thoughtproof-mcp
OfficialThe ThoughtProof MCP server verifies AI-generated reasoning and claims using adversarial multi-model consensus (Grok, Gemini, DeepSeek, Sonnet), helping you decide whether to trust and act on AI outputs.
Verify claims and reasoning: Submit any decision or reasoning claim via
verify_claim/verify_reasoningto receive a verdict (ALLOW, HOLD, UNCERTAIN, or DISSENT), a confidence score, and up to 3 key objections explaining why a claim may be challengedDomain-specific verification: Tailor analysis to
financial,medical,legal,code, orgeneralcontexts for more accurate assessmentsRisk-adjusted analysis: Set a stake level (
low,medium,high,critical) to adjust confidence thresholds based on decision consequenceAdjust verification depth: Choose between fast (2 models), standard (4 models), or deep (5+ models) to balance speed and cost ($0.008–$0.08 per verification)
Check agent trust scores: Use
check_agent_scoreto look up composite trust scores for specific agents, optionally filtered by domainGuard against hallucinations: Use verdicts and objections to validate AI outputs before acting on them
Allows looking up agent trust scores on the ERC-8004 registry, an Ethereum-based autonomous agent registry.
thoughtproof-mcp
thoughtproof-mcp — local stdio. Hero tool verify_decision (DQL spend / Sentinel irreversible exit). execute is true only on ALLOW.
MCP server for ThoughtProof — pre-execution decision verification for AI agents.
Hero tool: verify_decision. It routes inside the tool to DQL (spend / checkout) or Sentinel (irreversible exit) and returns a fail-closed execute flag. execute is true only on a native ALLOW.
This package is a local stdio MCP server (Node 18+) for Desktop / CLI hosts such as Cursor, Claude Desktop, Windsurf, and Cline. It is not a remote HTTP MCP server. It is not a Grok Web/Mobile custom connector.
Get keys at https://app.thoughtproof.ai/pricing.
Unpublished work is documented in UNRELEASED.md.
Quick Start
{
"mcpServers": {
"thoughtproof": {
"command": "npx",
"args": ["-y", "thoughtproof-mcp@0.3.2"],
"env": {
"DQL_API_KEY": "dqlk_your_key_here"
}
}
}
}Install with npx -y thoughtproof-mcp@0.3.2. Works with Claude Desktop, Cursor, Windsurf, Cline, and other local stdio MCP clients.
Related MCP server: agentshield-mcp
Tools
verify_before_action / verify_decision (hero)
verify_before_action is an alias of verify_decision (identical schema + handler). Soft fail-closed: host must honor execute=false.
Pre-execution gate for a proposed action. Routing is inside the tool — not an agent quiz.
Parameter | Type | Default | Description |
| string | (required) | User's stated goal / instruction |
| string | (required) | What the agent is about to do |
| string | (required) | The agent's own plan / reasoning |
| string | (optional) | Extra evidence |
|
|
| Explicit surface, or auto-route |
Auto-route: spend / checkout / booking / purchase / payment / cart / Stripe / price / budget / cap → DQL. High-blast irreversible exit without that language (publish, delete, deploy, send-to-prod, memory write) → Sentinel. Unsure → DQL. Explicit mode wins. RV / PLV are not on this path.
Camera mandate: do not put the overshoot in proposed_action or reasoning (for example, do not write “price is above the cap”). The verifier has to find the mismatch.
Envelope (always this shape):
{
"verdict": "ALLOW",
"execute": true,
"objections": [],
"receipt_id": "dql_…",
"surface": "dql",
"axes": [],
"recommendation": "execute"
}execute is true only on ALLOW. REVIEW, UNCERTAIN, BLOCK, timeouts, HTTP 402/4xx/5xx, and missing keys return execute: false. Fail-closed is soft at the protocol layer — the tool does not hard-stop the host. Replan is a new call (new receipt).
verify_claim
Verify any claim or AI-generated reasoning via RV (POST /v1/check). Unchanged.
Parameter | Type | Default | Description |
| string | (required) | The text to verify |
|
|
| Risk level — higher stakes trigger deeper verification |
|
|
| Domain context for specialized verification |
|
|
| Verification depth |
check_agent_score
Look up an agent's composite trust score on the ERC-8004 registry.
Parameter | Type | Description |
| string | Agent ID to look up |
| string | Optional domain filter |
verify_trade
Optional pre-execution gate for trading agents (Sentinel → RV). Not the default verify_decision path. See VERIFY_TRADE.md.
Configuration
Environment Variable | Default | Description |
| (none) | DQL key ( |
| (none) | Optional. Required only when |
| (off) | Set to |
| (none) | Operator key for |
|
| RV API base URL ( |
A missing Sentinel key returns execute: false with “Sentinel key not configured” — it does not silently call DQL.
Development
git clone https://github.com/ThoughtProof/thoughtproof-mcp.git
cd thoughtproof-mcp
npm install
npm run build
npm test
npm run dev # Run with tsx (hot reload)
npm run inspect # Test with MCP InspectorFor local MCP clients, point command at node and args at dist/index.js after npm run build.
Related
ThoughtProof — Decision verification for AI agents
pot-cli — CLI for reasoning verification
ERC-8004 — Autonomous Agent Registry
License
MIT — ThoughtProof
Maintenance
Tools
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAdversarial multi-model reasoning verification for AI agents. Claude, Grok, and DeepSeek challenge each decision — returns ALLOW or HOLD with JWKS-signed attestation. x402-gated on Base.4MIT
- FlicenseAqualityNot gradedmaintenanceTrust infrastructure for AI agents on Base. DEX Spread Oracle (live Uniswap V3 prices), on-chain escrow, insurance pool, and collective knowledge base. 7 smart contracts. Pay-per-query via x402 micropayments in USDC.6
- FlicenseAqualityCmaintenancePay-per-call tools for AI agents including trust checks, due diligence, market data, and human-verified approvals, settled in USDC on Base via the x402 protocol.16
- FlicenseAqualityCmaintenanceAgent-Level Transaction Safety Oracle. Before an AI agent signs a blockchain transaction, it returns a SAFE/UNSAFE verdict with a SENTINEL Score (AAA-D) and risk flags. Pay-per-call $0.005 USDC via x402 on Base.1
Related MCP Connectors
AI/LLM agent output audit MCP: policy eval, tamper-evident chain, AI safety, x402 USDC on Base.
AI-native settlement rail + intelligence oracle for autonomous agents. x402, Base mainnet, 81 tools.
Reputation oracle for AI agents on Base: SAFE/CAUTION/BLOCK + 0-100 score before you pay. x402+MCP
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ThoughtProof/thoughtproof-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server