ratchet
What this MCP does
Gates external side effects with permission checks, leases, idempotency, outcome tracking, rollback guidance, and signed receipts.
Tools
Input schema
{'type': 'object', 'required': ['effect_type', 'idempotency_key'], 'properties': {'run_id': {'type': 'string', 'description': 'Groups all effects from one task or run.'}, 'vendor': {'type': 'string', 'maxLength': 32, 'description': 'Which vendor performs this effect (e.g. "stripe", "square", "adyen"). Shapes vendor_idempotency_key so it satisfies that vendor\'s rules.'}, 'payload': {'type': 'object', 'description': "The action's parameters. Only a hash is stored — the raw content never persists. Reusing a key with different parameters is rejected, which catches key collisions.", 'additionalProperties': True}, 'agent_id': {'type': 'string', 'description': 'Identifier for you, the calling agent.'}, 'group_key': {'type': 'string', 'description': 'Use when this action is one step of a multi-step workflow that must succeed or fail as a whole, e.g. "booking:trip_8812". Lets the whole unit be rolled back later.'}, 'dimensions': {'type': 'object', 'description': 'Who or what this action is aimed at, most often the destination: {"counterparty":"acct_1234"}. SEND THIS whenever the action targets a specific recipient, account or customer. It is how a per-destination ceiling can exist at all — "no more than $200 to any one counterparty per day" — and only a keyed hash of the value is stored, so Ratchet counts the destination without ever being able to read it. Declaring can only tighten: it never removes a limit. If begin is refused with dimension_required, the operator has made a dimension mandatory for this effect type and you must send it.', 'additionalProperties': {'type': 'string'}}, 'effect_type': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9._-]{0,62}[a-z0-9])?$', 'description': 'Namespaced kind of side effect, e.g. "email.send", "payment.charge", "github.pr.create". Policy is configured per type.'}, 'compensation': {'type': 'object', 'required': ['effect_type', 'payload'], 'properties': {'payload': {'type': 'object', 'description': 'What the undo will need — booking ids, charge ids.', 'additionalProperties': True}, 'effect_type': {'type': 'string', 'description': 'e.g. "booking.cancel", "payment.refund"'}}, 'description': 'How to undo THIS step if the workflow has to be rolled back. Declare it now, while you still know what undoing means — it cannot be worked out later. Steps without one are permanent.'}, 'lease_seconds': {'type': 'integer', 'maximum': 3600, 'minimum': 5, 'description': 'How long you expect the action to take. Report before this elapses or the effect becomes indeterminate.'}, 'idempotency_key': {'type': 'string', 'maxLength': 255, 'minLength': 1, 'description': 'Deterministic identifier for this specific logical action, e.g. "welcome-email:user_123" or "invoice:2026-08:acct_88123". The SAME action retried must produce the SAME key.'}, 'compensates_effect_id': {'type': 'string', 'description': 'Set when THIS call IS an undo, naming the effect it reverses. Comes from ratchet_unwind_group.'}, 'estimated_cost_micros': {'type': 'integer', 'minimum': 0, 'description': 'What this action will cost at the third party, in micro-USD (1000000 = $1). ALWAYS SEND THIS when the action costs money. Spend ceilings are computed from it, and a ceiling with nothing declared against it never fires — the operator would be relying on a limit that cannot trigger. If the response contains budget_warning, that is exactly what has happened: tell the operator. Ratchet does not collect this money; it only counts it. It can also route the action to a human: an operator may set an approval threshold, and an action whose declared cost reaches it comes back approval_required instead of execute — so declaring accurately is what keeps large actions reviewable. Where a threshold is set, omitting this is refused with cost_required rather than allowed.'}}}
Input schema
{'type': 'object', 'required': ['effect_id', 'lease_token'], 'properties': {'effect_id': {'type': 'string'}, 'lease_token': {'type': 'string'}, 'extend_seconds': {'type': 'integer', 'maximum': 3600, 'minimum': 5, 'description': 'How much longer you need, from now. Clamped to the policy maximum.'}}}
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['effect_type', 'idempotency_key'], 'properties': {'effect_type': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9._-]{0,62}[a-z0-9])?$', 'description': 'Namespaced kind of side effect, e.g. "email.send", "payment.charge", "github.pr.create". Policy is configured per type.'}, 'idempotency_key': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['group_key'], 'properties': {'group_key': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['effect_type'], 'properties': {'effect_type': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9._-]{0,62}[a-z0-9])?$', 'description': 'Namespaced kind of side effect, e.g. "email.send", "payment.charge", "github.pr.create". Policy is configured per type.'}}}
Input schema
{'type': 'object', 'properties': {}}
Input schema
{'type': 'object', 'required': ['run_id'], 'properties': {'run_id': {'type': 'string', 'maxLength': 128, 'description': 'The run id you passed to ratchet_begin_effect for this task.'}}}
Input schema
{'type': 'object', 'properties': {}}
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1}, 'state': {'enum': ['awaiting_approval', 'pending', 'succeeded', 'failed', 'indeterminate', 'denied', 'cancelled'], 'type': 'string'}, 'run_id': {'type': 'string'}, 'effect_type': {'type': 'string', 'pattern': '^[a-z0-9]([a-z0-9._-]{0,62}[a-z0-9])?$', 'description': 'Namespaced kind of side effect, e.g. "email.send", "payment.charge", "github.pr.create". Policy is configured per type.'}}}
Input schema
{'type': 'object', 'required': ['effect_id'], 'properties': {'effect_id': {'type': 'string', 'description': 'The effect to fetch receipts for.'}}}
Input schema
{'type': 'object', 'required': ['effect_type', 'keys'], 'properties': {'keys': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 1000, 'description': 'Idempotency keys your system should have used for those actions.'}, 'effect_type': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['effect_id', 'lease_token', 'outcome'], 'properties': {'result': {'type': 'object', 'description': 'What the action produced (ids, confirmation numbers, links). Replayed verbatim to duplicate callers, so include what a retry would need.', 'additionalProperties': True}, 'outcome': {'enum': ['succeeded', 'failed'], 'type': 'string'}, 'effect_id': {'type': 'string'}, 'lease_token': {'type': 'string'}, 'failure_reason': {'type': 'string', 'description': 'Required when outcome is "failed".'}, 'actual_cost_micros': {'type': 'integer', 'minimum': 0, 'description': 'What it really cost, if different from the estimate.'}}}
Input schema
{'type': 'object', 'required': ['effect_id', 'outcome'], 'properties': {'result': {'type': 'object', 'additionalProperties': True}, 'outcome': {'enum': ['succeeded', 'failed', 'cancelled'], 'type': 'string'}, 'evidence': {'type': 'string', 'description': 'How you verified the real outcome. Stored in the audit trail.'}, 'effect_id': {'type': 'string'}}}
Input schema
{'type': 'object', 'required': ['group_key'], 'properties': {'reason': {'type': 'string', 'description': 'Why it is being rolled back. Stored for the operator.'}, 'group_key': {'type': 'string', 'description': 'The unit of work to roll back, e.g. "booking:trip_8812".'}}}
Recent tool changes
Similar MCP servers
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…
PHION Agent Trust Infrastructure
Provides agent trust, policy, provenance, evidence, delegation, telemetry, and transaction-control services for MCP and agent wor…
Swamp
Coordinates security agents through scoped bug-bounty programs, target claims, vulnerability submissions, peer review, shared fin…
AgentBIT
Routes pay-per-call tools over x402 on Base, covering discovery, data conversion, company research, counterparty screening, domai…
SaSame MCP Observatory + Gold Rush Town
Audits and profiles MCP servers, provides ecosystem analytics, trust and claim records, and non-custodial transaction or escrow a…
ThinkNEO Control Plane
Provides an enterprise AI control plane for governance, guardrails, spend tracking, compliance, and model or tool routing.