PCRZERO

Signed receipts for agent actions — adjudicate attestations against policy; verify any receipt offline, free, no account.

Documentation

PCRZERO — MCP server

Issue and verify signed receipts for agent actions from any MCP-speaking agent. PCRZERO adjudicates an attestation document against a policy and hands back a cryptographically signed receipt pair — durable, independently checkable proof that this decision was made, by these keys, over this document. Anyone can verify a receipt, offline, without an account and without trusting us.

Install

Add the server to your MCP client. The package runs over stdio — your agent host launches it; nothing listens on a port.

Claude Code

claude mcp add pcrzero -e PCRZERO_API_KEY=<your-key> -- npx -y @scytalex-llc/pcrzero-mcp

Claude Desktop / any JSON-configured MCP client

{
  "mcpServers": {
    "PCRZERO": {
      "command": "npx",
      "args": ["-y", "@scytalex-llc/pcrzero-mcp"],
      "env": { "PCRZERO_API_KEY": "<your-key>" }
    }
  }
}

No key yet? Leave env out. verify_receipt and get_keyset work with no API key and no account — only the paid tool needs one.

Requires Node 22 or later.

The three tools

ToolCostWhat it does
issue_receiptMetered — bills one receipt_verifications unit per callAdjudicates an attestation document against a policy on the live API and returns the verdict with a signed receipt pair. A fail verdict bills exactly like a pass: you are paying for the adjudication, not for the answer you wanted. The only tool here that spends.
verify_receiptFree, and it stays freeChecks a PCRZERO receipt pair against the signing keyset: whether the signature holds, and whether the receipt says what it appears to say. Offline by default — supply keyset and this call touches the network not at all; omit it and the server fetches the public keyset once. keyset_source in the result tells you which happened, every time.
get_keysetFreeReturns the current PCRZERO signing keyset — key ids, public halves, each key’s status. Public and unauthenticated. The same document an outside party fetches to check a receipt without trusting us.

Current pricing is published at pcrzero.com — it is deliberately not baked into this README or into any tool description.

Auth, exactly

PCRZERO_API_KEY in the server’s environment, via your MCP client configuration. It is sent as Authorization: Bearer on issue_receipt calls and used nowhere else: the key never appears in tool results, error text, or logs — not even redacted. With no key configured, issue_receipt refuses cleanly (auth_missing) and the two free tools keep working.

API errors pass through verbatim (code, message, request_id). This server never rewrites, retries, or softens a billing refusal.

Verify without trusting us

A PCRZERO receipt is checkable by anyone holding the public keyset — including people who are not our customers and never will be. Call get_keyset once (or fetch https://api.pcrzero.com/v1/keys yourself), pin it, and verify_receipt runs entirely offline from then on. If we disappeared tomorrow, every receipt ever issued would still verify.

Transport & scope

stdio only. No listen socket, no state, no receipt storage, no key-management tools — key management is a human path at pcrzero.com by design.


Proprietary — © Scytalex LLC. The receipt verification path is free to use for anyone, forever.