effects beyond its budget, and cannot leak information from pure sub-computations. It provides an MCP interface,
    69
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Runtime budget authority for autonomous agents - a set of tools to check, reserve, spend, and release budget before and after every costly, risky operation. The agent asks "can I afford this?" before acting, and reports what it actually used afterward.
    9
    118
    Apache 2.0
  • A
    license
    -
    quality
    C
    maintenance
    A deterministic AST evidence engine that forces AI agents to debug using verified execution facts instead of pattern-matching symptoms, enabling hallucination-free debugging for MCP-compatible agents.
    6
    Business Source 1.1

View all related MCP servers

Related MCP Connectors

  • Agent Token Budget MCP — hard per-session token + spend cap with signed budget-exhausted

  • Agentic workflow budget approvals with usage receipts.

  • Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/hernaninverso/costwright-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server