council
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@councilAsk Codex this same question and cross-examine the disagreements."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
council
Council is a local MCP server that lets the assistant you are talking to consult another vendor's assistant through your own CLIs and Gemini API key. It runs consultations as durable background jobs, returns independently produced answers for you and your assistant to assess, and records usage in a local ledger.
Claude Desktop / Claude Code / Codex app or extension
-> stable launcher -> stdio MCP server per host
-> detached runner per job
-> Claude / Codex / Gemini API / echo
<- results on disk <- council_pollStatus
Version 0.1.1 implements eight tools, the complete installer command set, three host registrations, multiple profiles, journalled recovery, git/zip updates and manifest-based uninstall. Windows is implemented. macOS/Linux ship stubs: diagnostics and permitted reads work, but starting consultations, active polling and cancellation require implemented process supervision. Terminal results remain readable. See CHANGELOG.
Related MCP server: Senior Consult MCP
What it is not
Council is not a hosted service, chat UI, account switcher or shared-subscription service. It ships no vendor CLI and does not automate vendor login. An agreement between assistants is not proof: check the shared claim before calling it verified. Read NOTICE before using third-party services.
Requirements
Windows, Node 20.11 or newer, and the vendor CLI/account or Gemini key for the
legs you use. Node 24 is the tested path; the launcher on the older enforced
floor remains unverified. Ripgrep is required for search. Echo requires no
vendor account. VERSIONS lists actual capability checks.
install-prereqs offers attended Node/Claude Code/Codex installation after
Node is available to run the setup wrapper.
Install
From an extracted release or checkout outside your vault:
bin\council-setup.cmd detect --vault "C:\Users\<you>\Vault"
bin\council-setup.cmd plan --vault "C:\Users\<you>\Vault"
bin\council-setup.cmd apply --plan "<file printed by plan>"
bin\council-setup.cmd verify
bin\council-setup.cmd loginReview the plan and confirm apply in your terminal. Apply downloads nothing.
Fully quit and restart Claude Desktop after registration and add the supplied
project instructions. For Gemini, follow with bin\council-setup.cmd set-key:
hidden input is validated and stored under the profile's DPAPI-protected
runtime secrets directory. See INSTALL for writes, exit
codes, login guidance and regional billing information via NOTICE.
Your vault
Council adopts your folder in place. It adds a path-free .council/vault.json
contract, missing rules files or marked rule blocks, and work directories.
Conventions add inbox/shared/output/index files by default for a fresh or
empty vault; answers-file conventions:false disables them, and
--conventions enables them on an existing vault. Jobs and ledger
default to the vault and can be relocated. It never moves existing notes,
reorders your index, deletes duplicates or installs executable code in the vault.
Existing files are backed up whole outside the vault before edits; conflicting
user edits are kept. See VAULT-CONTRACT.
Where things live
Zone | Example | Purpose |
Z0 |
| Installed runtime and stable launcher |
Z1 |
| Machine/profile config, manifests, journal and backups |
Z2 |
| Scratch, secrets, and jobs/ledger when relocated |
Z3 |
| Your notes, rules, tasks and default jobs/ledger |
Use --profile <id> consistently for several vaults. Profiles share the
installed application and shared skill; each owns its configuration and
runtime. Keep Z0/Z1 outside agent write grants. See CONFIG.
The eight tools
Tool | Purpose |
| Start one consultation or a fan-out |
| Wait for progress or read results; default wait 40 seconds, maximum 45 |
| Single-leg blocking convenience; degrades to a job ID when its host window ends |
| Cancel a job and its process tree |
| Find recent jobs across hosts |
| Ripgrep content search inside your vault |
| Zero-quota diagnostics and optional version probes |
| Inspect local usage, estimates and refusals |
Arguments, result shapes, paging and untrusted-output framing are in INTERFACES. Long consultations should use start/poll.
The four legs
Leg | Execution | Usage |
Claude | Official Claude Code CLI in restricted scratch context | Your vendor account |
Codex | Official CLI with ignored user rules/config and read-only sandbox | Your vendor account |
Gemini API | Council-owned HTTPS child with your API key | Your API project |
Antigravity ( | DISABLED BY DEFAULT | See NOTICE |
The additional echo backend is a local fake for zero-quota checks.
Council charges no fee; vendor usage may cost money or consume quota.
See PRICING.
Safety
The invariant is that nothing agent-writable changes what runs. Derived narrow
executable roots, an argv guard, environment allowlisting, restricted/read-only
CLI execution and app integrity checks enforce it within the documented write
boundary. Before spawning, the runner compares backend-built argv and sandbox
paths and revalidates read grants against the vault and runtime exclusions.
Untrusted configuration enters doctor-only mode. Leaf output is
framed as untrusted, with a single final NEXT: line from the renderer.
Shared hourly/daily/concurrency/depth fuses, deadlines and identity-checked
cancellation bound jobs. STOP files exist in the vault, profile runtime and
globally at %LOCALAPPDATA%\council\STOP; extra paths come from
COUNCIL_STOP_FILES. Trusted COUNCIL_MAX_* environment settings can override
fuse caps; host registrations cannot supply them. Whole-file backups cover edited
files, including host configuration, while recovery preserves unrelated host
entries. Removal follows manifest ownership; runtime/backup purges require
their own attended per-item decisions. Transient cleanup and explicit key
deletion have narrow scopes. This does not protect Z0/Z1 from a process granted
unrestricted access to your OS account. See SECURITY-MODEL.
Use installer update and uninstall for lifecycle changes and read their
plans/reports. TROUBLESHOOTING covers host restart,
shim, proxy and sign-in issues. node tests/run.mjs runs the local zero-quota
gate; TESTING explains fixture isolation and skips.
Not in 0.1.1
The following are deferred:
macOS/Linux process, secrets and file-attribute implementations (planned for v0.2).
npm publication and GitHub Actions beyond lint.
Gemini multi-turn resume and a GUI.
Router or debate-protocol changes.
Measured minimum versions for Codex and Antigravity; the latter remains disabled, see NOTICE.
Claude Code project-scope registration and MSIX Claude Desktop as a first-class write target.
Signed releases and pinned-binary-hash mode.
Automatic translation of the rules block.
Documentation
ARCHITECTURE — process model, zones and launcher rationale.
INSTALL — attended installation, writes and recovery.
CONFIG — machine/profile configuration, tokens and layout.
VAULT-CONTRACT — adoption, markers and conditional conventions.
PLATFORMS — platform capabilities and credential existence probes.
TESTING — isolated zero-quota tests and explicit skips.
RELEASING — tracked-tree staging, tags and release assets.
TROUBLESHOOTING — diagnostic reasons and host fixes.
MIGRATION — generic transition from an older in-vault install.
SECURITY-MODEL — trust boundaries, controls and residual risks.
VERSIONS — enforced floors, tested versions and capability probes.
PRICING — vendor usage, fuses and ledger interpretation.
SPEC — condensed normative contract for contributors.
INTERFACES — eight MCP tools and all installer commands.
cancel-timing — cancellation timing fields and interpretation.
INSTALLER-AUDIT-FIXES — installer audit decisions and fixes.
INSTALLER-READ-ONLY-DECISIONS — read-only installer decisions.
INSTALLER-VERBS — verification, update and uninstall details.
Release notes 0.1.1 — shipped scope and deferrals.
Also read NOTICE, SECURITY and CONTRIBUTING.
Acknowledgements
The independent-answer, cross-examination and chair structure draws on the open-source llm-council project. Council uses the official vendor CLIs and ripgrep; vendor software is installed separately and retains its own terms.
License
MIT. Not affiliated with Anthropic, OpenAI or Google.
This server cannot be deployed
Maintenance
Related MCP Connectors
Enterprise AI Control Plane: governance, guardrails, spend tracking, compliance & smart routing.
- BasinOAuthco.getbasin
Your AI assistants coordinate with other people's in one shared library across tools and companies.
AI model routing on your own vendor keys: pick the best model per prompt, or route and run it.
AI routing, memory, guardrails, and governance. Routes across Claude, GPT, Gemini.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI agents to consult with multiple AI models (GPT, Gemini, Grok, etc.) through OpenRouter with intelligent auto-selection, conversation history, and caching. Allows your AI assistant to seek expert opinions from specialized models for different tasks like coding, analysis, or general questions.29 npm1MIT
- AlicenseBqualityDmaintenanceEnables AI agents to consult expert models (Claude, GPT, Gemini, DeepSeek, Z.ai) for technical guidance, code reviews, and architectural advice without switching context.420 npm4MIT
- AlicenseAqualityAmaintenanceEnables Claude to chat with various AI models and obtain multi-model consensus for complex decisions.4735 npm2MIT
- AlicenseAqualityBmaintenanceEnables AI assistants to query hundreds of models across OpenAI, Google, and OpenRouter, with model discovery, deep-research jobs, and image generation.103MIT