Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

AgentLedger

REMOTE · AIAGENTSCITY.COM · SCANNED SEP 20

Meter, cap, and block AI agent spend before the provider is charged.

Available components

68 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability81
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1892 tokens (~145/item across 13 items; 12 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 87% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the AgentLedger MCP server?

AgentLedger is a hosted endpoint at https://aiagentscity.com/mcp/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · aiagentscity.com

# add to Claude Code
claude mcp add --transport http entradox-agent-ledger 'https://aiagentscity.com/mcp/'
// .cursor/mcp.json
{
  "mcpServers": {
    "entradox-agent-ledger": {
      "url": "https://aiagentscity.com/mcp/"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "entradox-agent-ledger": {
      "type": "http",
      "url": "https://aiagentscity.com/mcp/"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.entradox-agent-ledger]
url = "https://aiagentscity.com/mcp/"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "entradox-agent-ledger": {
      "type": "remote",
      "url": "https://aiagentscity.com/mcp/",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add entradox-agent-ledger --url 'https://aiagentscity.com/mcp/' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  entradox-agent-ledger:
    url: "https://aiagentscity.com/mcp/"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "entradox-agent-ledger": {
      "Transport": "http",
      "Url": "https://aiagentscity.com/mcp/"
    }
  }
}
# add to Vellum
assistant mcp add entradox-agent-ledger -t streamable-http -u 'https://aiagentscity.com/mcp/'
// mcp.json
{
  "mcpServers": {
    "entradox-agent-ledger": {
      "type": "http",
      "url": "https://aiagentscity.com/mcp/"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 19 Sept 26 0
    • Schema quality: 1638 → 1892 functional
    • Schema quality: good → excellent functional
    • New tool “ledger_start” functional
  • 18 Sept 26 +1
    • Server version: 4.0.3 → 4.0.5 functional
  • 17 Sept 26 +2
    • First check of Schema quality: 100 functional
    • Schema quality: excellent → good functional
    • New resource “agent-ledger” functional
  • 15 Sept 26 +1
    • Schema quality: 161 → 141 functional
    • Stability: unverified → 0.03 functional
    • Schema quality: good → excellent functional
    • New tool “skills_list_tool” functional
    • New tool “read_skill” functional
  • 14 Sept 26 63

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://aiagentscity.com/mcp/

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=aiagentscity.com CN=YE2,O=Let's Encrypt,C=US 13 Sept 2026 12 Dec 2026 ECDSA 256 ECDSA-SHA384 630f38597024e1187d5b4e13d3561409b8d
SANs: aiagentscity.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of aiagentscity.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
aiagentscity.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://aiagentscity.com/mcp/ Verified 200
http (plaintext) http://aiagentscity.com/mcp/ HTTPS enforced 301 https://aiagentscity.com/mcp/
MCP tools · 12 exposed · ~1,809 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
ledger_alerts ~104

Alert history for an agent: budget warnings (80% threshold) and spending spikes. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/alerts).

NameTypeReqDescription
agent_idstringyesunique agent identifier
agent_secretstringthe agent's own secret (either this or workspace_key)
workspace_keystringthe owning workspace's key (either this or agent_secret)

Structured output declared, but exposes no named fields.

No examples provided.

ledger_api_docs ~97

Self-serve documentation for AgentLedger — quickstart, MCP tools, REST endpoints, budget caps, error codes, and idempotency usage, as markdown.

NameTypeReqDescription
topicstring"quickstart" | "mcp" | "rest" | "budget" | "errors" | "idempotency" | "all" (default "" == "all"). Unknown topics fall back to the full docs.

Structured output declared, but exposes no named fields.

No examples provided.

ledger_examples ~51

Complete, runnable Python recipe for a common AgentLedger integration pattern.

NameTypeReqDescription
patternstringyes"python_tracking" | "budget_enforcement" | "weekly_report" | "retry_safe_writes"

Structured output declared, but exposes no named fields.

No examples provided.

ledger_list_agents ~89

Owner-only: full cross-tenant listing of every agent ever claimed on this instance, with totals. Requires the operator's admin_secret — this is a portfolio-wide view, not a per-agent report (use ledger_report for that — it requires that agent's agent_secret or its workspace_key).

NameTypeReqDescription
admin_secretstringoperator admin secret (not the same as an agent_secret)

Structured output declared, but exposes no named fields.

No examples provided.

ledger_report ~137

Spend report for an agent over a rolling window. Returns total spend, breakdown by rail and by service, budget status (ok/warning/exceeded), detected anomalies, and entry count. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/report).

NameTypeReqDescription
agent_idstringyesunique agent identifier
agent_secretstringthe agent's own secret (either this or workspace_key)
daysintegerreport window in days (default 30)
workspace_keystringthe owning workspace's key (either this or agent_secret)

Structured output declared, but exposes no named fields.

No examples provided.

ledger_revoke_secret ~129

Invalidate an agent_id's agent_secret WITHOUT deleting its spend history. Use when a credential may have leaked, or to stop an agent writing. Subsequent writes to that agent fail with agent_secret_mismatch until you rotate a new secret in. The agent_id stays claimed, so no other workspace can claim it and inherit the ledger. Requires the workspace_key that owns agent_id. Returns {"agent_id", "revoked": True, "_note"}, or {"error", "error_code"}.

NameTypeReqDescription
agent_idstringyes
workspace_keystringyes

Structured output declared, but exposes no named fields.

No examples provided.

ledger_rotate_secret ~160

Mint a NEW agent_secret for an agent_id your workspace already owns, invalidating the old one. Use this to RECOVER an agent whose secret was lost: the previous credential stops working immediately. Requires the workspace_key that owns agent_id — an agent's own agent_secret cannot rotate itself, because a leaked agent credential must not be able to lock its real owner out. Unlike ledger_track this never claims a new agent_id: an unknown id returns agent_not_claimed. The new secret is returned ONCE. Store it before you drop the response. Returns {"agent_id", "agent_secret", "_note"}, or {"error", "error_code"}.

NameTypeReqDescription
agent_idstringyes
workspace_keystringyes

Structured output declared, but exposes no named fields.

No examples provided.

ledger_set_budget ~304

Set spending caps for an agent. Warns at 80%, blocks spend when exceeded — enforced: a ledger_track call that would cross the cap is rejected. Dollar caps (monthly_cents/daily_cents) and token caps (monthly_tokens/ daily_tokens) are independent dimensions: dollar caps only cover non-"tokens" rails, token caps only cover rail="tokens" bookkeeping rows (tokens_in/tokens_out). Set both if the agent uses both. Monthly cap is required; the rest are optional (0 = no limit). Overwrites any existing budget for the agent. Claiming a brand-new agent_id requires your workspace_key; that first call mints an agent_secret (returned once — save it); later calls for that agent_id must pass the agent_secret back (no workspace_key needed again).

NameTypeReqDescription
agent_idstringyesunique agent identifier
agent_secretstringrequired for every call after the first for this agent_id
daily_centsintegerdaily spending cap in cents (0 = no daily cap)
daily_tokensintegerdaily token-burn cap (0 = no cap)
monthly_centsintegeryesmonthly spending cap in cents
monthly_tokensintegermonthly token-burn cap (0 = no cap)
workspace_keystringrequired when claiming a brand-new agent_id; not needed once the agent_id has been claimed

Structured output declared, but exposes no named fields.

No examples provided.

ledger_start ~254

Get a FREE AgentLedger workspace with no credential and no arguments — the MCP equivalent of opening POST /start in a browser. Call this FIRST if you have no credentials yet. Every other tool here (ledger_track, ledger_set_budget, ledger_report, ledger_alerts) needs a workspace_key or an agent_secret, so a caller arriving with neither must start here or it has nowhere to go. Takes NO arguments on purpose: the goal is zero friction. It returns a `workspace_key` (shown exactly once — it cannot be re-revealed, so store it before continuing) which you then send as `workspace_key` on your first ledger_track for a NEW agent_id. That first write returns the agent's own `agent_secret`, which authenticates every write after it. The free tier includes every rail, enforced budget caps, alerts, reports and the MCP server, capped at 3 agents per workspace. Minting is rate-limited per caller IP, the same limit the human door uses. Prefer to pay? POST /v1/billing/x402 with a wallet-signed payment needs no human and buys 24h of Pro (unlimited agents).

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

ledger_track ~383

Record a spend entry for an AI agent on any payment rail, with optional token counts. Claiming a brand-new agent_id requires your workspace_key (get one via x402 at POST /v1/billing/x402 — no human, no login — or at /start). That first call mints an agent_secret and returns it in the response — save it, every later call for that same agent_id must pass it back (no workspace_key needed again) or the write is rejected. Amounts are capped at $100,000/entry and must be >= 0. If a budget is set for this agent, an entry that would cross the monthly/daily cap is blocked, not just logged. Include tokens_in/tokens_out + model on every LLM call so token burn shows up in the /v1/tokens report.

NameTypeReqDescription
agent_idstringyesunique agent identifier (e.g. "research-agent-v2")
agent_secretstringrequired for every call after the first for this agent_id
amount_centsintegeryesspend amount in cents (100 = $1.00), 0-10000000
modelstringmodel name (e.g. "gpt-4o") — token burn is reported per model
railstringyespayment rail used — one of "mpp", "x402", "api_key", "manual"
servicestringyeswhat was purchased (e.g. "search_query", "data_export")
tokens_inintegerprompt tokens consumed (0 if unknown)
tokens_outintegercompletion tokens consumed (0 if unknown)
workspace_keystringrequired when claiming a brand-new agent_id; not needed once the agent_id has been claimed

Structured output declared, but exposes no named fields.

No examples provided.

read_skill ~50

Read a product skill file by its skill:// URI.

NameTypeReqDescription
uristringyese.g. skill://<product>/<skill-name>/SKILL.md Get valid URIs from `skills_list_tool`.

Structured output declared, but exposes no named fields.

No examples provided.

skills_list_tool ~51

List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the AgentLedger MCP server?

AgentLedger is an MCP server listed in the public MCP registry as io.github.entradox/agent-ledger. Meter, cap, and block AI agent spend before the provider is charged. This page covers its hosted endpoint (https://aiagentscity.com/mcp/).

Is the AgentLedger MCP server safe to use?

AgentLedger scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the AgentLedger MCP server expose?

AgentLedger exposes 12 tools: ledger_rotate_secret, ledger_revoke_secret, ledger_track, ledger_set_budget, ledger_report, and 7 more. Their descriptions and schemas cost roughly 1,809 tokens of context every time the server is loaded.

Does the AgentLedger MCP server require authentication?

No. We connected to AgentLedger without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the AgentLedger MCP server still maintained?

AgentLedger is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.