AgentLedger
Meter, cap, and block AI agent spend before the provider is charged.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"agent-ledger": {
"url": "https://agent-ledger-production-0ff8.up.railway.app/mcp/"
}
}
}Remote-Endpunkte
https://agent-ledger-production-0ff8.up.railway.app/mcp/streamable-httphttps://aiagentscity.com/mcp/streamable-httpWas es kann
Tool-Inventar
Tools (14)
🔴ledger_rotate_secret(agent_id, workspace_key)
Mint a NEW agent_secret for an agent_id your workspace already owns, invalidating the old one. Use this to RECOVER an agent whose secret was lost: the previous credential stops working immediately. Requires the workspace_key that owns agent_id — an agent's own agent_secret cannot rotate itself, because a leaked agent credential must not be able to lock its real owner out. Unlike ledger_track this never claims a new agent_id: an unknown id returns agent_not_claimed. The new secret is returned ONCE. Store it before you drop the response. Returns {"agent_id", "agent_secret", "_note"}, or {"error", "error_code"}.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string"
},
"workspace_key": {
"type": "string"
}
},
"required": [
"agent_id",
"workspace_key"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🔴ledger_revoke_secret(agent_id, workspace_key)
Invalidate an agent_id's agent_secret WITHOUT deleting its spend history. Use when a credential may have leaked, or to stop an agent writing. Subsequent writes to that agent fail with agent_secret_mismatch until you rotate a new secret in. The agent_id stays claimed, so no other workspace can claim it and inherit the ledger. Requires the workspace_key that owns agent_id. Returns {"agent_id", "revoked": True, "_note"}, or {"error", "error_code"}.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string"
},
"workspace_key": {
"type": "string"
}
},
"required": [
"agent_id",
"workspace_key"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟡ledger_track(agent_id, rail, amount_cents, service, tokens_in, ...)
Record a spend entry for an AI agent on any payment rail, with optional token counts. Claiming a brand-new agent_id requires your workspace_key (get one via x402 at POST /v1/billing/x402 — no human, no login — or at /start). That first call mints an agent_secret and returns it in the response — save it, every later call for that same agent_id must pass it back (no workspace_key needed again) or the write is rejected. Amounts are capped at $100,000/entry and must be >= 0. If a budget is set for this agent, an entry that would cross the monthly/daily cap is blocked, not just logged. Include tokens_in/tokens_out + model on every LLM call so token burn shows up in the /v1/tokens report.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "unique agent identifier (e.g. \"research-agent-v2\")"
},
"rail": {
"type": "string",
"description": "payment rail used — one of \"mpp\", \"x402\", \"api_key\", \"manual\""
},
"amount_cents": {
"type": "integer",
"description": "spend amount in cents (100 = $1.00), 0-10000000"
},
"service": {
"type": "string",
"description": "what was purchased (e.g. \"search_query\", \"data_export\")"
},
"tokens_in": {
"default": 0,
"type": "integer",
"description": "prompt tokens consumed (0 if unknown)"
},
"tokens_out": {
"default": 0,
"type": "integer",
"description": "completion tokens consumed (0 if unknown)"
},
"model": {
"default": "",
"type": "string",
"description": "model name (e.g. \"gpt-4o\") — token burn is reported per model"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "required for every call after the first for this agent_id"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "required when claiming a brand-new agent_id; not\n needed once the agent_id has been claimed"
}
},
"required": [
"agent_id",
"rail",
"amount_cents",
"service"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🔴ledger_set_budget(agent_id, monthly_cents, daily_cents, monthly_tokens, daily_tokens, ...)
Set spending caps for an agent. Warns at 80%, blocks spend when exceeded — enforced: a ledger_track call that would cross the cap is rejected. Dollar caps (monthly_cents/daily_cents) and token caps (monthly_tokens/ daily_tokens) are independent dimensions: dollar caps only cover non-"tokens" rails, token caps only cover rail="tokens" bookkeeping rows (tokens_in/tokens_out). Set both if the agent uses both. Monthly cap is required; the rest are optional (0 = no limit). Overwrites any existing budget for the agent. Claiming a brand-new agent_id requires your workspace_key; that first call mints an agent_secret (returned once — save it); later calls for that agent_id must pass the agent_secret back (no workspace_key needed again).
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "unique agent identifier"
},
"monthly_cents": {
"type": "integer",
"description": "monthly spending cap in cents"
},
"daily_cents": {
"default": 0,
"type": "integer",
"description": "daily spending cap in cents (0 = no daily cap)"
},
"monthly_tokens": {
"default": 0,
"type": "integer",
"description": "monthly token-burn cap (0 = no cap)"
},
"daily_tokens": {
"default": 0,
"type": "integer",
"description": "daily token-burn cap (0 = no cap)"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "required for every call after the first for this agent_id"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "required when claiming a brand-new agent_id; not\n needed once the agent_id has been claimed"
}
},
"required": [
"agent_id",
"monthly_cents"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_report(agent_id, days, agent_secret, workspace_key)
Spend report for an agent over a rolling window. Returns total spend, breakdown by rail and by service, budget status (ok/warning/exceeded), detected anomalies, and entry count. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/report).
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "unique agent identifier"
},
"days": {
"default": 30,
"type": "integer",
"description": "report window in days (default 30)"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "the agent's own secret (either this or workspace_key)"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "the owning workspace's key (either this or agent_secret)"
}
},
"required": [
"agent_id"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_proxy_attach(agent_id, provider, agent_secret, workspace_key)
Point your provider traffic at the proxy so budget caps are enforced BEFORE the provider is contacted, instead of being reported afterwards. This closes the gap where the brake was unreachable from MCP: an agent connected over MCP could record spend (ledger_track) but nothing could refuse a call. With this, the cap is enforced on every LLM call. Returns the base_url to use, the two headers to send, and the exact change for the OpenAI and Anthropic SDKs. Your provider credential is NOT part of this: it stays in Authorization / x-api-key and is only forwarded, never stored.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "the agent whose budget the proxied calls are billed to"
},
"provider": {
"default": "openai",
"type": "string",
"description": "which upstream to proxy: openai or anthropic"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "the agent's own secret (either this or workspace_key)"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "the owning workspace's key (either this or agent_secret)"
}
},
"required": [
"agent_id"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_alerts(agent_id, agent_secret, workspace_key)
Alert history for an agent: budget warnings (80% threshold) and spending spikes. Requires a credential: either the agent's own agent_secret or its workspace's workspace_key (same rule as GET /v1/alerts).
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "unique agent identifier"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "the agent's own secret (either this or workspace_key)"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "the owning workspace's key (either this or agent_secret)"
}
},
"required": [
"agent_id"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_check_spend(agent_id, amount_cents, model, tokens_in, tokens_out, ...)
Ask BEFORE you spend: may this agent spend this much right now? Returns allowed (true/false), a stable reason code (within_budget, over_monthly_cap, over_daily_cap, over_monthly_token_cap, over_daily_token_cap, no_budget_set, unpriced_model), a one-line message, the cost estimate, the price used (with its source and as_of date) and every budget window with cap, spent and remaining. Same decision the /proxy/{provider} gate enforces. Read-only: nothing is recorded or reserved, so record the spend with ledger_track afterwards. Give exactly one spend shape: amount_cents (any rail, e.g. an x402 purchase), OR model with tokens_in/tokens_out.
Eingabe-Schema
{
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"description": "the agent that would spend"
},
"amount_cents": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "the spend in cents, if you already know it"
},
"model": {
"default": "",
"type": "string",
"description": "model id to price from tokens (instead of amount_cents)"
},
"tokens_in": {
"default": 0,
"type": "integer",
"description": "expected input tokens (with model)"
},
"tokens_out": {
"default": 0,
"type": "integer",
"description": "expected output tokens, e.g. your max_tokens (with model)"
},
"agent_secret": {
"default": "",
"type": "string",
"description": "the agent's own secret (either this or workspace_key)"
},
"workspace_key": {
"default": "",
"type": "string",
"description": "the owning workspace's key (either this or agent_secret)"
}
},
"required": [
"agent_id"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_price(model, tokens_in, tokens_out)
What will this call cost? Priced from the same table the caps use. Exists because ledger_track requires the CALLER to supply amount_cents, so an agent whose spend is capped could under-report its own cost and stay under the cap. This returns the number the enforcement path would use, so an agent can report honestly (and plan before it spends). Cost = (tokens_in * in_rate + tokens_out * out_rate) / 1_000_000. If the model has cache rates, the standard in-rate is used, which is the conservative direction for a spend cap. Every price carries the source it came from and the date it was read, and `verified: false` means the number was NOT read off the provider's own pricing page. Treat an unverified price as an estimate, not a measurement.
Eingabe-Schema
{
"type": "object",
"properties": {
"model": {
"type": "string",
"description": "the model id you are about to call (e.g. gpt-4o, claude-sonnet-4)"
},
"tokens_in": {
"default": 0,
"type": "integer",
"description": "expected input tokens"
},
"tokens_out": {
"default": 0,
"type": "integer",
"description": "expected output tokens, e.g. your max_tokens"
}
},
"required": [
"model"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟡ledger_start
Get a FREE AgentLedger workspace with no credential and no arguments — the MCP equivalent of opening POST /start in a browser. Call this FIRST if you have no credentials yet. Every other tool here (ledger_track, ledger_set_budget, ledger_report, ledger_alerts) needs a workspace_key or an agent_secret, so a caller arriving with neither must start here or it has nowhere to go. Takes NO arguments on purpose: the goal is zero friction. It returns a `workspace_key` (shown exactly once — it cannot be re-revealed, so store it before continuing) which you then send as `workspace_key` on your first ledger_track for a NEW agent_id. That first write returns the agent's own `agent_secret`, which authenticates every write after it. The free tier includes every rail, enforced budget caps, alerts, reports and the MCP server, capped at 3 agents per workspace. Minting is rate-limited per caller IP, the same limit the human door uses. Prefer to pay? POST /v1/billing/x402 with a wallet-signed payment needs no human and buys 24h of Pro (unlimited agents).
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_api_docs(topic)
Self-serve documentation for AgentLedger — quickstart, MCP tools, REST endpoints, budget caps, error codes, and idempotency usage, as markdown.
Eingabe-Schema
{
"type": "object",
"properties": {
"topic": {
"default": "",
"type": "string",
"description": "\"quickstart\" | \"mcp\" | \"rest\" | \"budget\" | \"errors\" | \"idempotency\" | \"all\"\n (default \"\" == \"all\"). Unknown topics fall back to the full docs."
}
},
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢ledger_examples(pattern)
Complete, runnable Python recipe for a common AgentLedger integration pattern.
Eingabe-Schema
{
"type": "object",
"properties": {
"pattern": {
"type": "string",
"description": "\"python_tracking\" | \"budget_enforcement\" | \"weekly_report\" |\n \"retry_safe_writes\""
}
},
"required": [
"pattern"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢skills_list_tool
List this product's skills. Each entry carries the SKILL.md URI, its name and description, verbatim frontmatter, and a per-file sha256 manifest. Read a body with `read_skill`.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}🟢read_skill(uri)
Read a product skill file by its skill:// URI.
Eingabe-Schema
{
"type": "object",
"properties": {
"uri": {
"type": "string",
"description": "e.g. skill://<product>/<skill-name>/SKILL.md\n Get valid URIs from `skills_list_tool`."
}
},
"required": [
"uri"
],
"additionalProperties": false
}Ausgabe-Schema
{
"type": "object",
"additionalProperties": true
}Community
Nachweis