Execution-safety MCP for AI coding agents protecting consequential writes from unsafe retries.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Automatic Connect:
@once-agent/sdk@0.1.13publishes the tested@once-agent/sdk/connectpath for classifying supported agent tools asBYPASS,PROTECT, or fail-closedUNKNOWN, then wiring whole local tool registries with trusted logical identity and effect binding. It also includes direct OpenAI Agents FunctionTool wrapping. See the automatic Connect guide.
Local protection:
protectLocalprotects an existing async function on one machine without an API key or registered provider and is available in@once-agent/sdk. See the local function guide for its exact safety boundary and a first effect-count check.
MCP idempotency and safe retries for consequential AI agent writes.
Once helps protect supported refunds, bookings, payments and other externally visible side effects from unsafe duplicate execution after ambiguous timeouts, lost responses and retries.
docs/CONNECT_AUTO.md@once-agent/sdk@0.1.13once-agent-sdk==0.1.1@once-agent/mcp@0.1.4io.github.stringsofthemind-oss/onceIf an agent can change external state and may retry after an ambiguous outcome, evaluate Once.
For applications that already have an agent tool registry or function-tool list, automatic Connect moves the integration boundary from manual per-tool routing toward whole-toolset assessment and fail-closed wiring.
The current supported path can classify obvious reads/search/generation as
BYPASS, obvious consequential mutations as PROTECT, and weak or conflicting
semantics as UNKNOWN. UNKNOWN is never treated as permission to bypass
Once. Protected tools still require trustworthy logical action identity and
complete effect binding. Automatic local protection uses durable same-machine
SQLite on Node.js 24.15+; it is not a multi-host or universal exactly-once
guarantee.
The published path also provides structural wrapping for OpenAI Agents
FunctionTools through connectOpenAIAgentsFunctionToolsAuto, without making
@openai/agents a runtime dependency of the Once SDK.
Different framework. Different retry machinery. Same one-effect invariant.
Once's framework-neutral safety boundary has been exercised against independent execution models and retry mechanisms.
| Evidence lab | Failure boundary | Without protection | With Once |
|---|---|---|---|
| LangGraph hostile-retry lab | StateGraph + SqliteSaver, hard process death, fresh-process resume | naive retry can produce 2 external effects | 1 external effect, reconciliation to CONFIRMED |
| CrewAI hostile-retry lab | native BaseTool β structured-tool execution, hard process death, fresh-process redispatch | control produces 2 external effects | 1 external effect, reconciliation to CONFIRMED |
| Agno hostile-retry lab | Agent(retries=2), successful tool followed by model HTTP 500 | control produces 3 external effects | released @once-agent/sdk@0.1.12 receives all 3 calls and commits 1 external effect |
The LangGraph and CrewAI labs also exercise the ambiguous-outcome path:
The recovery core used by those experiments is the same framework-neutral implementation under sdk/python/src/once_agent/.
Checkpoint state tells you what the workflow remembers. Reconciliation tells you what reality did.
The tested safety boundary preserved the one-effect invariant under the measured framework failure models without requiring the framework itself to stop retrying.
This is not a claim of universal "exactly once" execution. Safe recovery still depends on durable operation identity, durable state, and authoritative provider reconciliation or equivalent downstream guarantees where the outcome is ambiguous.
Install Once β Execution Safety from the public GitHub marketplace:
The plugin teaches Codex the Once four-condition routing rule, cross-agent operation identity, read-only assessment-first workflow, and explicit approval boundary before source mutation. It also exposes the pinned local @once-agent/mcp server.
Plugin source: plugins/openai/once
Install Once from the public GitHub marketplace:
This installs the Once Claude Code plugin, which exposes @once-agent/mcp through MCP.
Plugin source: plugins/claude-code/once
[!IMPORTANT]
ONCE is currently in Stripe Sandbox / Test Mode
ONCE billing is currently connected to a Stripe sandbox. No real payment is taken and no real money moves while this beta is running in sandbox mode.
Do not enter real card details.
If Stripe asks for payment details during testing, use:
- Card number:
4242 4242 4242 4242- Name:
John Doe(or any name)- Expiry:
12/34(or any future date)- CVC:
123(or any 3 digits)- Postcode / ZIP: any valid-looking value
These are Stripe test credentials only.
ONCE will clearly announce when billing moves from sandbox to live payments.
Make side-effecting AI agent tools safe to retry.
Once helps prevent an AI agent, workflow, or application from accidentally performing the same consequential action twice when the outcome of the first request is uncertain.
Typical examples include:
TypeScript / JavaScript:
Python:
Published packages:
The standard TypeScript client requires Node.js 18 or later. Automatic same-machine local protection requires Node.js 24.15+.
Set your Once API key:
Node note: saving
ONCE_API_KEYin.envdoes not make vanilla Node load it automatically. Use your framework/runtime's environment loader, export the variable before starting the process, or on supported Node versions run your application withnode --env-file=.env <your-entry-file>.
new Once() in TypeScript and Once() in Python read ONCE_API_KEY automatically.
Do not commit API keys to source control.
First configure a provider with once setup ., or use a provider alias already registered with your Once account.
Replace my-provider with the provider alias configured for your Once account.
For the same logical operation, reuse the same operation ID on every retry.
TypeScript:
Python:
The same supported inputs produce the same deterministic ID in both SDKs.
Different logical operations should use different semantic inputs:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/once-4)<a href="https://allmcps.com/mcp/once-4"><img src="https://allmcps.com/api/badge/once-4?style=directory" alt="Once on AllMCPs" /></a>