Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. 💻 Developer Tools
  3. Kepil
K
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Kepil

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time — check back soon.
View Repository

Passport, mandate, fail-closed action gate and tamper-evident journal for AI agents.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON ▾
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself — its README, its docs, or a verified owner. We haven’t found those for kepil, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing Alternatives💻 More in Developer Tools

Documentation Overview

Kepil

PyPI License: AGPL v3

Accountability layer for AI agents. Give every agent a passport, put every action through one gate, and keep a log that cannot be rewritten afterwards.

53% of organisations have had an AI agent exceed its intended permissions. 48% of agents in production run with no monitoring at all. Only 22% treat an agent as an entity with its own identity. — Cloud Security Alliance and State of AI Agent Security, 2026

Kepil is what the other 78% are missing: identity, mandate, enforcement, evidence — and the part nobody else does, undo.

Terminal
pip install kepil
python -m kepil.admin        # http://localhost:7317

Русская версия: README.ru.md


What it does

Passport. Every agent version gets an immutable card: who built it, who runs it, what it does, what it will never do, its risk class, its autonomy class, its limits, and when its risks are due for review. A new version is a new card; the old one is kept forever.

Mandate. A machine-readable power of attorney for one job: allowed actions, allowed systems, spending limits, a validity window, and which action types must be confirmed by a human. Anything not explicitly allowed is refused.

Gate. The single point through which an agent touches the outside world. Every action is checked against the mandate before a model is even called. Fail-closed: any error inside the check means refusal, never a pass.

Journal. Append-only JSONL where every record carries the hash of the one before it. Editing or deleting a record is detectable — by anyone, using an independent implementation:

Terminal
npx proofbyte-agent-trace verify data/journal.jsonl

Undo. The journal is a graph of actions, and every profession declares its compensating action. Kepil walks that graph backwards and stops honestly at the first step that cannot be undone. Agent platforms record what happened; this one puts it back.

Confirmations on your phone. Irreversible actions arrive in Telegram with two buttons — approve or return — so being accountable does not mean sitting at a laptop.

Use it from any MCP client

Kepil ships an MCP server, so an editor, an assistant or another agent can work through it — and every action still passes the same gate into the same journal.

config.json
{
  "mcpServers": {
    "kepil": { "command": "python", "args": ["-m", "kepil.mcp"] }
  }
}

Seven tools: list professions, create an order, run a step, read order status, see what is waiting for a human, verify the journal, read an agent passport.

One tool is deliberately missing: confirmation. If a model could approve an irreversible action, the human would drop out of the chain and the whole design would be pointless. The confirmation card goes to a person — in the panel or in Telegram — and no MCP client can press it. A test enforces this.

Guard your existing automations

Kepil has a small JSON API, so an n8n workflow, a Make scenario or your own script can ask permission before acting:

Terminal
curl -X POST http://localhost:7317/api/check   -H "Authorization: Bearer $KEPIL_API_TOKEN"   -H "Content-Type: application/json"   -d '{"order_id":"ord-0042","action":"send:message","system":"whatsapp.local"}'
config.json
{ "decision": "await_human", "allowed": false, "needs_human": true,
  "reason": "необратимое действие: требуется подтверждение человека" }

The answer is recorded in the journal, so later you can show on what grounds the automation did — or did not do — something. For n8n there is a ready node: n8n-nodes-kepil.

The API stays off until you set a token (panel → Settings, or KEPIL_API_TOKEN). A panel bound to localhost is protected by the binding; a programmatic interface is not, so it is disabled by default.

An agent here is never fully autonomous

AgentPassport refuses to be constructed with the autonomy class where a human can no longer cancel a decision. That is a deliberate architectural limit rather than a missing feature — see ADR-0002. The gate enforces the same rule regardless of what a profession definition claims.

Professions: behaviour as data, not code

An agent's job is a JSON description: ordered steps, boundaries, limits, irreversible action patterns, rollback rules. Adding a new kind of work means adding a file — or filling in a form in the panel. The dangerous parts stay in code and under test.

Five ship with the project: inbound leads, process automation, bookkeeping documents, AI-adoption audit, public-procurement packages.

Undo that stops honestly

An order's journal is a sequence of actions and every profession declares the compensating action for each, so the panel can walk it backwards: pick a window, and the pass runs from the last action towards earlier ones, stopping at the first one that cannot be undone. What will happen is shown before the button is pressed, naming the step where the pass will stop — an undo promise that quietly fails is worse than no undo at all. The result is recorded as an operator's decision, which is why neither the MCP server nor the JSON API can roll anything back: an agent undoing its own actions would be signing in somebody else's name.

The panel

python -m kepil.admin opens an operator console: orders, professions, agent passports, a meter (actions, tokens, cost, human time replaced), the compliance generator, the journal with chain verification and anchoring, and settings.

State is plain JSON files under KEPIL_DATA (default ./data). No database: you can open them, read them, and attach them to a dispute.

The confirmation round trip is what witnesses the log

A hash chain proves the surviving records agree with each other. It says nothing about what was removed: cut the journal at record 3, rewrite everything after it with correct prev_hash values, and verification prints Integrity confirmed over a shorter history that is perfectly consistent with itself.

The fix was already in the design without being used. The confirmation card leaves the writer process and goes to a person, in the panel or in Telegram, and that round trip is the one artifact produced outside the writer. So the card now carries the current chain head, the decision that comes back quotes the head it saw, and the journal records it.

A rewritten prefix now has to contradict a message sitting somewhere the writer cannot reach. Verification stops being a self-consistency check and becomes a second party's statement about what the log looked like at a given moment.

Code
chain against itself:  Integrity confirmed
witnessed head:        confirmation at record 0 refers to root sha256:a3d124b9…,
                       which is no longer in the chain: the history was cut or
                       rewritten (3 such confirmations)

Records written after the last witnessed head stay unprotected. That is where the guarantee stops, and it says so.

This came from a reader, ANP2 Network, who described both the attack and the fix in one comment.

Survey: what the installation proves, and what a person must answer

A compliance survey is a list of questions bound to legal norms. Some of the answers are already in the installation — risk and autonomy class in the passport, documentation completeness in the pack, confirmations and stops in the journal. The rest a person has to answer: the provenance of training data, the feature list of a model, insurance contracts.

The panel runs a checklist and splits every item into three: closed by evidence from the installation, a gap, or needs a human. On a real installation about a fifth closes automatically. If it closed much more than that, the checklist would be incomplete.

Two properties are worth stating. A resolver returns a fact — "no high autonomy declared", "zero stops in the journal" — never a verdict of compliance; the conclusion and the signature stay with a person. And a checklist file references the name of a resolver declared in code and contains nothing executable, because otherwise a JSON file from elsewhere would be a way to run code on the machine that keeps the journal.

The integrity resolver reports the system's own weakness: if the chain root has never been fixed, or is fixed unsigned next to the journal, there is no outside witness and the whole history could be rewritten.

Code
8.2  needs a human   anchors exist, but 1 of 1 is unsigned and stored next to
                     the journal — there is no outside witness

Compliance packs

Documentation requirements differ by country and change faster than code, so the texts live outside the engine. The neutral pack shipped here follows international practice (ISO/IEC 42001, record-keeping in the spirit of the EU AI Act). Jurisdiction packs — for example Kazakhstan's AI Law No. 230-VIII with order No. 95/НҚ — are dropped into $KEPIL_DATA/packs as files.

Design rules

  • Zero dependencies. The core runs on the Python 3.11+ standard library, and CI fails the build if a third-party import appears. That keeps Kepil installable inside an air-gapped perimeter, and keeps the supply-chain attack surface of a tool that sees every action at zero.
  • Values never enter the journal — only types, counts and hashes.
  • The verifier is a separate implementation in another language. Proof that only its own author can check is not proof.

Related projects

Read the full README →View source on GitHub →

Related MCP Servers

View all in Developer Tools View all alternatives
  • O
    Openapi MCP Server

    Connect any HTTP/REST API server using an Open API spec (v3)

    💻 Developer Tools3 views
    Compare vs Openapi MCP Server →
  • C
    Claude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    💻 Developer Tools8 views
    Compare vs Claude Task Master →
  • N
    Next Devtools MCP
    Verified

    Official Next.js MCP server for coding agents. Provides runtime diagnostics, route inspection, dev server logs, docs search, and upgrade guides. Requires Next.js 16+ dev server for full runtime features.

    💻 Developer Tools6 views
    Compare vs Next Devtools MCP →
  • M
    MCP Server Docker

    Integrate with Docker to manage containers, images, volumes, and networks.

    💻 Developer Tools3 views
    Compare vs MCP Server Docker →

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about Kepil

We don't have a confirmed install command for kepil yet, so we don't publish a generated one — a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/oleg-vdv/kepil) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewKepil AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/kepil?style=directory)](https://allmcps.com/mcp/kepil)
HTML Embed
<a href="https://allmcps.com/mcp/kepil"><img src="https://allmcps.com/api/badge/kepil?style=directory" alt="Kepil on AllMCPs" /></a>

Technical Specs & Signals

Category💻Developer Tools
More technical detailsExpand ▾
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging · 27/100How this signal is calculated ▾
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

★ Featured
A

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in 💻 Developer Tools →Best MCP servers for Developers →Alternatives to Kepil →Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients