Attested multi-agent consensus: proposals, votes, and outcomes stamped and traced.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Attested multi-agent consensus with a shared blackboard β an MCP server.
An orchestrator opens a proposal, participating agents write context to a shared blackboard and vote with reasoning, Quorum applies a principled aggregation algorithm from the social choice literature, and every step β proposal, writes, votes, outcome β is attested via Stamp and traced to Telinea. The record is immutable, tamper-evident, and independently verifiable.
Hosted endpoint (no sign-in, public):
https://quorum-mcp.terradev.cloud/mcp
Majority vote among LLM agents fails on disputed questions because agents trained on overlapping data share systematic blind spots β they are not the independent voters the Condorcet Jury Theorem requires. And when agents do decide together, the decision process β who voted, what they said, what context they worked from β is invisible.
Quorum is the complete primitive: algorithm plus state plus provenance.
register β one-time account setup: bind your api_key (a Quorum
key you choose) to your telinea_key. The Telinea key is stored
encrypted under a key derived from your Quorum key (AES-256-GCM,
HKDF) β the Quorum key itself is never stored. Every span for your
proposals is then pushed with your Telinea key, standard OTLP bearer
auth.
propose β open a proposal: name (becomes the proposal id),
question, voters (expected identities), deadline_minutes.
Optional: api_key (from register β binds the proposal to your
Telinea account for span streaming; omit for anonymous use),
namespace (tenant prefix β the id becomes ns:name, so different
teams can reuse names without colliding), options (default
["yes","no"]), algorithm (default approval), quorum (min %
of voters, default 100), threshold (supermajority share, default
66.67), description. Returns the proposal id, creation attestation
id, deadline, and blackboard URI.
write β append key/value to the proposal's blackboard, with
optional author. Writes are appended, never replaced β the full
ordered history is preserved and attested.
read β read the blackboard: every write in order with timestamp,
author, and attestation id. Optional key filter. The deliberation
record before voting.
vote β submit a ballot from an expected voter identity, with
optional reasoning (stored in the attested record, never affects the
outcome). Ballot shape depends on the algorithm β see below. Duplicate
votes and post-deadline votes are rejected with structured errors.
resolve β apply the algorithm and attest the outcome. Callable
once quorum is met (or after the deadline); also fires automatically
when the deadline passes with quorum. Idempotent. Condorcet cycles and
missed supermajority thresholds return co_winners with status
unresolved β genuine ambiguity is surfaced, never hidden.
history β the complete attested record: creation, every write,
every vote with reasoning, the outcome. Optional filter:
all | writes | votes | outcome. The compliance artifact.
| Algorithm | Ballot | Use when |
|---|---|---|
plurality | option string | Binary decisions only |
approval | option or list of options | Default. No strategic incentive; weak/multiple preferences |
borda | ranking of all options | 3β5 options; surfaces the broadly-acceptable choice |
condorcet | ranking or single option | Rational preference aggregation; cycles returned as co_winners |
opinion_pool | {option: probability} summing to 1 | Genuine probabilistic beliefs; returns full distribution |
supermajority | option string | High-stakes decisions needing >50% (set threshold) |
LLM consensus failures are often information failures, not algorithm failures β agents vote in isolation. The blackboard is shared working memory scoped to one proposal: agents write analysis, read each other's findings, then vote informed. Write-first, read-second ordering and immutable pre-deadline votes are the conformity-bias defenses.
Every proposal is one Telinea trace. The root span (proposal) opens at
propose and closes at resolve or deadline expiry β its duration is
the deliberation time. Each write, vote, and the resolution is a child
span emitted in real time with its Stamp attestation id. Root status:
OK decided, UNRESOLVED ambiguous, ERROR expired without quorum.
Span ids are deterministic (uuid5 over proposal id + event seq), so replays and restarts stay idempotent. Push is fire-and-forget and fail-safe β telemetry can never break a vote.
Auth is per-account: spans are pushed with the Telinea key registered
via register, so ingest attributes them to the correct account. The
key is stored encrypted (AES-256-GCM under HKDF of your Quorum key β
never stored); a proposal-scoped re-encryption under the server-held
QUORUM_DATA_KEY lets spans authenticate after restarts without
re-presenting the Quorum key. A database dump exposes only ciphertext.
Config: TELINEA_INGEST_URL (default
https://ingest.terradev.cloud/v1/traces), TELINEA_WORKSPACE_ID,
TELINEA_PROJECT_ID, TELINEA_DISABLED=1, QUORUM_DATA_KEY,
QUORUM_ACCOUNTS (account store path, default
~/.quorum/accounts.json).
| Endpoint | Method | Description |
|---|---|---|
/mcp | POST | JSON-RPC 2.0 β single or batch; notifications β 202 |
/mcp | GET | SSE keep-alive channel |
/ | GET/POST | Service identity / MCP alias |
/health | GET | {"status":"ok"} |
/v1/info | GET | Self-describing service info (tools, auth, spans, docs) |
/.well-known/agent.json | GET | Agent card |
/.well-known/oauth-protected-resource | GET | RFC 9728 β public, no auth |
Concurrency capped at 100 simultaneous POST /mcp via asyncio.Semaphore.
Rate limiting is per-proposal: write and vote are capped at
QUORUM_PROPOSAL_RATE events/min per proposal id (default 120), so one
hot proposal can't starve the rest. The edge per-IP zone in Caddy is a
coarse backstop only.
Attestation is queued and coalesced: concurrent events share one NTP sample per drain batch instead of one query per event β each event still gets its own Stamp record (unique id, own payload hash), so throughput isn't bound by NTP round-trips.
Event-sourced: one append-only JSONL file per proposal under
~/.quorum/proposals (override QUORUM_DATA_DIR). Namespaced
proposals live in per-namespace subdirectories
(proposals/<ns>/<name>.jsonl). The log is the history β history
is a filtered read of the same file the tools append to. Nothing is
rewritten or deleted.
Caddy handles TLS once DNS points at the host. See deploy/Caddyfile.
Copyright 2026 theoddden. Licensed under the Apache License, Version 2.0.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/quorum-2)<a href="https://allmcps.com/mcp/quorum-2"><img src="https://allmcps.com/api/badge/quorum-2?style=directory" alt="Quorum on AllMCPs" /></a>