MCP 服务器

AgentLedger

io.github.entradox/agent-ledger
商业与运营 MCP 与智能体基础设施 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Tracks, budgets, caps, alerts on, and reports AI agent spending across payment and token usage rails.

ledger_alerts
Agent Budget Alerts
Alert history for an agent: budget warnings (80% threshold) and spending spikes. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/alerts).
只读 幂等
输入模式
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'unique agent identifier'}, 'agent_secret': {'type': 'string', 'default': '', 'description': "the agent's own secret (either this or workspace_key)"}, 'workspace_key': {'type': 'string', 'default': '', 'description': "the owning workspace's key (either this or agent_secret)"}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_api_docs
AgentLedger API Docs
Self-serve documentation for AgentLedger — quickstart, MCP tools, REST endpoints, budget caps, error codes, and idempotency usage, as markdown.
只读 幂等
输入模式
{'type': 'object', 'properties': {'topic': {'type': 'string', 'default': '', 'description': '"quickstart" | "mcp" | "rest" | "budget" | "errors" | "idempotency" | "all"\n   (default "" == "all"). Unknown topics fall back to the full docs.'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_check_spend
Check Before Spending
Ask BEFORE you spend: may this agent spend this much right now? Returns allowed (true/false), a stable reason code (within_budget, over_monthly_cap, over_daily_cap, over_monthly_token_cap, over_daily_token_cap, no_budget_set, unpriced_model), a one-line message, the cost estimate, the price used (with its source and as_of date) and every budget window with cap, spent and remaining. Same decision the /proxy/{provider} gate enforces. Read-only: nothing is recorded or reserved, so record the spend with ledger_track afterwards. Give exactly one spend shape: amount_cents (any rail, e.g. an x402 purchase), OR model with tokens_in/tokens_out.
只读 幂等
输入模式
{'type': 'object', 'required': ['agent_id'], 'properties': {'model': {'type': 'string', 'default': '', 'description': 'model id to price from tokens (instead of amount_cents)'}, 'agent_id': {'type': 'string', 'description': 'the agent that would spend'}, 'tokens_in': {'type': 'integer', 'default': 0, 'description': 'expected input tokens (with model)'}, 'tokens_out': {'type': 'integer', 'default': 0, 'description': 'expected output tokens, e.g. your max_tokens (with model)'}, 'agent_secret': {'type': 'string', 'default': '', 'description': "the agent's own secret (either this or workspace_key)"}, 'amount_cents': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'default': None, 'description': 'the spend in cents, if you already know it'}, 'workspace_key': {'type': 'string', 'default': '', 'description': "the owning workspace's key (either this or agent_secret)"}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_examples
AgentLedger Recipes
Complete, runnable Python recipe for a common AgentLedger integration pattern.
只读 幂等
输入模式
{'type': 'object', 'required': ['pattern'], 'properties': {'pattern': {'type': 'string', 'description': '"python_tracking" | "budget_enforcement" | "weekly_report" |\n     "retry_safe_writes"'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_price
Price a Call Before You Make It
What will this call cost? Priced from the same table the caps use. Exists because ledger_track requires the CALLER to supply amount_cents, so an agent whose spend is capped could under-report its own cost and stay under the cap. This returns the number the enforcement path would use, so an agent can report honestly (and plan before it spends). Cost = (tokens_in * in_rate + tokens_out * out_rate) / 1_000_000. If the model has cache rates, the standard in-rate is used, which is the conservative direction for a spend cap. Every price carries the source it came from and the date it was read, and `verified: false` means the number was NOT read off the provider's own pricing page. Treat an unverified price as an estimate, not a measurement.
只读 幂等
输入模式
{'type': 'object', 'required': ['model'], 'properties': {'model': {'type': 'string', 'description': 'the model id you are about to call (e.g. gpt-4o, claude-sonnet-4)'}, 'tokens_in': {'type': 'integer', 'default': 0, 'description': 'expected input tokens'}, 'tokens_out': {'type': 'integer', 'default': 0, 'description': 'expected output tokens, e.g. your max_tokens'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_proxy_attach
Attach the Budget-Enforcing Proxy
Point your provider traffic at the proxy so budget caps are enforced BEFORE the provider is contacted, instead of being reported afterwards. This closes the gap where the brake was unreachable from MCP: an agent connected over MCP could record spend (ledger_track) but nothing could refuse a call. With this, the cap is enforced on every LLM call. Returns the base_url to use, the two headers to send, and the exact change for the OpenAI and Anthropic SDKs. Your provider credential is NOT part of this: it stays in Authorization / x-api-key and is only forwarded, never stored.
只读 幂等
输入模式
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'description': 'the agent whose budget the proxied calls are billed to'}, 'provider': {'type': 'string', 'default': 'openai', 'description': 'which upstream to proxy: openai or anthropic'}, 'agent_secret': {'type': 'string', 'default': '', 'description': "the agent's own secret (either this or workspace_key)"}, 'workspace_key': {'type': 'string', 'default': '', 'description': "the owning workspace's key (either this or agent_secret)"}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_report
Agent Spend Report
Spend report for an agent over a rolling window. Returns total spend, breakdown by rail and by service, budget status (ok/warning/exceeded), detected anomalies, and entry count. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/report).
只读 幂等
输入模式
{'type': 'object', 'required': ['agent_id'], 'properties': {'days': {'type': 'integer', 'default': 30, 'description': 'report window in days (default 30)'}, 'agent_id': {'type': 'string', 'description': 'unique agent identifier'}, 'agent_secret': {'type': 'string', 'default': '', 'description': "the agent's own secret (either this or workspace_key)"}, 'workspace_key': {'type': 'string', 'default': '', 'description': "the owning workspace's key (either this or agent_secret)"}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_revoke_secret
Revoke Agent Secret
Invalidate an agent_id's agent_secret WITHOUT deleting its spend history. Use when a credential may have leaked, or to stop an agent writing. Subsequent writes to that agent fail with agent_secret_mismatch until you rotate a new secret in. The agent_id stays claimed, so no other workspace can claim it and inherit the ledger. Requires the workspace_key that owns agent_id. Returns {"agent_id", "revoked": True, "_note"}, or {"error", "error_code"}.
可能执行破坏性操作
输入模式
{'type': 'object', 'required': ['agent_id', 'workspace_key'], 'properties': {'agent_id': {'type': 'string'}, 'workspace_key': {'type': 'string'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_rotate_secret
Rotate Agent Secret
Mint a NEW agent_secret for an agent_id your workspace already owns, invalidating the old one. Use this to RECOVER an agent whose secret was lost: the previous credential stops working immediately. Requires the workspace_key that owns agent_id — an agent's own agent_secret cannot rotate itself, because a leaked agent credential must not be able to lock its real owner out. Unlike ledger_track this never claims a new agent_id: an unknown id returns agent_not_claimed. The new secret is returned ONCE. Store it before you drop the response. Returns {"agent_id", "agent_secret", "_note"}, or {"error", "error_code"}.
可能执行破坏性操作
输入模式
{'type': 'object', 'required': ['agent_id', 'workspace_key'], 'properties': {'agent_id': {'type': 'string'}, 'workspace_key': {'type': 'string'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_set_budget
Set Agent Budget
Set spending caps for an agent. Warns at 80%, blocks spend when exceeded — enforced: a ledger_track call that would cross the cap is rejected. Dollar caps (monthly_cents/daily_cents) and token caps (monthly_tokens/ daily_tokens) are independent dimensions: dollar caps only cover non-"tokens" rails, token caps only cover rail="tokens" bookkeeping rows (tokens_in/tokens_out). Set both if the agent uses both. Monthly cap is required; the rest are optional (0 = no limit). Overwrites any existing budget for the agent. Claiming a brand-new agent_id requires your workspace_key; that first call mints an agent_secret (returned once — save it); later calls for that agent_id must pass the agent_secret back (no workspace_key needed again).
可能执行破坏性操作 幂等
输入模式
{'type': 'object', 'required': ['agent_id', 'monthly_cents'], 'properties': {'agent_id': {'type': 'string', 'description': 'unique agent identifier'}, 'daily_cents': {'type': 'integer', 'default': 0, 'description': 'daily spending cap in cents (0 = no daily cap)'}, 'agent_secret': {'type': 'string', 'default': '', 'description': 'required for every call after the first for this agent_id'}, 'daily_tokens': {'type': 'integer', 'default': 0, 'description': 'daily token-burn cap (0 = no cap)'}, 'monthly_cents': {'type': 'integer', 'description': 'monthly spending cap in cents'}, 'workspace_key': {'type': 'string', 'default': '', 'description': 'required when claiming a brand-new agent_id; not\n           needed once the agent_id has been claimed'}, 'monthly_tokens': {'type': 'integer', 'default': 0, 'description': 'monthly token-burn cap (0 = no cap)'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_start
Start a Workspace
Get a FREE AgentLedger workspace with no credential and no arguments — the MCP equivalent of opening POST /start in a browser. Call this FIRST if you have no credentials yet. Every other tool here (ledger_track, ledger_set_budget, ledger_report, ledger_alerts) needs a workspace_key or an agent_secret, so a caller arriving with neither must start here or it has nowhere to go. Takes NO arguments on purpose: the goal is zero friction. It returns a `workspace_key` (shown exactly once — it cannot be re-revealed, so store it before continuing) which you then send as `workspace_key` on your first ledger_track for a NEW agent_id. That first write returns the agent's own `agent_secret`, which authenticates every write after it. The free tier includes every rail, enforced budget caps, alerts, reports and the MCP server, capped at 3 agents per workspace. Minting is rate-limited per caller IP, the same limit the human door uses. Prefer to pay? POST /v1/billing/x402 with a wallet-signed payment needs no human and buys 24h of Pro (unlimited agents).
输入模式
{'type': 'object', 'properties': {}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
ledger_track
Track Agent Spend
Record a spend entry for an AI agent on any payment rail, with optional token counts. Claiming a brand-new agent_id requires your workspace_key (get one via x402 at POST /v1/billing/x402 — no human, no login — or at /start). That first call mints an agent_secret and returns it in the response — save it, every later call for that same agent_id must pass it back (no workspace_key needed again) or the write is rejected. Amounts are capped at $100,000/entry and must be >= 0. If a budget is set for this agent, an entry that would cross the monthly/daily cap is blocked, not just logged. Include tokens_in/tokens_out + model on every LLM call so token burn shows up in the /v1/tokens report.
输入模式
{'type': 'object', 'required': ['agent_id', 'rail', 'amount_cents', 'service'], 'properties': {'rail': {'type': 'string', 'description': 'payment rail used â\x80\x94 one of "mpp", "x402", "api_key", "manual"'}, 'model': {'type': 'string', 'default': '', 'description': 'model name (e.g. "gpt-4o") â\x80\x94 token burn is reported per model'}, 'service': {'type': 'string', 'description': 'what was purchased (e.g. "search_query", "data_export")'}, 'agent_id': {'type': 'string', 'description': 'unique agent identifier (e.g. "research-agent-v2")'}, 'tokens_in': {'type': 'integer', 'default': 0, 'description': 'prompt tokens consumed (0 if unknown)'}, 'tokens_out': {'type': 'integer', 'default': 0, 'description': 'completion tokens consumed (0 if unknown)'}, 'agent_secret': {'type': 'string', 'default': '', 'description': 'required for every call after the first for this agent_id'}, 'amount_cents': {'type': 'integer', 'description': 'spend amount in cents (100 = $1.00), 0-10000000'}, 'workspace_key': {'type': 'string', 'default': '', 'description': 'required when claiming a brand-new agent_id; not\n           needed once the agent_id has been claimed'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
read_skill
Read Skill
Read a product skill file by its skill:// URI.
输入模式
{'type': 'object', 'required': ['uri'], 'properties': {'uri': {'type': 'string', 'description': 'e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`.'}}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
skills_list_tool
Skills List Tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
输入模式
{'type': 'object', 'properties': {}, 'additionalProperties': False}
输出模式
{'type': 'object', 'additionalProperties': True}
已移除
ledger_list_agents
2026年9月29日 02:52
已添加
ledger_price
2026年9月29日 02:52
已添加
ledger_check_spend
2026年9月29日 02:52
已添加
ledger_proxy_attach
2026年9月29日 02:52
已添加
ledger_start
2026年9月21日 02:50
已添加
read_skill
2026年9月17日 12:41
已添加
skills_list_tool
2026年9月17日 12:41
已添加
ledger_examples
2026年9月17日 12:41
已添加
ledger_api_docs
2026年9月17日 12:41
已添加
ledger_list_agents
2026年9月17日 12:41
已添加
ledger_alerts
2026年9月17日 12:41
已添加
ledger_report
2026年9月17日 12:41
已添加
ledger_set_budget
2026年9月17日 12:41
已添加
ledger_track
2026年9月17日 12:41
已添加
ledger_revoke_secret
2026年9月17日 12:41
已添加
ledger_rotate_secret
2026年9月17日 12:41

ThinkNEO Control Plane

ai.thinkneo/control-plane

Provides an enterprise AI control plane for governance, guardrails, spend tracking, compliance, and model or tool routing.

Focxle: AI governance for B2B deals between agents

com.focxle/afos

Provides agent spending controls, delegated budgets, signed authority checks, negotiations, escrow contracts, workforce hiring, a…

Conductor Relay MCP

io.github.Zman504/conductor-relay-mcp

Provides agent enrollment, discovery, messaging, task exchange, job claiming, governed direct sessions, balances, and marketplace…

Catalyst Governance

io.github.Stratogenic-AI/catalyst

Governs AI-agent actions through permission checks, approval workflows, compliance scans, task management, workflow registration,…

CIVITAE — Governed AI Agent Marketplace

xyz.signomy/civitae

Provides a governed marketplace and collaboration platform for registering AI agents, discovering missions and bounties, negotiat…

Licium

io.github.Licium-ai/licium

Provides structured page data, source monitoring, bounty workflows, paid callable capabilities, and a directory of remote MCP end…

Sales Ops — Commission Statement Review — Quillon Operations (f8485f73)

com.a2awire/benchmark-commission-statement-review-2026-09-17-f8485f73

Provides A2AWire agent registration, benchmarking, agent discovery and hiring, paid work, data purchases, and USDC escrow workflo…

Healthcare Admin — Authorization Review — Northgate Advisors (2bd7f518)

com.a2awire/benchmark-authorization-review-2026-09-16-2bd7f518

Provides A2AWire agent registration, benchmarking, agent discovery and hiring, paid work, data purchases, and USDC escrow workflo…