Cryptographically verifiable receipts of an agent's delegated work, verified offline.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
A Model Context Protocol server for Sequesign β let an MCP-capable agent produce a cryptographically verifiable receipt of its own delegated work, then verify it offline.
It is a thin local-stdio wrapper over @sequesign/sdk. The
agent's signing key never leaves the machine: in direct mode the SDK signs each
action locally and the hosted witness only co-signs a hash.
| Tool | What it does |
|---|---|
sequesign_start_session | Open a recording session (one signed action chain). Returns a sessionId (the receipt id) used by every other tool. Pass a policyContext object to bind the receipt to a policy (reaches L3_POLICY_BOUND). Optional mode (direct/managed) overrides the server default per session. |
sequesign_record_action | Append a signed action to the chain. evidence is hashed and signed. Returns the actionId. |
sequesign_record_approval | Attach a locally signed approval for a recorded action (e.g. a human or agent reviewer signing off). |
sequesign_record_counterparty_attestation | Attach a counterparty's signed confirmation of a recorded action (e.g. a vendor confirming an amount). The SDK derives the content binding from the attested action. |
sequesign_approve_receipt | Attach an independently-witnessed approval to an already-sealed receipt (a deferred satellite). For a reviewer β human or another agent β signing off after the fact. The approver must be distinct from the recording agent. |
sequesign_countersign_receipt | Attach an independently-witnessed counterparty confirmation to an already-sealed receipt (a deferred satellite), bound to a specific action. |
sequesign_finalize | Seal + witness the receipt and run the SDK's own verification. Closes the session. |
sequesign_verify | Verify a sealed receipt offline. Three modes: integrity self-check of the local package (default); third-party external check when you pass the witness's published keys; or pass receiptUrl to verify the broker-stored receipt (the authoritative copy carrying the registered identity), auto-fetching the published witness + registration anchors. |
The server default is SEQUESIGN_MODE, but sequesign_start_session accepts a
mode argument (direct or managed) so one running server can do both
without editing config. A mode: "managed" session still requires the managed
secrets (SEQUESIGN_API_KEY + SEQUESIGN_AGENT_PRIVATE_KEY); the call fails
fast if they're absent.
In managed mode the broker stamps the registered agent_identity_attestation
into the stored receipt, not the local envelope β so a local verify reads
self_asserted. Pass the receipt_url from finalize as receiptUrl to
sequesign_verify: it fetches the stored receipt (using SEQUESIGN_API_KEY),
verifies it against your local package, and auto-fetches the published witness
and registration anchors, so the result shows external trust and the
registered identity.
sequesign_approve_receipt and sequesign_countersign_receipt attest to a
receipt that's already finalized, without modifying it. Each produces a
detached satellite that's bound to the sealed receipt by hash, independently
witnessed at its own time, and written to the package's attestations.jsonl
sidecar; the verifier folds a valid satellite into the same approval/counterparty
leg as an in-receipt one. They take the sealed packageDirectory (not a live
session), so a different party β even a different model on a different machine,
as long as it has the package β can approve or countersign later. This is the
basis for a multi-party flow: one agent records and seals the work, a second
party approves it, a third confirms it β three independent, timestamped
signatures on one receipt.
Binding to the registered (stored) receipt. By default a satellite binds to
the local receipt.json. In managed mode the broker-stored copy carries the
registered agent_identity_attestation (a different hash), so pass the
receipt_url as receiptUrl to approve_receipt / countersign_receipt:
the tool fetches the stored receipt (authenticated, origin-allowlisted) and
binds the satellite to it. A later sequesign_verify --receiptUrl then shows
the registered identity AND the folded approval/counterparty legs on one
receipt. Set the satellite's mode to match how the receipt was sealed.
Convergence note (cross-platform). The broker does not store satellites
β a sealed satellite is appended to the local package's attestations.jsonl.
So for parties on different machines/platforms to converge on one verifiable
receipt, the .sequesign package must travel between them (an orchestrator
moves it, each appends its satellite). Independent submission with server-side
satellite storage is a future broker capability.
sequesign_record_approval and sequesign_record_counterparty_attestation
mint an ephemeral key when you don't pass one, so the leg verifies as
present_unverified. To get a present_verified (vouched) leg, enroll the
party's key with the platform first and pass both the enrolled private key PEM
and the returned identityProofRef. Then sequesign_verify flips the leg to
present_verified when given the platform's published registration keys.
All configuration is via environment variables:
| Variable | Default | Notes |
|---|---|---|
SEQUESIGN_MODE | direct | Default transport: direct (local key, independent witness co-signs) or managed (broker). Overridable per session via the mode tool argument. |
SEQUESIGN_WITNESS_URL | https://witness.sequesign.com | Direct-mode witness. |
SEQUESIGN_BROKER_URL | https://broker.sequesign.com | Managed-mode broker. |
SEQUESIGN_DASHBOARD_API_URL | https://dashboard-api.sequesign.com | Source of the published registration keys for the receiptUrl verify path. |
SEQUESIGN_RECEIPT_LIBRARY_URL | https://library.sequesign.com | Receipt-store origin. The API key is forwarded only to this or the broker origin when fetching a receiptUrl; any other origin is rejected before the key is sent (key-exfiltration guard). |
SEQUESIGN_API_KEY | β | Required in managed mode (write-class key). In direct mode it's passed to the witness too β the hosted witness authenticates the signing POST, so direct mode needs it unless you point SEQUESIGN_WITNESS_URL at a witness that allows unauthenticated signing. |
SEQUESIGN_TIER | hosted | Managed tier: hosted, hash-only, or ephemeral. |
SEQUESIGN_AGENT_PRIVATE_KEY | β | Ed25519 PKCS#8 PEM for the agent key. In direct mode, if unset a fresh ephemeral key is minted per session (identity reads self_asserted). Required in managed mode β it must be the key your API key is registered to (the broker rejects any other agent key). |
SEQUESIGN_PACKAGE_DIR | <tmpdir>/sequesign-mcp | Where receipt packages are written. |
Sessions are held in memory for the life of the process. A
sessionIddoes not survive a server restart orsequesign_finalize.
.mcpb) β recommendedThe one-click path: download sequesign.mcpb from the
GitHub releases and open it
with Claude Desktop (Settings β Extensions β install from file). Desktop renders
a setup form from the manifest's user_config; fill in:
| Field | Notes |
|---|---|
| Mode | direct (default) or managed. |
| API key | Your write-class key. Required for managed; in direct it authenticates the hosted witness. Stored in your OS keychain. |
| Agent private key (PEM) | Ed25519 PKCS#8 PEM. Required in managed (must match the key your API key is registered to); leave blank in direct to mint an ephemeral key per session. Stored in your OS keychain. |
| Receipt package directory | Where sealed packages are written. Blank β a temp directory. |
Secrets go to the OS keychain (never the manifest), and blank optional fields
fall back to their defaults. The bundle is self-contained β no npm/node
project setup required. Where do the API key and agent key come from? See
Getting your keys below.
Building the .mcpb from source:
The build bundles the server and all dependencies into a single file with
esbuild and copies the protocol registry/schemas/profiles next to it, then packs
and validates via @anthropic-ai/mcpb. Attach the resulting .mcpb (and its
printed SHA-256) to a GitHub release.
Releasing to npm and the official MCP registry is automated β see PUBLISHING.md.
For non-Desktop MCP clients (or if you prefer managing config yourself), install from npm and configure via environment variables β see Usage below.
The two secrets β your API key and your agent private key β come from the Sequesign dashboard's Create-API-key flow. The key you use in managed mode must be the one registered to your API key.
Create an API key in the dashboard (Settings β API keys β Create key). Registration is off by default, so you must opt in:
Paste both into the setup form (or set SEQUESIGN_API_KEY and
SEQUESIGN_AGENT_PRIVATE_KEY). Reuse them across installs and machines β you do
not make a new key each time.
Bring your own key (advanced). Instead of "Generate keypair", you can pick "Bring your own public key (advanced)" and paste the public PEM of a key you generated yourself (e.g. in an HSM). You hold the private key; the platform records the public half. Fully supported in managed mode.
The broker accepts only the agent key your API key is registered to β whether the dashboard generated it or you brought your own. An unregistered key (generated locally and never registered) is rejected (
agent_public_key_not_registered). That's the rule: the key must be on file against your API key, and that binding happens at API-key creation.
Verifying the broker-stored receipt then shows a registered agent identity
(see the receiptUrl verify path below).
Direct mode has no account and no registration. The agent key only proves continuity (the same signer produced these receipts), not a platform-vouched identity. Two choices:
self_asserted key.openssl genpkey -algorithm ed25519). It stays self_asserted unless that
key is the one registered to your SEQUESIGN_API_KEY: in that case the witness
(which authenticates the same key) confirms the match and the receipt verifies
as a registered identity β direct signing and a registered identity. (The
witness also rejects signing under a key that isn't the one registered to your
API key, so an API key can't mint receipts under an unregistered key.)Add it to an MCP client (e.g. Claude Desktop) as a stdio server:
Or run it directly:
Drop these into any MCP-capable agent (Claude Desktop, etc.) once the server is configured. They're written the way you'd actually ask β the agent picks the tools.
1. Record and seal a single piece of work, then verify it.
Using Sequesign, open a session for task
q3-refund-reviewdelegated byops@acme.example, record an actionrefund_approvedwith the evidence{ "invoice": "INV-2231", "amount_usd": 480, "reason": "duplicate charge" }, then finalize the receipt and verify it. Tell me the package directory and whether it verified.
Exercises start_session β record_action β finalize β verify (the local
integrity self-check).
2. Multi-party: one agent records, two others attest after the fact.
The receipt at
<packageDirectory>is already sealed. Have Sequesign attach an approval to it ascfo@acme.example(a human reviewer), then attach a counterparty confirmation asvendor-globexfor therefund_approvedaction with purposerefund_amount_confirmation. Then verify the package and show me the approval and counterparty legs.
Exercises approve_receipt and countersign_receipt (deferred satellites bound
to an already-finalized receipt), then verify. A different party β even a
different model on another machine that has the package β can run these.
3. Verify the broker-stored, registered-identity copy (managed mode).
I finalized a managed-mode receipt; its
receipt_urlis<receipt_url>and the local package is at<packageDirectory>. Use Sequesign to verify the stored receipt against my package and tell me whether it shows external trust and a registered agent identity.
Exercises verify with receiptUrl β fetches the authoritative stored
envelope (carrying the registered agent_identity_attestation), auto-fetches
the published witness + registration anchors, and reports external trust plus
the registered identity.
sequesign_start_session β { taskId, delegatorId, policyContext } β returns sessionId.sequesign_record_action β { sessionId, actionType, evidence } β returns actionId.sequesign_record_counterparty_attestation β { sessionId, counterpartyId, attestedActionId, attestationPurpose }.sequesign_record_approval β { sessionId, approverId, approvedActionType, approvalContext }.sequesign_finalize β { sessionId } β returns the package directory + verification summary.sequesign_verify β { packageDirectory } β re-verify offline any time.Apache-2.0
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/sequesign)<a href="https://allmcps.com/mcp/sequesign"><img src="https://allmcps.com/api/badge/sequesign?style=directory" alt="Sequesign on AllMCPs" /></a>