AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Agent Receipts Mcp

mcp-dhanushs1912-svg-agent-receipts-mcp · by dhanushs1912-svg

Prove what your AI agents did - EU AI Act-ready audit trails: signed, tamper-evident receipts with offline verification. MCP server + HTTP API.

No reviews yet
0 installs
25 views
0.0% view→install

Install

$ agentstack add mcp-dhanushs1912-svg-agent-receipts-mcp

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-dhanushs1912-svg-agent-receipts-mcp)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Agent Receipts Mcp? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

agent-receipts

[](https://www.npmjs.com/package/agent-receipts-mcp) [](LICENSE)

Prove what your AI agents did.

On August 2, 2026, the EU AI Act's record-keeping obligations for high-risk AI systems became enforceable: automatic event logging (Article 12), deployer log retention of at least six months (Article 26), and penalties up to €15M or 3% of global turnover. The question your auditor, regulator, or counterparty will ask is simple:

> "Your AI agent approved this. Prove exactly what it did — and prove nobody edited the record."

An ordinary log file can't answer that: whoever owns the log can edit it. agent-receipts gives every consequential agent action a cryptographically signed, timestamped receipt that anyone can verify offline — and exports signed audit bundles you can hand directly to a compliance officer.

What a receipt proves

  • What happened, when — action type, summary, actor, principal, ISO 8601 timestamp
  • It hasn't been altered — Ed25519 signature over canonical JSON; change one character

and verification fails

  • Nothing was deleted — receipts are hash-chained with monotonic sequence numbers per

vault; every audit export automatically flags gaps (deletions) and chain breaks

  • Without exposing your data — hash-only privacy: payloads are SHA-256 fingerprinted

and immediately discarded, never stored or transmitted

Built for the audit conversation

export_audit_bundle produces what compliance actually needs: all receipts in a date range, a tamper-evidence report (sequence gaps, chain breaks), the signing public key, and a manifest signature over the whole bundle. Retention is yours to control — the vault is a local SQLite file you keep as long as Article 26 (or your policy) requires.

You don't have to trust us. Receipts verify offline against a pinned public key with the bundled CLI — no account, no network call, no dependence on this service existing tomorrow. That's what makes the evidence durable.

Quick start (MCP — local, free)

// Claude Desktop / Claude Code / any MCP client
{
  "mcpServers": {
    "agent-receipts": {
      "command": "npx",
      "args": ["-y", "agent-receipts-mcp"],
      "env": { "AGENT_RECEIPTS_DATA": "" }
    }
  }
}

Requires Node.js >= 22.13 (uses the built-in node:sqlite — zero native dependencies). Prefer one-click? Grab the .mcpb bundle from Releases and open it with Claude Desktop.

| Tool | When an agent should call it | | --- | --- | | issue_receipt | Immediately after any consequential action. Returns the signed receipt. | | verify_receipt | Before trusting a receipt presented by another agent or system. | | export_audit_bundle | When a human asks for the audit trail of a date range. | | get_service_info | To fetch the public key worth pinning for offline verification. |

Quick start (HTTP API)

npm install && npm run build
npm run serve        # http://localhost:8787
# 1. Create a vault (returns your API key — shown once)
curl -X POST localhost:8787/v1/vaults -d '{"name":"acme-compliance"}'

# 2. Issue a receipt after an agent action
curl -X POST localhost:8787/v1/receipts \
  -H "Authorization: Bearer ark_..." \
  -d '{"action_type":"invoice.approved","summary":"Approved INV-1042 for EUR 1,250",
       "payload":{"invoice":"INV-1042","amount":1250},"actor":"agent:ap-bot@acme"}'

# 3. Anyone can verify — no auth
curl -X POST localhost:8787/v1/verify -d '{"receipt":{...}}'

# 4. Export a signed audit bundle for the compliance officer
curl "localhost:8787/v1/export?from=2026-01-01" -H "Authorization: Bearer ark_..."

Service manifest for machine discovery: GET /.well-known/agent-receipts.json.

Offline verification

npx -y -p agent-receipts-mcp agent-receipts-verify receipt.json --pubkey 
# exit 0 = authentic, exit 1 = invalid/tampered

Receipt format (agent-receipts/v1)

{
  "schema": "agent-receipts/v1",
  "id": "rcpt_...",
  "vault_id": "vlt_...",
  "sequence": 42,                      // monotonic per vault; gaps = deletion evidence
  "issued_at": "2026-07-15T12:34:56.789Z",
  "action": {
    "type": "invoice.approved",
    "summary": "Approved invoice INV-1042 for EUR 1,250",
    "actor": "agent:ap-bot@acme",      // optional
    "principal": "acme-gmbh",          // optional
    "context": { "jurisdiction": "EU" } // optional
  },
  "payload_hash": "sha256:...",        // or null; contents never stored
  "prev_receipt_hash": "sha256:...",   // hash chain to the previous receipt
  "key_id": "key_...",
  "public_key": "",   // embedded for offline verification
  "signature": ""
}

Canonicalization is JCS-style: lexicographically sorted keys, no whitespace. The JSON Schema lives at [docs/receipt.schema.json](docs/receipt.schema.json).

EU AI Act mapping (informational)

| Obligation | How agent-receipts helps | | --- | --- | | Art. 12 — automatic event logging | issue_receipt on every consequential action; timestamps, actor, traceable chain | | Art. 26 — keep logs ≥ 6 months | Local vault you retain on your terms; signed export_audit_bundle for handover | | Traceability / integrity | Ed25519 signatures, hash chain, deletion detection, offline verification |

Not legal advice. Whether your system is "high-risk" and what you must log is a question for your counsel. agent-receipts produces evidence infrastructure.

Status & roadmap

  • [x] Core: issue / verify / export with hash chain + Ed25519
  • [x] MCP stdio server + HTTP API + offline verifier CLI + MCPB bundle
  • [ ] Hosted vaults with per-receipt pricing
  • [ ] RFC 3161 / transparency-log timestamp anchoring
  • [ ] Key rotation and multi-key verification

MIT License.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.