AgentLedger
REMOTE · AIAGENTSCITY.COM · SCANNED SEP 20
Meter, cap, and block AI agent spend before the provider is charged.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (ledger_rotate_secret). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1892 tokens (~145/item across 13 items; 12 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
- Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 87% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the AgentLedger MCP server?
AgentLedger is a hosted endpoint at https://aiagentscity.com/mcp/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · aiagentscity.com
claude mcp add --transport http entradox-agent-ledger 'https://aiagentscity.com/mcp/'
{
"mcpServers": {
"entradox-agent-ledger": {
"url": "https://aiagentscity.com/mcp/"
}
}
} {
"servers": {
"entradox-agent-ledger": {
"type": "http",
"url": "https://aiagentscity.com/mcp/"
}
}
} [mcp_servers.entradox-agent-ledger] url = "https://aiagentscity.com/mcp/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"entradox-agent-ledger": {
"type": "remote",
"url": "https://aiagentscity.com/mcp/",
"enabled": true
}
}
} openclaw mcp add entradox-agent-ledger --url 'https://aiagentscity.com/mcp/' --transport streamable-http
mcp_servers:
entradox-agent-ledger:
url: "https://aiagentscity.com/mcp/" {
"McpServers": {
"entradox-agent-ledger": {
"Transport": "http",
"Url": "https://aiagentscity.com/mcp/"
}
}
} assistant mcp add entradox-agent-ledger -t streamable-http -u 'https://aiagentscity.com/mcp/'
{
"mcpServers": {
"entradox-agent-ledger": {
"type": "http",
"url": "https://aiagentscity.com/mcp/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 0
- Schema quality: 1638 → 1892 ▼ functional
- Schema quality: good → excellent functional
- New tool “ledger_start” functional
- 18 Sept 26 +1
- Server version: 4.0.3 → 4.0.5 functional
- 17 Sept 26 +2
- First check of Schema quality: 100 functional
- Schema quality: excellent → good functional
- New resource “agent-ledger” functional
- 15 Sept 26 +1
- Schema quality: 161 → 141 ▲ functional
- Stability: unverified → 0.03 ▲ functional
- Schema quality: good → excellent functional
- New tool “skills_list_tool” functional
- New tool “read_skill” functional
- 14 Sept 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://aiagentscity.com/mcp/
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=aiagentscity.com | CN=YE2,O=Let's Encrypt,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 630f38597024e1187d5b4e13d3561409b8d |
| SANs: aiagentscity.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of aiagentscity.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| aiagentscity.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://aiagentscity.com/mcp/ | Verified | 200 | |
| http (plaintext) | http://aiagentscity.com/mcp/ | HTTPS enforced | 301 | https://aiagentscity.com/mcp/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ledger_alerts Agent Budget Alerts ~104
Alert history for an agent: budget warnings (80% threshold) and spending spikes. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/alerts).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | unique agent identifier |
| agent_secret | string | – | the agent's own secret (either this or workspace_key) |
| workspace_key | string | – | the owning workspace's key (either this or agent_secret) |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_api_docs AgentLedger API Docs ~97
Self-serve documentation for AgentLedger — quickstart, MCP tools, REST endpoints, budget caps, error codes, and idempotency usage, as markdown.
| Name | Type | Req | Description |
|---|---|---|---|
| topic | string | – | "quickstart" | "mcp" | "rest" | "budget" | "errors" | "idempotency" | "all" (default "" == "all"). Unknown topics fall back to the full docs. |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_examples AgentLedger Recipes ~51
Complete, runnable Python recipe for a common AgentLedger integration pattern.
| Name | Type | Req | Description |
|---|---|---|---|
| pattern | string | yes | "python_tracking" | "budget_enforcement" | "weekly_report" | "retry_safe_writes" |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_list_agents List Tracked Agents ~89
Owner-only: full cross-tenant listing of every agent ever claimed on this instance, with totals. Requires the operator's admin_secret — this is a portfolio-wide view, not a per-agent report (use ledger_report for that — it requires that agent's agent_secret or its workspace_key).
| Name | Type | Req | Description |
|---|---|---|---|
| admin_secret | string | – | operator admin secret (not the same as an agent_secret) |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_report Agent Spend Report ~137
Spend report for an agent over a rolling window. Returns total spend, breakdown by rail and by service, budget status (ok/warning/exceeded), detected anomalies, and entry count. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/report).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | unique agent identifier |
| agent_secret | string | – | the agent's own secret (either this or workspace_key) |
| days | integer | – | report window in days (default 30) |
| workspace_key | string | – | the owning workspace's key (either this or agent_secret) |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_revoke_secret Revoke Agent Secret ~129
Invalidate an agent_id's agent_secret WITHOUT deleting its spend history. Use when a credential may have leaked, or to stop an agent writing. Subsequent writes to that agent fail with agent_secret_mismatch until you rotate a new secret in. The agent_id stays claimed, so no other workspace can claim it and inherit the ledger. Requires the workspace_key that owns agent_id. Returns {"agent_id", "revoked": True, "_note"}, or {"error", "error_code"}.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | – |
| workspace_key | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_rotate_secret Rotate Agent Secret ~160
Mint a NEW agent_secret for an agent_id your workspace already owns, invalidating the old one. Use this to RECOVER an agent whose secret was lost: the previous credential stops working immediately. Requires the workspace_key that owns agent_id — an agent's own agent_secret cannot rotate itself, because a leaked agent credential must not be able to lock its real owner out. Unlike ledger_track this never claims a new agent_id: an unknown id returns agent_not_claimed. The new secret is returned ONCE. Store it before you drop the response. Returns {"agent_id", "agent_secret", "_note"}, or {"error", "error_code"}.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | – |
| workspace_key | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_set_budget Set Agent Budget ~304
Set spending caps for an agent. Warns at 80%, blocks spend when exceeded — enforced: a ledger_track call that would cross the cap is rejected. Dollar caps (monthly_cents/daily_cents) and token caps (monthly_tokens/ daily_tokens) are independent dimensions: dollar caps only cover non-"tokens" rails, token caps only cover rail="tokens" bookkeeping rows (tokens_in/tokens_out). Set both if the agent uses both. Monthly cap is required; the rest are optional (0 = no limit). Overwrites any existing budget for the agent. Claiming a brand-new agent_id requires your workspace_key; that first call mints an agent_secret (returned once — save it); later calls for that agent_id must pass the agent_secret back (no workspace_key needed again).
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | unique agent identifier |
| agent_secret | string | – | required for every call after the first for this agent_id |
| daily_cents | integer | – | daily spending cap in cents (0 = no daily cap) |
| daily_tokens | integer | – | daily token-burn cap (0 = no cap) |
| monthly_cents | integer | yes | monthly spending cap in cents |
| monthly_tokens | integer | – | monthly token-burn cap (0 = no cap) |
| workspace_key | string | – | required when claiming a brand-new agent_id; not needed once the agent_id has been claimed |
Structured output declared, but exposes no named fields.
No examples provided.
ledger_start Start a Workspace ~254
Get a FREE AgentLedger workspace with no credential and no arguments — the MCP equivalent of opening POST /start in a browser. Call this FIRST if you have no credentials yet. Every other tool here (ledger_track, ledger_set_budget, ledger_report, ledger_alerts) needs a workspace_key or an agent_secret, so a caller arriving with neither must start here or it has nowhere to go. Takes NO arguments on purpose: the goal is zero friction. It returns a `workspace_key` (shown exactly once — it cannot be re-revealed, so store it before continuing) which you then send as `workspace_key` on your first ledger_track for a NEW agent_id. That first write returns the agent's own `agent_secret`, which authenticates every write after it. The free tier includes every rail, enforced budget caps, alerts, reports and the MCP server, capped at 3 agents per workspace. Minting is rate-limited per caller IP, the same limit the human door uses. Prefer to pay? POST /v1/billing/x402 with a wallet-signed payment needs no human and buys 24h of Pro (unlimited agents).
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
ledger_track Track Agent Spend ~383
Record a spend entry for an AI agent on any payment rail, with optional token counts. Claiming a brand-new agent_id requires your workspace_key (get one via x402 at POST /v1/billing/x402 — no human, no login — or at /start). That first call mints an agent_secret and returns it in the response — save it, every later call for that same agent_id must pass it back (no workspace_key needed again) or the write is rejected. Amounts are capped at $100,000/entry and must be >= 0. If a budget is set for this agent, an entry that would cross the monthly/daily cap is blocked, not just logged. Include tokens_in/tokens_out + model on every LLM call so token burn shows up in the /v1/tokens report.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | yes | unique agent identifier (e.g. "research-agent-v2") |
| agent_secret | string | – | required for every call after the first for this agent_id |
| amount_cents | integer | yes | spend amount in cents (100 = $1.00), 0-10000000 |
| model | string | – | model name (e.g. "gpt-4o") — token burn is reported per model |
| rail | string | yes | payment rail used — one of "mpp", "x402", "api_key", "manual" |
| service | string | yes | what was purchased (e.g. "search_query", "data_export") |
| tokens_in | integer | – | prompt tokens consumed (0 if unknown) |
| tokens_out | integer | – | completion tokens consumed (0 if unknown) |
| workspace_key | string | – | required when claiming a brand-new agent_id; not needed once the agent_id has been claimed |
Structured output declared, but exposes no named fields.
No examples provided.
read_skill Read Skill ~50
Read a product skill file by its skill:// URI.
| Name | Type | Req | Description |
|---|---|---|---|
| uri | string | yes | e.g. skill://<product>/<skill-name>/SKILL.md Get valid URIs from `skills_list_tool`. |
Structured output declared, but exposes no named fields.
No examples provided.
skills_list_tool Skills List Tool ~51
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
What is the AgentLedger MCP server?
AgentLedger is an MCP server listed in the public MCP registry as io.github.entradox/agent-ledger. Meter, cap, and block AI agent spend before the provider is charged. This page covers its hosted endpoint (https://aiagentscity.com/mcp/).
Is the AgentLedger MCP server safe to use?
AgentLedger scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the AgentLedger MCP server expose?
AgentLedger exposes 12 tools: ledger_rotate_secret, ledger_revoke_secret, ledger_track, ledger_set_budget, ledger_report, and 7 more. Their descriptions and schemas cost roughly 1,809 tokens of context every time the server is loaded.
Does the AgentLedger MCP server require authentication?
No. We connected to AgentLedger without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the AgentLedger MCP server still maintained?
AgentLedger is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.