The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the LoopGrid MCP listing page.
MCP access to the LoopGrid evidence plane for consequential AI and agent decisions.
loopgrid-mcp is a thin Model Context Protocol (MCP) bridge for LoopGrid.
It lets an MCP-compatible AI host record and retrieve signed, tamper-evident decision evidence through six MCP tools while keeping the MCP layer separate from the LoopGrid core runtime.
The bridge communicates with LoopGrid exclusively through its REST API. It does not import LoopGrid internals, access the LoopGrid database directly, change signing logic, alter the evidence schema, or modify the existing LoopGrid SDK contracts.
Current version:
Available through:
loopgrid-mcpgithub.com/loopgridio/loopgrid-mcpio.github.loopgridio/loopgrid-mcpThe official MCP Registry entry is active and currently points to the PyPI 0.1.0 package using local stdio transport.
The v0.1 release uses local stdio transport.
No separate hosted MCP service, Railway deployment, Render deployment, AWS service, or MCP-specific database is required.
The server exposes six tools:
loopgrid.record_decisionloopgrid.record_reviewloopgrid.record_actionloopgrid.record_outcomeloopgrid.get_evidenceloopgrid.verify_evidenceLoopGrid MCP is an evidence bridge, not a business-action executor.
loopgrid.record_action does not issue a Stripe refund, modify Salesforce, change ServiceNow, or invoke another external business system. It records evidence supplied by the calling integration that an external action occurred.
Likewise, loopgrid.record_outcome records an outcome reported by the calling integration.
LoopGrid can cryptographically verify the integrity of the captured record. That verification does not independently prove that every external-world claim in the record is true and does not determine legal or regulatory compliance.
Human review receives additional protection. loopgrid.record_review is registered as an MCP tool but is disabled by default. To enable it, an operator must explicitly configure both the review flag and reviewer identity. The model cannot choose the configured reviewer identity.
Raw FULL-mode disclosure payloads are also excluded from MCP evidence export by default.
Normal use of the Python stdio server does not require Node.js.
Node.js is only needed for optional browser-based MCP Inspector tooling.
The project uses the official MCP Python SDK v2 line:
For local evaluation using Docker:
Leave the LoopGrid container running.
By default, LoopGrid MCP expects the service at:
Create a Python virtual environment:
Install the published package:
Run:
Expected shape:
The local evaluation configuration does not require a service key when LoopGrid authentication is disabled.
Run:
Because this is a stdio MCP server, running it directly normally causes it to wait for MCP messages on standard input.
In normal use, an MCP-compatible host starts this command for you.
A generic client configuration looks like:
On Windows, some MCP hosts may require the full path to the executable, for example:
See:
for an example.
For development or repository validation:
Then verify connectivity:
Run:
Run:
Run:
The smoke test creates a synthetic decision, records synthetic action and outcome evidence, verifies the decision, and downloads an evidence ZIP.
It does not call a real external business system.
Run:
This launches loopgrid-mcp as a child stdio server using the official MCP Python client and verifies:
A successful run ends with:
This is the recommended automated release-gate test for the MCP protocol path.
The browser-based MCP Inspector can be useful for manual exploration, but it is not required to run or validate LoopGrid MCP.
The canonical automated protocol test in this repository remains:
If your installed MCP development tooling supports the Inspector cleanly, you can also try:
loopgrid.record_decisionCaptures a decision through the LoopGrid REST API.
Optional inputs can also append model evidence and evaluate an existing LoopGrid policy.
It never executes proposed_action.
Example:
loopgrid.record_reviewRecords an approve/reject review through the LoopGrid review endpoint.
This tool is disabled by default.
To enable it deliberately:
When LoopGrid authentication is enabled, the configured service key must also have the appropriate review scope.
loopgrid.record_actionAppends tool_executed evidence to the decision record.
It does not execute the external tool.
Canonical fields such as the tool name cannot be overwritten by free-form details.
loopgrid.record_outcomeAppends outcome_observed evidence.
The calling integration is responsible for obtaining the real downstream outcome.
Canonical fields such as status and verified_against cannot be overwritten by free-form details.
loopgrid.get_evidenceDownloads the portable LoopGrid evidence ZIP to:
The default directory is:
Raw disclosure payloads are blocked from MCP evidence export unless explicitly enabled:
loopgrid.verify_evidenceAsks the connected LoopGrid service to verify the decision's signed workspace chain.
This is service-side verification.
Independent/offline verification of an exported evidence bundle should use the corresponding LoopGrid evidence-verification workflow rather than duplicating that verifier inside the MCP bridge.
For local evaluation with LoopGrid authentication disabled, no service key is required.
When authentication is enabled:
Use the minimum scopes required by the MCP tools you enable.
Do not use an administrative key unless administration is genuinely required.
See:
for the complete supported environment-variable configuration.
Common settings include:
The bridge does not automatically load .env.
The MCP host should inject environment variables, or the operator should configure them in the environment that starts the server.
The LoopGrid service URL is operator configuration rather than an MCP tool argument. This prevents a model from redirecting the bridge to an arbitrary LoopGrid host through a tool call.
LoopGrid supports evidence workflows with different disclosure levels.
The MCP bridge follows conservative defaults:
LoopGrid core and LoopGrid MCP intentionally remain separate:
The MCP bridge communicates with the LoopGrid core runtime only over HTTP.
LoopGrid MCP 0.1.0 has been validated on Windows against the public LoopGrid 0.8.1-design-partner container.
Validation included:
The official MCP Python client successfully negotiated MCP protocol:
See VALIDATION.md for the detailed release-gate record.
LoopGrid MCP is published in the official MCP Registry as:
Current Registry version:
Registry metadata:
The Registry entry is publicly discoverable and points to:
The corresponding Python package is published as:
The hidden ownership marker near the top of this README:
is intentionally retained because it is used for MCP Registry package ownership verification.
For future releases:
server.json to the same version;server.json with mcp-publisher;0.1.0 is a design preview, not Production GA.
It is intended to validate a clean MCP integration path for LoopGrid v0.8.x without changing LoopGrid's signing, hash-chain, evidence-bundle, verification, or SDK contracts.
LoopGrid provides signed, tamper-evident evidence and append-only decision history. Verification confirms the integrity of the captured record; it does not determine legal compliance.
Apache-2.0.
See LICENSE.