Deterministic AI audit layer: evaluates LLM/agent outputs against configurable policies (jailbreak, safety, quality, wallet, trade, MEV compliance) and writes every verdict to a tamper-evident SHA-256 hash chain β metadata only, never raw content. 17 tools including a full crypto-trading compliance suite. Pay-per-call via x402 (USDC on Base), from $0.01. mcp.fronesislabs.com/mcp
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Dcl Webhook.
X-GitHub-DeliveryCallable MCP tool function
activeCallable MCP tool function
owner_payer_refCallable MCP tool function
Don't trust the agent. Trust the proof.
Autonomous AI agents now take actions with real consequences β financial, legal, reputational. Most of them are black boxes: no record of what was decided, why, or whether that decision was tampered with afterward.
DCL Trust Oracle closes that gap. Every agent output is evaluated against policy in real time and sealed into a tamper-evident hash chain β a deterministic, cryptographically verifiable record of what happened and when. Edit any past entry and the entire chain invalidates. No one β not even Fronesis Labs β has to be trusted for the record to hold up.
DCL Trust Oracle provides deterministic policy evaluation for LLM outputs with a tamper-evident audit chain. The system stores only cryptographic hashes and decision metadata β never raw content β enabling verifiable, post-action forensic analysis across distributed AI agents.
Available two ways:
webhook_server.py) β direct HTTP integration.mcp_server.py) β native Model Context Protocol
integration for AI agents. Live at https://mcp.fronesislabs.com/mcp
(streamable-http). Also listed on Smithery
(remote URL β same production endpoint; see smithery.yaml) and the
official MCP Registry.Both servers share the same evaluation logic and tamper-evident chain
(dcl_core.py), and are priced identically.
Server runs on http://localhost:8080
Production (hosted):
Streamable HTTP transport β point any MCP client here directly, no setup required.
Local development:
Server runs on http://localhost:8081 (streamable-http transport)
Catch a bad output before it reaches a user, a wallet, or downstream system.
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
POST /evaluate/fast | dcl_evaluate_fast | $0.01 | Fast policy check for low-risk outputs. Returns tamper-evident tx_hash. |
POST /evaluate/strict | dcl_evaluate_strict | $0.05 | Deep analysis for high-stakes outputs with higher confidence thresholds. |
POST /evaluate/jailbreak | dcl_evaluate_jailbreak | $0.02 | Instruction adherence check β detects prompt injection patterns and role-hijacking attempts. |
POST /evaluate/safety | dcl_evaluate_safety | $0.01 | Baseline screening for known harmful text patterns. Optimized for high throughput. |
POST /evaluate/quality | dcl_evaluate_quality | $0.03 | Content quality & drift check β evaluates format adherence and contextual drift. |
POST /evaluate/batch | dcl_evaluate_batch | $0.10 | Bulk processing β up to 200 items per MCP call (REST default max_items: 20). Cost-effective for multi-turn history. |
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
POST /pipeline/start | dcl_pipeline_start | $0.05 | Initializes a long-running audit session for continuous drift tracking. Returns pipeline_id. |
When something did go wrong, reconstruct exactly what happened.
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
GET /audit/{tx_hash} | dcl_audit_decode | $0.10 | Basic post-action audit β returns verdict, confidence, agent_id, reason by tx_hash. |
GET /audit/{tx_hash}/deep | dcl_audit_decode_deep | $0.50 | Deep forensic audit β includes drift context, tamper-evidence indices, environmental metadata. |
| REST Endpoint | MCP Tool | Price | Description |
|---|---|---|---|
POST /evaluate/secrets | dcl_evaluate_secrets | $0.02 | Secret & credential leak scan. |
POST /evaluate/pii | dcl_evaluate_pii | $0.02 | PII detection scan. |
Continuous security auditing and release verification for AI Agent Skills and GitHub repositories. Sentinel monitors code updates via GitHub Webhooks, blocks regressions against your security baseline, and automatically recovers skill status upon clean rescans.
| REST Endpoint | Price | Description |
|---|---|---|
POST /sentinel/register | $49.00 / 30d | Register a skill/repo for continuous monitoring. Requires passing initial baseline audit (score >= 0.80; returns HTTP 422 if failed). Issues webhook_secret. |
POST /sentinel/webhook/{webhook_secret} | Free | GitHub Webhook receiver. Audits new release tags, blocks regressions, and logs tamper-evident events. |
POST /sentinel/scan | $0.05β$0.50 | Pay-per-call repository audit (update_rescan, deep_scan, forensic_audit). |
GET /sentinel/status/{repo_full_name} | Free | Query skill security status (active, blocked, unregistered) and last known good version. |
POST /sentinel/renew | $49.00 / 30d | Extend 30-day monitoring entitlement for a registered skill (owner-verified). |
GET /sentinel/prices | Free | Returns current price breakdown for Sentinel services. |
X-GitHub-Delivery tracking).status: blocked) are automatically restored to active once a clean, policy-compliant release is published.owner_payer_ref).score >= 0.80). Compromised or failing repositories are rejected immediately (HTTP 422) to prevent invalid entitlement setup.These tools are exposed on the live MCP server only (no REST routes in webhook_server.py).
| MCP Tool | Price | Description |
|---|---|---|
dcl_evaluate_jailbreak_crypto | $0.02 | Crypto-specific jailbreak & injection detection. |
dcl_evaluate_wallet | $0.02 | Wallet secret guardian. |
dcl_evaluate_trade | $0.02 | Trade decision verifier. |
dcl_evaluate_mev | $0.03 | MEV & market-abuse compliance screen. |
dcl_evaluate_signal | $0.03 | Market signal fabrication screen. |
dcl_evaluate_output_sanitizer | $0.02 | Output sanitizer β final gate. |
dcl_commit | $0.01 | Leibniz Layer crypto commit β seal a decision to the audit chain. |
| Endpoint | Description |
|---|---|
GET /health | Service status and chain length |
GET /policies | List of built-in policy names |
GET /chain/status | Chain integrity, drift mode, drift score |
GET /chain/export | Full chain export with integrity verification |
You don't have to take the server's word for it. tx_hash is recomputed
from the record's own fields, not just linked to the previous row β so
anyone can independently confirm a record wasn't edited after the fact,
without calling back into this server. See
@fronesis-labs/dcl-sdk (TS/JS)
or dcl-core (Python) for the
free, offline verification libraries.
Every paid call above is metered and settled automatically via the x402 protocol (USDC on Base).
We support two payment models:
This design eliminates API-key provisioning and invoicing overhead. Per-call pricing makes large-scale agent operations practical (an autonomous system can make thousands of evaluation calls a day).
The REST API is x402-gated via fastapi-x402; the MCP server uses
paymcp in Mode.X402, paying automatically for x402-aware clients and
falling back to a guided payment link for clients without a configured wallet.
Both settle to the same wallet, and neither has a bypass path β
an unpaid call simply receives no verdict.
Apache License 2.0 β see LICENSE.
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/fronesis-labs-dcl-webhook)<a href="https://allmcps.com/mcp/fronesis-labs-dcl-webhook"><img src="https://allmcps.com/api/badge/fronesis-labs-dcl-webhook?style=directory" alt="Dcl Webhook on AllMCPs" /></a>