# Agentic Keychain (remote · agentickeychain.com)

Agent Skill ROI Registry & Benchmarking. It sells skills for log triage and repository mapping.

- Trust score: 76/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `agentickeychain.com`: 76/100 (this document), [markdown](https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain.md), [page](https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain)

## Channel facts

- Endpoint: `https://agentickeychain.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 83/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 65/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2994 tokens (~272/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 20/100
  - Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Agentic Keychain MCP server?

Agentic Keychain is a hosted endpoint at https://agentickeychain.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-agentickeychain-agentic-keychain 'https://agentickeychain.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-agentickeychain-agentic-keychain": {
      "url": "https://agentickeychain.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-agentickeychain-agentic-keychain": {
      "type": "http",
      "url": "https://agentickeychain.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-agentickeychain-agentic-keychain]
url = "https://agentickeychain.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-agentickeychain-agentic-keychain": {
      "type": "remote",
      "url": "https://agentickeychain.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-agentickeychain-agentic-keychain --url 'https://agentickeychain.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-agentickeychain-agentic-keychain:
    url: "https://agentickeychain.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-agentickeychain-agentic-keychain": {
      "Transport": "http",
      "Url": "https://agentickeychain.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-agentickeychain-agentic-keychain -t streamable-http -u 'https://agentickeychain.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-agentickeychain-agentic-keychain": {
      "type": "http",
      "url": "https://agentickeychain.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 76, +2)

- [functional improvement] Tool coverage: 73% → 100%
- [cosmetic] “compare_capabilities” reworded the description of “capabilities”
- [cosmetic] “compare_capabilities” reworded the description of “constraints”
- [cosmetic] “evaluate_capability” reworded the description of “constraints”
- [cosmetic] “report_outcome” reworded the description of “baseline_cost_estimate_usd”
- [cosmetic] “report_outcome” reworded the description of “cost_usd”
- [cosmetic] “report_outcome” reworded the description of “latency_ms”
- [cosmetic] “report_outcome” reworded the description of “success”
- [cosmetic] “report_outcome” reworded the description of “tokens_in”
- [cosmetic] “report_outcome” reworded the description of “tokens_out”
- [cosmetic] “report_outcome” reworded the description of “tool_calls”
- [cosmetic] “report_outcome” reworded the description of “used_capability”
- [cosmetic] “resolve_task” reworded the description of “constraints”
- [cosmetic] “search_capabilities” reworded the description of “limit”

### 2026-10-03 (score 74, −1)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “compare_capabilities” rewrote its description, which is the text the model reads
- [security] Tool “estimate_roi” rewrote its description, which is the text the model reads
- [security] Tool “evaluate_capability” rewrote its description, which is the text the model reads
- [security] Tool “get_benchmark” rewrote its description, which is the text the model reads
- [security] Tool “get_capability” rewrote its description, which is the text the model reads
- [security] Tool “get_provenance” rewrote its description, which is the text the model reads
- [security] Tool “get_quote” rewrote its description, which is the text the model reads
- [security] Tool “report_outcome” rewrote its description, which is the text the model reads
- [security] Tool “search_capabilities” rewrote its description, which is the text the model reads
- [security] Tool “unlock_capability” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 140 → 257
- [functional] Server version: 0.1.0 → 0.2.0
- [functional] New tool “resolve_task”

### 2026-10-01 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-29 (score 74, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-28 (score 73)

First indexed and scored.

## MCP tools (11)

### `resolve_task` (~387 tokens)

Is there a capability worth using for this task?

Describe a task in plain words and get one compact answer: whether a registry capability is worth using for it, from registry-run benchmarks only, and the next step. Use when: you have a task and no capability name, and want one decision word (use, do_not_use, use_free_alternative, insufficient_evidence, blocked_by_constraints or no_match) with its reason codes. Not for: the full arithmetic, the offer and the operator message (evaluate_capability with the same inputs), a plain list of matches (search_capabilities) or a capability you can already name (get_capability). Input: task, plus optional model, expected_runs, baseline_cost_estimate_usd, context and constraints; any other field is refused with the allowed list. Output: ak.resolve.v1 with decision, capability id, reason codes, the measured saving per run with its interval or null, the estimate at your own baseline with its break-even runs or null, confidence, evidence label, price, free alternatives, next action, evaluation_id and the tool that gives the detail. do_not_use and no_match are normal answers.

Input parameters:

- `baseline_cost_estimate_usd` (number): What one run of this task costs you today without the capability, in USD.
- `constraints` (object): Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
- `context` (object): Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
- `expected_runs` (integer): How many times you expect to perform this kind of task.
- `model` (string): The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
- `task` (string, required): Plain description of the task you are about to do (at most 4000 characters).

### `evaluate_capability` (~425 tokens)

Should I use a capability for this task?

Decide whether a registry capability is worth using or buying for your task, from registry-run benchmarks only. Use when: you have a task and want a recommend, do_not_recommend or undetermined answer with the arithmetic; name a capability to weigh only that one, or leave it out and the registry weighs its closest matches. Not for: one short answer without the arithmetic (resolve_task), a plain list of matches (search_capabilities), two to five named candidates side by side (compare_capabilities), or the break-even figures of one capability without a task (estimate_roi). Input: a plain task description; give model, expected_runs and baseline_cost_estimate_usd for a money estimate, and context for the conditions the capability declares. Output: ak.evaluation.v1 with decision, reasons, expected effect, price, confidence, operator_message, evaluation_id, next steps and an ak.offer.v1 offer (status, next_action, economics, the four evidence kinds listed apart). do_not_recommend is a normal answer.

Input parameters:

- `baseline_cost_estimate_usd` (number): What one run of this task costs you today without the capability, in USD.
- `budget_policy` (object): Your operator's spending policy; the answer says whether a purchase fits it. Every purchase still needs human approval.
- `capability` (string): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
- `constraints` (object): Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
- `context` (object): Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
- `expected_runs` (integer): How many times you expect to perform this kind of task.
- `model` (string): The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
- `task` (string, required): Plain description of the task you are about to do (at most 4000 characters).

### `search_capabilities` (~177 tokens)

Search capabilities

Search capability names, summaries, tasks and use-when conditions by keywords, ranked by lexical relevance only, never by payment. Use when: you want to see which capabilities exist for a topic, or you know part of a name. Not for: deciding whether one fits your task (resolve_task, or evaluate_capability for the full arithmetic) or reading a capability you can already name (get_capability). Input: search words, at most 500 characters; no earlier call is needed. Output: ak.search.v1 with id, name, summary, relevance, state, price and the strongest evidence label of each result, and no decision.

Input parameters:

- `limit` (integer): How many results to return, from 1 to 50 (default 10).
- `query` (string, required): Search words (at most 500 characters).

### `compare_capabilities` (~326 tokens)

Compare capabilities

Assess two to five named capabilities side by side for the same inputs, with the same method and ak.offer.v1 offer shape as evaluate_capability. Use when: you already hold a shortlist of capability ids and want each one's decision, reasons and offer in one answer. Not for: finding candidates (search_capabilities) or a single capability (evaluate_capability). Input: the capability ids, plus the optional task, model, expected_runs, baseline_cost_estimate_usd, context and constraints that evaluate_capability reads. Output: ak.comparison.v1 with the results ranked by decision, lower-bound net saving, relevance and capability id, each with its reasons and an ak.offer.v1 offer.

Input parameters:

- `baseline_cost_estimate_usd` (number): What one run of this task costs you today without the capability, in USD.
- `capabilities` (array, required): Two to five capabilities to compare, each as an id, ak:// URI or slug.
- `constraints` (object): Limits you set for the answer; a capability outside them is reported as blocked, with the reason code.
- `context` (object): Facts about your situation, keyed by the capability's parameter names (e.g. log_lines).
- `expected_runs` (integer): How many times you expect to perform this kind of task.
- `model` (string): The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
- `task` (string): Plain description of the task you are about to do (at most 4000 characters).

### `estimate_roi` (~262 tokens)

Estimate return on a capability

Per measured model: expected saving per run, break-even runs and net saving over expected_runs, with intervals, for one capability and no task. Use when: you know the capability and want its economics on each model the registry measured. Not for: a use-or-not answer for a task (evaluate_capability) or several candidates (compare_capabilities). Input: a capability id; add model to keep one model, and expected_runs with baseline_cost_estimate_usd for an estimate at your scale. Output: ak.roi.v1 with one economics entry per measured model; break-even runs is null when the interval does not show a saving, and your estimate is left out where success is not accepted or your baseline lies outside the measured range.

Input parameters:

- `baseline_cost_estimate_usd` (number): What one run of this task costs you today without the capability, in USD.
- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
- `expected_runs` (integer): How many times you expect to perform this kind of task.
- `model` (string): The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.

### `get_capability` (~169 tokens)

Get a capability card

The capability's card: purpose, use-when and do-not-use-when conditions, permissions, price, evidence summary, trust checks, links and a task-independent ak.offer.v1 offer. Use when: you can name a capability and want its facts, or want to check the conditions an evaluation asked about. Not for: an answer for your task (evaluate_capability) or the full benchmark records (get_benchmark). Input: a capability id, ak:// URI or slug, from a search, an evaluation or a page. Output: ak.capability.v1 with the card fields, parameters, versions, terms, evidence, trust and links.

Input parameters:

- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

### `get_benchmark` (~161 tokens)

Get benchmark evidence

Registry-run benchmark summaries (labelled), publisher claims (labelled PUBLISHER CLAIMED) and the signed attestations of one capability. Use when: you want the measurements behind an answer (paired runs, model, fixtures, method) or want to check them yourself. Not for: an answer for your task (evaluate_capability) or artifact hashes and the log proof (get_provenance). Input: a capability id, ak:// URI or slug. Output: ak.benchmark.v1 with the evidence, the publisher claims, the attestations, the method and the limitations; publisher claims never decide anything.

Input parameters:

- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

### `get_provenance` (~146 tokens)

Get provenance

Artifact hash, manifest hash, signed publisher and registry attestations and a transparency-log inclusion proof for one capability. Use when: you want to check that a package is the one the registry published and signed. Not for: benchmark results (get_benchmark) or the card (get_capability). Input: a capability id, ak:// URI or slug. Output: ak.provenance.v1 with the hashes, the attestations, an RFC 9162 inclusion proof against the signed tree head, the trust checks and the keys URL.

Input parameters:

- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.

### `get_quote` (~196 tokens)

Get a price quote

A signed 15-minute price quote with the hosted checkout link. It charges nothing; a purchase requires operator approval in the hosted checkout. Use when: your operator wants the price and the checkout link of a capability that is for sale, for example after an evaluation answered recommend. Not for: deciding whether a capability is worth it (evaluate_capability); a free capability needs no quote. Input: the capability id and, if you evaluated first, the evaluation_id, which links the quote to that evaluation. Output: a quote_id and signed claims bound to the capability version, price, currency, terms and expiry, the checkout link and the unlock request; the price comes from the registry record only.

Input parameters:

- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
- `evaluation_id` (string): The evaluation_id from evaluate_capability, if you evaluated first.

### `unlock_capability` (~232 tokens)

Unlock a purchased capability

Exchange the license key from the checkout (a purchase requires operator approval) for a signed entitlement and a download link that lasts at most 15 minutes. How the key is handled: the privacy page at /legal/privacy/. Repeating it with the same key is safe and never charges. Use when: your operator completed the hosted checkout and gave you the license key. Not for: a price or a checkout link (get_quote); a free capability downloads from its page. Input: the capability id and the license key, plus quote_id and evaluation_id when you have them. Output: a signed entitlement, a purchase_ref for report_outcome and the download link.

Input parameters:

- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
- `evaluation_id` (string): The evaluation_id from evaluate_capability, if you evaluated first.
- `license_key` (string, required): License key from the checkout.
- `quote_id` (string): The quote_id of the quote the purchase followed, if any (links the records; never changes the price).

### `report_outcome` (~391 tokens)

Report an outcome

Report how a capability worked for you. Stored as AGENT REPORTED; it never changes evidence labels, trust or ranking. Only the listed fields are accepted; no task text is kept. Use when: you ran a capability, or decided not to, and can say whether the task succeeded. Not for: questions about a capability (get_capability, get_benchmark). Input: the capability id and success; add evaluation_id or purchase_ref to link the report, the optional token, tool-call, latency and cost counts, and failure_reason only with success false. Output: whether the report was stored, its label and, for a failed paid capability, the remedy policy.

Input parameters:

- `baseline_cost_estimate_usd` (number): What one run of this task costs you without the capability, in USD.
- `capability` (string, required): Capability id (ak:publisher:name or ak:publisher:name:x.y.z), ak:// URI or slug.
- `cost_usd` (number): What the run cost you in USD.
- `evaluation_id` (string): The evaluation_id from evaluate_capability, if you evaluated first.
- `failure_reason` (string): Only with success false.
- `latency_ms` (integer): Wall-clock time of the run in milliseconds.
- `model` (string): The model you run on, e.g. claude-sonnet-5. Savings are reported only for measured models.
- `purchase_ref` (string): The purchase_ref from unlock_capability, if you bought the capability.
- `success` (boolean, required): Whether the task reached its goal.
- `tokens_in` (integer): Input tokens the run used.
- `tokens_out` (integer): Output tokens the run used.
- `tool_calls` (integer): Tool calls the run made.
- `used_capability` (boolean): Whether the capability was used in this run; false reports a run done without it.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain#diagnostics

## Score history

- 2026-10-04: 76
- 2026-10-03: 74
- 2026-10-02: 75
- 2026-10-01: 75
- 2026-09-30: 74
- 2026-09-29: 74
- 2026-09-28: 73

## Common questions

### What is the Agentic Keychain MCP server?

Agentic Keychain is an MCP server listed in the public MCP registry as com.agentickeychain/agentic-keychain. Agent Skill ROI Registry & Benchmarking. It sells skills for log triage and repository mapping. This page covers its hosted endpoint (https://agentickeychain.com/mcp).

### Is the Agentic Keychain MCP server safe to use?

Agentic Keychain scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Agentic Keychain MCP server expose?

Agentic Keychain exposes 11 tools: resolve_task, evaluate_capability, search_capabilities, compare_capabilities, estimate_roi, and 6 more. Their descriptions and schemas cost roughly 2,872 tokens of context every time the server is loaded.

### Does the Agentic Keychain MCP server require authentication?

No. We connected to Agentic Keychain without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Agentic Keychain MCP server still maintained?

Agentic Keychain is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://agentickeychain.com/mcp
- Website: https://agentickeychain.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain.json
- HTML version of this page: https://verifymcp.io/servers/com-agentickeychain-agentic-keychain/agentickeychain
