MCP server
Five tools that let an agent open and verify warrants, and none that let it settle one.
The MCP server exposes five tools — open, verify, status, list and test_spec — and deliberately no tool that releases, refunds or partially releases.
npx -y @gowarrant/mcp@latestThe five tools
| Tool | What it does |
|---|---|
warrant_open | Holds funds against a spec and a deadline. |
warrant_verify | Fetches a deliverable and lets the policy decide. |
warrant_status | Reads one warrant's current state. |
warrant_list | Lists warrants, filterable by state. |
warrant_test_spec | Evaluates clauses against a body. Holds nothing. |
There is no settle tool, and that is the design
An agent connected over MCP can commit money and can ask for a decision. It
cannot make the payment decision itself: releasing, refunding and partially
releasing are not exposed here, and the underlying endpoints refuse an API key
anyway with 403 user_session_required.
The model is that the agent does the work and a person approves anything the
policy will not settle automatically. A tool named warrant_release would make
the passkey threshold decorative.
Setup
gowarrant init detects the client from what is on disk — .mcp.json means
Claude Code, .cursor/ means Cursor, .codex/ means Codex — writes the config
and prints the install line. Where it detects nothing it prints all of them
rather than guessing.
npx gowarrant init
npx gowarrant init --client cursor
npx gowarrant init --dry-runIt does not create an account, mint a key or send anything anywhere. A first-run command that surprises you is a first-run command nobody trusts twice.
Claude Code
claude mcp add --scope project warrant -- npx -y @gowarrant/mcp@latestCursor
npx gowarrant init --client cursorCodex
codex mcp add warrant -- npx -y @gowarrant/mcp@latestAnything else
{
"mcpServers": {
"warrant": { "command": "npx", "args": ["-y", "@gowarrant/mcp@latest"] }
}
}The server reads WARRANT_API_KEY from its environment. Use a wr_test_ key
while you are wiring it up.
Amounts, as the model sees them
warrant_open takes the amount as a decimal string — "1.50" — and converts it
to the smallest unit before it reaches the API. That is deliberate: a language
model writing 1.5 as a number is the single most likely way an integration
goes wrong, and the tool schema is the place to catch it.
What crosses the wire is still "1500000", validated against ^[0-9]+$. See
the API reference for why.
Trying a spec without spending
warrant_test_spec takes clauses and a response body and returns the per-clause
result. It is the tool to reach for when a model is drafting a spec: no key
required, nothing held, nothing recorded.
What the agent cannot see
The server is scoped to the key it holds, so an agent sees its own organisation's warrants and nothing else. Cross-tenant reads return 404 rather than 403, because answering "forbidden" would confirm an id exists.