Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Agentic Keychain

REMOTE · AGENTICKEYCHAIN.COM · SCANNED OCT 4

Agent Skill ROI Registry & Benchmarking. It sells skills for log triage and repository mapping.

76 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security83
Transport & Reachability100
Schema Quality & AI Usability65
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2994 tokens (~272/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Agentic Keychain MCP server?

Agentic Keychain is a hosted endpoint at https://agentickeychain.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · agentickeychain.com

# add to Claude Code
claude mcp add --transport http com-agentickeychain-agentic-keychain 'https://agentickeychain.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-agentickeychain-agentic-keychain": {
      "url": "https://agentickeychain.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-agentickeychain-agentic-keychain": {
      "type": "http",
      "url": "https://agentickeychain.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-agentickeychain-agentic-keychain]
url = "https://agentickeychain.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-agentickeychain-agentic-keychain": {
      "type": "remote",
      "url": "https://agentickeychain.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-agentickeychain-agentic-keychain --url 'https://agentickeychain.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-agentickeychain-agentic-keychain:
    url: "https://agentickeychain.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-agentickeychain-agentic-keychain": {
      "Transport": "http",
      "Url": "https://agentickeychain.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-agentickeychain-agentic-keychain -t streamable-http -u 'https://agentickeychain.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-agentickeychain-agentic-keychain": {
      "type": "http",
      "url": "https://agentickeychain.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 +2
    • Tool coverage: 73% → 100% ▲ functional
    • “compare_capabilities” reworded the description of “capabilities” cosmetic
    • “compare_capabilities” reworded the description of “constraints” cosmetic
    • “evaluate_capability” reworded the description of “constraints” cosmetic
    • “report_outcome” reworded the description of “baseline_cost_estimate_usd” cosmetic
    • “report_outcome” reworded the description of “cost_usd” cosmetic
    • “report_outcome” reworded the description of “latency_ms” cosmetic
    • “report_outcome” reworded the description of “success” cosmetic
    • “report_outcome” reworded the description of “tokens_in” cosmetic
    • “report_outcome” reworded the description of “tokens_out” cosmetic
    • “report_outcome” reworded the description of “tool_calls” cosmetic
    • “report_outcome” reworded the description of “used_capability” cosmetic
    • “resolve_task” reworded the description of “constraints” cosmetic
    • “search_capabilities” reworded the description of “limit” cosmetic
  • 3 Oct 26 −1
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “compare_capabilities” rewrote its description, which is the text the model reads security
    • Tool “estimate_roi” rewrote its description, which is the text the model reads security
    • Tool “evaluate_capability” rewrote its description, which is the text the model reads security
    • Tool “get_benchmark” rewrote its description, which is the text the model reads security
    • Tool “get_capability” rewrote its description, which is the text the model reads security
    • Tool “get_provenance” rewrote its description, which is the text the model reads security
    • Tool “get_quote” rewrote its description, which is the text the model reads security
    • Tool “report_outcome” rewrote its description, which is the text the model reads security
    • Tool “search_capabilities” rewrote its description, which is the text the model reads security
    • Tool “unlock_capability” rewrote its description, which is the text the model reads security
    • Schema quality: 140 → 257 ▼ functional
    • Server version: 0.1.0 → 0.2.0 functional
    • New tool “resolve_task” functional
  • 1 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 29 Sept 26 +1
    • Stability: unverified → 0.03 ▲ functional
  • 28 Sept 26 73

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 6 Oct 2026 · Probed https://agentickeychain.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=agentickeychain.com CN=YE2,O=Let's Encrypt,C=US 25 Sept 2026 24 Dec 2026 ECDSA 256 ECDSA-SHA384 6f6071f110d631e97853551202e517cf647
SANs: agentickeychain.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of agentickeychain.com. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
agentickeychain.com. present 60603 13 Verified
agentickeychain.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000
x-content-type-options nosniff
x-frame-options DENY
referrer-policy same-origin
permissions-policy interest-cohort=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://agentickeychain.com/mcp Verified 200
http (plaintext) http://agentickeychain.com/mcp HTTPS enforced 308 https://agentickeychain.com/mcp
MCP tools · 11 exposed · ~2,872 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
compare_capabilities ~326

Assess two to five named capabilities side by side for the same inputs, with the same method and ak.offer.v1 offer shape as evaluate_capability. Use when: you already hold a shortlist of capability ids and want each one's decision, reasons and offer in one answer. Not for: finding candidates (search_capabilities) or a single capability (evaluate_capability). Input: the capability ids, plus the optional task, model, expected_runs, baseline_cost_estimate_usd, context and constraints that evaluate_capability reads. Output: ak.comparison.v1 with the results ranked by decision, lower-bound net saving, relevance and capability id, each with its reasons and an ak.offer.v1 offer.

NameTypeReqDescription
baseline_cost_estimate_usdnumber–What one run of this task costs you today without the capability, in USD.
capabilitiesarrayyesTwo to five capabilities to compare, each as an id, ak:// URI or slug.
constraintsobject–Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
contextobject–Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
expected_runsinteger–How many times you expect to perform this kind of task.
modelstring–The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
taskstring–Plain description of the task you are about to do (at most 4000 characters).

No output schema declared.

No examples provided.

estimate_roi ~262

Per measured model: expected saving per run, break-even runs and net saving over expected_runs, with intervals, for one capability and no task. Use when: you know the capability and want its economics on each model the registry measured. Not for: a use-or-not answer for a task (evaluate_capability) or several candidates (compare_capabilities). Input: a capability id; add model to keep one model, and expected_runs with baseline_cost_estimate_usd for an estimate at your scale. Output: ak.roi.v1 with one economics entry per measured model; break-even runs is null when the interval does not show a saving, and your estimate is left out where success is not accepted or your baseline lies outside the measured range.

NameTypeReqDescription
baseline_cost_estimate_usdnumber–What one run of this task costs you today without the capability, in USD.
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
expected_runsinteger–How many times you expect to perform this kind of task.
modelstring–The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.

No output schema declared.

No examples provided.

evaluate_capability ~425

Decide whether a registry capability is worth using or buying for your task, from registry-run benchmarks only. Use when: you have a task and want a recommend, do_not_recommend or undetermined answer with the arithmetic; name a capability to weigh only that one, or leave it out and the registry weighs its closest matches. Not for: one short answer without the arithmetic (resolve_task), a plain list of matches (search_capabilities), two to five named candidates side by side (compare_capabilities), or the break-even figures of one capability without a task (estimate_roi). Input: a plain task description; give model, expected_runs and baseline_cost_estimate_usd for a money estimate, and context for the conditions the capability declares. Output: ak.evaluation.v1 with decision, reasons, expected effect, price, confidence, operator_message, evaluation_id, next steps and an ak.offer.v1 offer (status, next_action, economics, the four evidence kinds listed apart). do_not_recommend is a normal answer.

NameTypeReqDescription
baseline_cost_estimate_usdnumber–What one run of this task costs you today without the capability, in USD.
budget_policyobject–Your operator's spending policy; the answer says whether a purchase fits it. Every purchase still needs human approval.
capabilitystring–Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
constraintsobject–Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
contextobject–Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
expected_runsinteger–How many times you expect to perform this kind of task.
modelstring–The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
taskstringyesPlain description of the task you are about to do (at most 4000 characters).

No output schema declared.

No examples provided.

get_benchmark ~161

Registry-run benchmark summaries (labelled), publisher claims (labelled PUBLISHER CLAIMED) and the signed attestations of one capability. Use when: you want the measurements behind an answer (paired runs, model, fixtures, method) or want to check them yourself. Not for: an answer for your task (evaluate_capability) or artifact hashes and the log proof (get_provenance). Input: a capability id, ak:// URI or slug. Output: ak.benchmark.v1 with the evidence, the publisher claims, the attestations, the method and the limitations; publisher claims never decide anything.

NameTypeReqDescription
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

No output schema declared.

No examples provided.

get_capability ~169

The capability's card: purpose, use-when and do-not-use-when conditions, permissions, price, evidence summary, trust checks, links and a task-independent ak.offer.v1 offer. Use when: you can name a capability and want its facts, or want to check the conditions an evaluation asked about. Not for: an answer for your task (evaluate_capability) or the full benchmark records (get_benchmark). Input: a capability id, ak:// URI or slug, from a search, an evaluation or a page. Output: ak.capability.v1 with the card fields, parameters, versions, terms, evidence, trust and links.

NameTypeReqDescription
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

No output schema declared.

No examples provided.

get_provenance ~146

Artifact hash, manifest hash, signed publisher and registry attestations and a transparency-log inclusion proof for one capability. Use when: you want to check that a package is the one the registry published and signed. Not for: benchmark results (get_benchmark) or the card (get_capability). Input: a capability id, ak:// URI or slug. Output: ak.provenance.v1 with the hashes, the attestations, an RFC 9162 inclusion proof against the signed tree head, the trust checks and the keys URL.

NameTypeReqDescription
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

No output schema declared.

No examples provided.

get_quote ~196

A signed 15-minute price quote with the hosted checkout link. It charges nothing; a purchase requires operator approval in the hosted checkout. Use when: your operator wants the price and the checkout link of a capability that is for sale, for example after an evaluation answered recommend. Not for: deciding whether a capability is worth it (evaluate_capability); a free capability needs no quote. Input: the capability id and, if you evaluated first, the evaluation_id, which links the quote to that evaluation. Output: a quote_id and signed claims bound to the capability version, price, currency, terms and expiry, the checkout link and the unlock request; the price comes from the registry record only.

NameTypeReqDescription
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
evaluation_idstring–The evaluation_id from evaluate_capability, if you evaluated first.

No output schema declared.

No examples provided.

report_outcome ~391

Report how a capability worked for you. Stored as AGENT REPORTED; it never changes evidence labels, trust or ranking. Only the listed fields are accepted; no task text is kept. Use when: you ran a capability, or decided not to, and can say whether the task succeeded. Not for: questions about a capability (get_capability, get_benchmark). Input: the capability id and success; add evaluation_id or purchase_ref to link the report, the optional token, tool-call, latency and cost counts, and failure_reason only with success false. Output: whether the report was stored, its label and, for a failed paid capability, the remedy policy.

NameTypeReqDescription
baseline_cost_estimate_usdnumber–What one run of this task costs you without the capability, in USD.
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
cost_usdnumber–What the run cost you in USD.
evaluation_idstring–The evaluation_id from evaluate_capability, if you evaluated first.
failure_reasonstring–Only with success false.
latency_msinteger–Wall-clock time of the run in milliseconds.
modelstring–The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
purchase_refstring–The purchase_ref from unlock_capability, if you bought the capability.
successbooleanyesWhether the task reached its goal.
tokens_ininteger–Input tokens the run used.
tokens_outinteger–Output tokens the run used.
tool_callsinteger–Tool calls the run made.
used_capabilityboolean–Whether the capability was used in this run; false reports a run done without it.

No output schema declared.

No examples provided.

resolve_task ~387

Describe a task in plain words and get one compact answer: whether a registry capability is worth using for it, from registry-run benchmarks only, and the next step. Use when: you have a task and no capability name, and want one decision word (use, do_not_use, use_free_alternative, insufficient_evidence, blocked_by_constraints or no_match) with its reason codes. Not for: the full arithmetic, the offer and the operator message (evaluate_capability with the same inputs), a plain list of matches (search_capabilities) or a capability you can already name (get_capability). Input: task, plus optional model, expected_runs, baseline_cost_estimate_usd, context and constraints; any other field is refused with the allowed list. Output: ak.resolve.v1 with decision, capability id, reason codes, the measured saving per run with its interval or null, the estimate at your own baseline with its break-even runs or null, confidence, evidence label, price, free alternatives, next action, evaluation_id and the tool that gives the detail. do_not_use and no_match are normal answers.

NameTypeReqDescription
baseline_cost_estimate_usdnumber–What one run of this task costs you today without the capability, in USD.
constraintsobject–Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
contextobject–Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
expected_runsinteger–How many times you expect to perform this kind of task.
modelstring–The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
taskstringyesPlain description of the task you are about to do (at most 4000 characters).

No output schema declared.

No examples provided.

search_capabilities ~177

Search capability names, summaries, tasks and use-when conditions by keywords, ranked by lexical relevance only, never by payment. Use when: you want to see which capabilities exist for a topic, or you know part of a name. Not for: deciding whether one fits your task (resolve_task, or evaluate_capability for the full arithmetic) or reading a capability you can already name (get_capability). Input: search words, at most 500 characters; no earlier call is needed. Output: ak.search.v1 with id, name, summary, relevance, state, price and the strongest evidence label of each result, and no decision.

NameTypeReqDescription
limitinteger–How many results to return, from 1 to 50 (default 10).
querystringyesSearch words (at most 500 characters).

No output schema declared.

No examples provided.

unlock_capability ~232

Exchange the license key from the checkout (a purchase requires operator approval) for a signed entitlement and a download link that lasts at most 15 minutes. How the key is handled: the privacy page at /legal/privacy/. Repeating it with the same key is safe and never charges. Use when: your operator completed the hosted checkout and gave you the license key. Not for: a price or a checkout link (get_quote); a free capability downloads from its page. Input: the capability id and the license key, plus quote_id and evaluation_id when you have them. Output: a signed entitlement, a purchase_ref for report_outcome and the download link.

NameTypeReqDescription
capabilitystringyesCapability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
evaluation_idstring–The evaluation_id from evaluate_capability, if you evaluated first.
license_keystringyesLicense key from the checkout.
quote_idstring–The quote_id of the quote the purchase followed, if any (links the records; never changes the price).

No output schema declared.

No examples provided.

Common questions

What is the Agentic Keychain MCP server?

Agentic Keychain is an MCP server listed in the public MCP registry as com.agentickeychain/agentic-keychain. Agent Skill ROI Registry & Benchmarking. It sells skills for log triage and repository mapping. This page covers its hosted endpoint (https://agentickeychain.com/mcp).

Is the Agentic Keychain MCP server safe to use?

Agentic Keychain scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Agentic Keychain MCP server expose?

Agentic Keychain exposes 11 tools: resolve_task, evaluate_capability, search_capabilities, compare_capabilities, estimate_roi, and 6 more. Their descriptions and schemas cost roughly 2,872 tokens of context every time the server is loaded.

Does the Agentic Keychain MCP server require authentication?

No. We connected to Agentic Keychain without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Agentic Keychain MCP server still maintained?

Agentic Keychain is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.