Back to Browse

Tillpad MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Bounded KVP, RAG search, and wipe receipts for agent jobs over remote MCP

About

Bounded KVP, RAG search, and wipe receipts for agent jobs over remote MCP

Remote endpoints: streamable-http: https://tillpad.cnrcode.com/mcp

Security Report

6.2
Moderate6.2Moderate Risk

This is a well-designed schema stub for a remote MCP server with excellent security practices. The repository correctly delegates all functionality to a hosted remote server, requires Bearer token authentication via environment-injected headers, and contains no dangerous patterns, hardcoded secrets, or malicious code. The codebase is minimal, properly typed with Zod validation, and documentation clearly warns users against committing real keys. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).

3 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Tillpad MCP

Bounded storage and search for agent jobs.

Remote MCP Transport Auth License: MIT

Tillpad gives agents namespaced key-value storage, file upload + semantic search, budget-aware metering, and run keys that wipe with a signed receipt when the job is done.

Live endpoint: https://tillpad.cnrcode.com/mcp

This repository is the public catalog and schema stub for directory crawlers. It is not the hosted server. Point MCP clients at the live URL above with a Tillpad API key. Running the TypeScript in this repo does not store or search anything.

Agent guide: see AGENTS.md for discovery URLs, auth, and MCP connect snippets.

Get an API key

Zero-human (agents)

  1. POST https://tillpad.cnrcode.com/api/agents/bootstrap with { "email": "agent@example.com" }bootstrapToken (no outbound mail).
  2. POST https://tillpad.cnrcode.com/api/billing/machine-pay with Authorization: Bearer <bootstrapToken> and optional { "sku": "pro_prepaid_30d" }.
  3. Settle Stripe MPP ($9.00 / 30 days) → response includes secret (tp_…) and planPeriodEnd.

See scratchpad.txt and llms-full.txt. Legal: Terms.

Human path

  1. Open tillpad.cnrcode.com and create an account.
  2. Subscribe to Tillpad Pro on Pricing, then mint an API key in the dashboard. Secrets start with tp_.
  3. Use an account key for ongoing access, or a run key when the job should expire and wipe.

Never commit a real key. Use the tp_… placeholder in configs.

Connect a client

Transport is Streamable HTTP. Send Authorization: Bearer tp_… on every request.

Cursor

User or project MCP config:

{
  "mcpServers": {
    "tillpad": {
      "url": "https://tillpad.cnrcode.com/mcp",
      "headers": {
        "Authorization": "Bearer tp_…"
      }
    }
  }
}

Claude Desktop / Claude Code

{
  "mcpServers": {
    "tillpad": {
      "command": "npx",
      "args": ["mcp-remote", "https://tillpad.cnrcode.com/mcp", "--header", "Authorization: Bearer tp_…"]
    }
  }
}

Generic remote MCP

{
  "url": "https://tillpad.cnrcode.com/mcp",
  "headers": {
    "Authorization": "Bearer tp_…"
  }
}

Discovery manifests on the product host:

Tools

Schemas in src/server.ts match the hosted server.

ToolWhat it does
usage_getCurrent period usage and quotas
budget_getRemaining quotas, soft thresholds, and a checkout URL
budget_estimatePreflight 402/429 before spending (textLength / byteLength for rag_index)
billing_machine_payHow agents unlock prepaid Pro or buy SKUs via Stripe MPP (sku optional)
agent_bootstrapZero-human onboarding: bootstrap token from email (no outbound mail)
keys_createMint a run/sub key from an account tp_ key
kvp_putStore a string under a namespace/key (response includes budget)
kvp_getRead a namespaced value
kvp_deleteDelete a KVP key
kvp_listList keys in a namespace
file_uploadUpload UTF-8 text for RAG indexing (prefLights rag_index)
files_listList uploaded files
files_typesSupported upload extensions and MIME types
rag_searchSemantic search over indexed documents
inspect_storageNamespace inventory (scoped to the key when applicable)
run_finishWipe namespaces bound to this run key; returns a signed wipe receipt
support_contactContact Tillpad support from a Pro account; replies go to the account email

Typical agent loop

  1. Mint a run key in the dashboard (dedicated namespace, TTL, optional op budget).
  2. Store working state with kvp_put and/or file_upload.
  3. Retrieve with kvp_get / kvp_list and rag_search.
  4. Call run_finish to wipe run namespaces and keep the signed receipt.

Use budget_estimate before large index jobs. budget_get / usage_get show what is left in the period.

Auth and errors

  • 401 — missing or invalid Authorization: Bearer tp_…
  • 402 / 429 — plan or quota. JSON includes code, status, actions, and budget
    • actions[].type: "checkout" — hosted Stripe Checkout URL for a recurring human subscription
    • actions[].type: "machine_pay" — agent prepaid Pro (30/90 days) or top-up SKUs via Stripe MPP; default sku pro_prepaid_30d at $9.00

This is Stripe Machine Payments Protocol, not ChatGPT Instant Checkout / ACP.

Product docs

The Tillpad product (Worker, billing, storage) is closed source. This catalog is MIT-licensed so directories can list tools and install snippets.

Directory listing

Registry name: com.cnrcode/tillpad (domain namespace via cnrcode.com).

  1. Ensure https://cnrcode.com/.well-known/mcp-registry-auth is deployed (cnrcode-site repo).

  2. Set GitHub repo secret MCP_PRIVATE_KEY (hex; see cnrcode-site key generation script).

  3. Push a version tag so GitHub Actions publishes server.json to the official MCP Registry:

    git tag v0.1.1
    git push origin v0.1.1
    
  4. Optionally submit https://github.com/number1101/tillpad-mcp at mcp.directory/submit.

License

MIT — catalog, documentation, and schema stub only.

Reviews

No reviews yet

Be the first to review this server!