A record of what an agent did that the agent cannot quietly rewrite, and a way for anyone to check.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
A record of what an agent did that the agent cannot quietly rewrite, and a way for anyone who doubts it to check.
Every row your agent writes is hash-chained to the row before it. Change a row, delete one, or swap two, and the check names the line where the chain breaks. Hand the file to someone else and they can run the same check without asking you for anything.
One package. One command: arcaeon <verb>.
Python 3.10 or newer. The base install has zero dependencies. That means pip
pulls in arcaeon and nothing else: no protocol SDK, no crypto library, no
parser. Everything in the Record, Prove and Save lists below runs on the
Python standard library. It also means no network on import. The hosted
verbs open a connection when you run them, and so do a few options that say
so: proxy --pin-witness, and receipt cite, which looks each citation up
online. Everything else works offline.
The heavy parts are extras. Add only what you use:
| extra | what it adds | what it pulls in |
|---|---|---|
arcaeon[mcp] | arcaeon mcp (the MCP server, and arcaeon mcp --tools), vet serve, vet probe | the MCP Python SDK and its dependencies (about 30 packages, including cryptography) |
arcaeon[ts] | vet's TypeScript checks | tree-sitter |
arcaeon[sign] | signed vet reports (badge --receipt, and SIGNED rather than UNSIGNED seals), receipt signature checks | cryptography |
arcaeon[all] | all three | all of the above |
Other ways in, same package:
pipx keeps arcaeon in a space of its own, apart from your other Python
packages, and still puts arcaeon on your path.
uvx (from uv) runs it once without keeping an install: the demo logs two
rows, changes one word and shows the BROKEN line.
On Windows, when pip is not found, the py launcher that comes with Python
installs it for your user alone, no administrator needed.
Log two rows, check them, change one word of history, check again. The lines
run as typed in PowerShell, cmd and a POSIX shell. --field KEY=VALUE builds
the row for you, so there is no JSON to quote; that matters on Windows, where
PowerShell 5.1 strips the inner double quotes from a JSON argument like
'{"tool": "search"}' before arcaeon ever sees it.
That is the whole idea. The edit was one word in the first row, and the check found it and named the line. Exit 0 means VERIFIED. Exit 1 means BROKEN. A CI gate can use the exit code alone.
What it did not catch: someone deleting the last rows. See Limits below, and
arcaeon pin, which is the fix.
Three families. The full reference, with usage lines and examples, is docs/VERBS.md.
log: add one JSON row to a ledger.verify: check a ledger's chain. VERIFIED, BROKEN or COULD NOT LOOK.receipt: issue or check a portable receipt someone else can verify.once: prove a side effect (a refund, an email) ran once, not twice.proxy: sit in front of an MCP server and record every tool call.pin: hand a ledger's current head to a witness, a local file or the hosted one.deal: a purchase recorded on both sides, step by step.reconcile: line up two tapes of the same calls. MATCHED, MISSING, ALTERED or COULD NOT LOOK.audit: check a log, pin its head, or export it as one bundle.vet: read an MCP server's source and grade it. No code runs.badge: a free Markdown badge and JSON report for an MCP server.seal: the same badge, sealed by the hosted witness. Paid.baseline: score a fixed probe set before a change and again after.compact: check a receipt that says what a context compaction dropped.distill: cut a tool's output to a token budget and record what was cut.dedup: drop near-copies from a list of texts.meter: per-key usage counts and monthly caps for your own tools.stamp, credits, buy: the hosted door (below).mcp: the MCP server (below).selftest: run every bundled self-check.version: print the version of the package and each part.stamp, pin --remote, seal and credits talk to the hosted witness at
witness.arcaeon.io, over HTTPS, and only when you run them. buy reads the
offers file bundled with the package and makes no request.
arcaeon stamp FILE: sends the file's sha256 and size, never its bytes.
Works without a key, inside a free daily allowance.arcaeon pin LEDGER --ns NAME --remote: records your ledger's head with
the hosted witness. Needs ARCAEON_KEY.arcaeon seal PATH: grades an MCP server,
then seals the report. Needs ARCAEON_KEY and nothing else, and uses one
credit. The witness's pin is the seal: it records your ledger's head and
checks no signature from your machine. With the arcaeon[sign] extra and a
signing key in MCP_VET_RECEIPT_KEY the report is also signed and the seal
says SIGNED; on the base install it says UNSIGNED and is sealed all the
same. Without ARCAEON_KEY nothing is sent, you still get the free badge,
and it exits 3. A key pins only under its own namespace prefix; you do not
need to know yours. If the default namespace is refused, seal reads your
prefix from the refusal (no credit spent) and pins under
<prefix>-sealed-scans. --ns still picks one yourself.arcaeon credits: shows your balance. Needs ARCAEON_KEY. Looking is free.arcaeon buy: prints a checkout link. It opens nothing and takes no card.
Payment happens on Stripe's page.ARCAEON_KEY is the one setting. Treat it like a password: a leaked key can
pin in your name. For plans and prices, see arcaeon.io/pricing.
arcaeon mcp starts the MCP server on stdio. It gives an agent the ledger,
vet and witness tools. arcaeon mcp --tools lists them without starting
anything; it needs the [mcp] extra too (on the base install it prints the
pip install 'arcaeon[mcp]' hint and exits 2).
A note for MCP registry listings: before 0.9, uvx arcaeon started this
server. It still does for 30 days after this release, when there is no verb
and stdin is not a terminal. Point your client at arcaeon mcp now. The
fallback is removed in 1.0.0.
One table for every verb. What each word means, in two sentences apiece, is in docs/WORDS.md.
| code | meaning |
|---|---|
| 0 | good: VERIFIED, MATCHED, COMPARED, a clean grade, or the command did what it said |
| 1 | a bad finding: BROKEN, MISSING, ALTERED, a high-severity grade, a receipt that does not check out |
| 2 | bad usage: the verb could not start on what it was given |
| 3 | COULD NOT LOOK: nothing wrong was found, and not everything could be checked |
3 is never a pass. A gate that treats only 0 as green fails on it, which is the point.
Many logs, one summary: keep the three counts side by side. Any summary arcaeon prints over many logs shows how many were VERIFIED, how many BROKEN and how many COULD NOT LOOK, never one rate. "98% verified" hides whether the other 2% were broken or simply never read, and those call for very different Monday mornings. If you build your own dashboard on the exit codes, keep the three columns too.
Before 0.9 some old tools used other codes for the same words (reconcile used
2 for COULD NOT LOOK, for example). For the 0.9.x releases, --legacy-exit on
a verb returns the old tool's own code, so a gate wired to it keeps working
while you rewire it. The flag goes away in 1.0.0. MIGRATION.md lists every
code that moved.
The short version, before the detail:
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/arcaeon)<a href="https://allmcps.com/mcp/arcaeon"><img src="https://allmcps.com/api/badge/arcaeon?style=directory" alt="Arcaeon on AllMCPs" /></a>