Skip to content
Warrantv0.1

MCP server

Five tools that let an agent open and verify warrants, and none that let it settle one.

The MCP server exposes five tools — open, verify, status, list and test_spec — and deliberately no tool that releases, refunds or partially releases.

npx -y @gowarrant/mcp@latest

The five tools

ToolWhat it does
warrant_openHolds funds against a spec and a deadline.
warrant_verifyFetches a deliverable and lets the policy decide.
warrant_statusReads one warrant's current state.
warrant_listLists warrants, filterable by state.
warrant_test_specEvaluates clauses against a body. Holds nothing.

There is no settle tool, and that is the design

An agent connected over MCP can commit money and can ask for a decision. It cannot make the payment decision itself: releasing, refunding and partially releasing are not exposed here, and the underlying endpoints refuse an API key anyway with 403 user_session_required.

The model is that the agent does the work and a person approves anything the policy will not settle automatically. A tool named warrant_release would make the passkey threshold decorative.

Setup

gowarrant init detects the client from what is on disk — .mcp.json means Claude Code, .cursor/ means Cursor, .codex/ means Codex — writes the config and prints the install line. Where it detects nothing it prints all of them rather than guessing.

npx gowarrant init
npx gowarrant init --client cursor
npx gowarrant init --dry-run

It does not create an account, mint a key or send anything anywhere. A first-run command that surprises you is a first-run command nobody trusts twice.

Claude Code

claude mcp add --scope project warrant -- npx -y @gowarrant/mcp@latest

Cursor

npx gowarrant init --client cursor

Codex

codex mcp add warrant -- npx -y @gowarrant/mcp@latest

Anything else

{
  "mcpServers": {
    "warrant": { "command": "npx", "args": ["-y", "@gowarrant/mcp@latest"] }
  }
}

The server reads WARRANT_API_KEY from its environment. Use a wr_test_ key while you are wiring it up.

Amounts, as the model sees them

warrant_open takes the amount as a decimal string — "1.50" — and converts it to the smallest unit before it reaches the API. That is deliberate: a language model writing 1.5 as a number is the single most likely way an integration goes wrong, and the tool schema is the place to catch it.

What crosses the wire is still "1500000", validated against ^[0-9]+$. See the API reference for why.

Trying a spec without spending

warrant_test_spec takes clauses and a response body and returns the per-clause result. It is the tool to reach for when a model is drafting a spec: no key required, nothing held, nothing recorded.

What the agent cannot see

The server is scoped to the key it holds, so an agent sees its own organisation's warrants and nothing else. Cross-tenant reads return 404 rather than 403, because answering "forbidden" would confirm an id exists.