MCP Server

agent-covenant

io.github.jdhart81/agent-covenant
MCP & Agent Infrastructure Security Public & reachable MCP 2025-11-25

What this MCP does

Manages deny-by-default authority covenants for agents, including scoped permissions, spending limits, revocation, act checks, and tamper-evident audit verification.

check_act
Check (and if allowed, record) a proposed act against a covenant. Deny-by-default. Idempotent on act_id — retries never double-consume budget. Every check lands on the audit chain.
Input schema
{'type': 'object', 'title': 'check_actArguments', 'required': ['covenant_id', 'act_id', 'scope'], 'properties': {'scope': {'type': 'string', 'title': 'Scope'}, 'act_id': {'type': 'string', 'title': 'Act Id'}, 'covenant_id': {'type': 'string', 'title': 'Covenant Id'}, 'amount_minor': {'type': 'integer', 'title': 'Amount Minor', 'default': 0}}}
Output schema
{'type': 'object', 'title': 'check_actOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
covenant_status
Current state, consumed/remaining budget, and check count.
Input schema
{'type': 'object', 'title': 'covenant_statusArguments', 'required': ['covenant_id'], 'properties': {'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
Output schema
{'type': 'object', 'title': 'covenant_statusOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
describe_agent
Fleet-standard self-description.
Input schema
{'type': 'object', 'title': 'describe_agentArguments', 'properties': {}}
Output schema
{'type': 'object', 'title': 'describe_agentOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
grant_covenant
Grant an agent a covenant: an explicit lease of authority. scopes support wildcards ('payments.*', '*'); budget_minor is the total spend ceiling in minor units; expires_at is ISO-8601. Returns the covenant_id.
Input schema
{'type': 'object', 'title': 'grant_covenantArguments', 'required': ['principal', 'agent_id', 'scopes', 'budget_minor', 'expires_at'], 'properties': {'scopes': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Scopes'}, 'agent_id': {'type': 'string', 'title': 'Agent Id'}, 'principal': {'type': 'string', 'title': 'Principal'}, 'expires_at': {'type': 'string', 'title': 'Expires At'}, 'budget_minor': {'type': 'integer', 'title': 'Budget Minor'}}}
Output schema
{'type': 'object', 'title': 'grant_covenantOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
list_covenants
List covenants, optionally filtered by state (ACTIVE|REVOKED|EXPIRED) and/or the bound agent.
Input schema
{'type': 'object', 'title': 'list_covenantsArguments', 'properties': {'state': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'State', 'default': None}, 'agent_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Agent Id', 'default': None}}}
Output schema
{'type': 'object', 'title': 'list_covenantsOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
revoke_covenant
Revoke a covenant immediately and terminally. All subsequent checks deny.
Input schema
{'type': 'object', 'title': 'revoke_covenantArguments', 'required': ['covenant_id'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'default': ''}, 'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
Output schema
{'type': 'object', 'title': 'revoke_covenantOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
verify_audit
Verify the tamper-evident audit chain of allowed/denied acts.
Input schema
{'type': 'object', 'title': 'verify_auditArguments', 'required': ['covenant_id'], 'properties': {'covenant_id': {'type': 'string', 'title': 'Covenant Id'}}}
Output schema
{'type': 'object', 'title': 'verify_auditOutput', 'required': ['result'], 'properties': {'result': {'type': 'string', 'title': 'Result'}}}
Added
describe_agent
Sept. 17, 2026, 12:42 p.m.
Added
list_covenants
Sept. 17, 2026, 12:42 p.m.
Added
verify_audit
Sept. 17, 2026, 12:42 p.m.
Added
covenant_status
Sept. 17, 2026, 12:42 p.m.
Added
revoke_covenant
Sept. 17, 2026, 12:42 p.m.
Added
check_act
Sept. 17, 2026, 12:42 p.m.
Added
grant_covenant
Sept. 17, 2026, 12:42 p.m.