Server data from the Official MCP Registry
Bounded KVP, RAG search, and wipe receipts for agent jobs over remote MCP
About
Bounded KVP, RAG search, and wipe receipts for agent jobs over remote MCP
Remote endpoints: streamable-http: https://tillpad.cnrcode.com/mcp
Security Report
This is a catalog stub and schema reference for a remote MCP server. The code itself is minimal and safe—it defines tool schemas that match a hosted Tillpad service without implementing actual functionality. Authentication is properly delegated to the remote endpoint (Bearer token required), and no sensitive data is hardcoded. The codebase has appropriate input validation via Zod schemas and makes no dangerous system calls. Minor quality observations include broad catch-all error handling and stub responses that could be more granular, but these do not pose security risks. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).
4 files analyzed · 5 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
Tillpad MCP
Bounded storage and search for agent jobs.
Tillpad gives agents namespaced key-value storage, file upload + semantic search, receive-only email inboxes, budget-aware metering, and run keys that wipe with a signed receipt when the job is done.
Live endpoint: https://tillpad.cnrcode.com/mcp
This repository is the public catalog and schema stub for directory crawlers. It is not the hosted server. Point MCP clients at the live URL above with a Tillpad API key. Running the TypeScript in this repo does not store or search anything.
Agent guide: see AGENTS.md for discovery URLs, auth, and MCP connect snippets.
Get an API key
Zero-human (agents)
POST https://tillpad.cnrcode.com/api/agents/bootstrapwith{ "email": "agent@example.com" }→bootstrapToken(no outbound mail).POST https://tillpad.cnrcode.com/api/billing/machine-paywithAuthorization: Bearer <bootstrapToken>and optional{ "sku": "pro_prepaid_30d" }.- Settle Stripe MPP ($9.00 / 30 days) → response includes
secret(tp_…) andplanPeriodEnd.
See scratchpad.txt and llms-full.txt. Legal: Terms.
Human path
- Open tillpad.cnrcode.com and create an account.
- Subscribe to Tillpad Pro on Pricing, then mint an API key in the dashboard. Secrets start with
tp_. - Use an account key for ongoing access, or a run key when the job should expire and wipe.
Never commit a real key. Use the tp_… placeholder in configs.
Connect a client
Transport is Streamable HTTP. Send Authorization: Bearer tp_… on every request.
Cursor
Install via Cursor Marketplace (plugin)
This repo includes a Cursor plugin manifest and root mcp.json for one-click install from the Cursor Marketplace.
Tillpad MCP tools cover namespaced KVP, RAG search, receive-only email inboxes, scheduled HTTPS jobs, budget metering, and run-key wipe receipts.
- Install the Tillpad plugin from the marketplace (or test locally — see below).
- Open Cursor Settings → Customize → Tillpad and set Tillpad API key (
tp_…from bootstrap + machine-pay or the dashboard). - Reload the window. MCP tools should appear under the Tillpad server.
The plugin points at https://tillpad.cnrcode.com/mcp with Authorization: Bearer ${TILLPAD_API_KEY}. Never commit a real key.
Local plugin test (before marketplace submission):
# Copy catalog repo into Cursor local plugins folder
$dest = "$env:USERPROFILE\.cursor\plugins\local\tillpad"
New-Item -ItemType Directory -Force -Path $dest | Out-Null
Copy-Item -Recurse -Force "C:\dev\tillpad\tillpad-mcp\*" $dest
# Then: Cursor Customize → Tillpad → set TILLPAD_API_KEY → Developer: Reload Window
Submit the public repo at cursor.com/marketplace/publish when ready.
Manual MCP config
User or project MCP config:
{
"mcpServers": {
"tillpad": {
"url": "https://tillpad.cnrcode.com/mcp",
"headers": {
"Authorization": "Bearer tp_…"
}
}
}
}
Claude Desktop / Claude Code
{
"mcpServers": {
"tillpad": {
"command": "npx",
"args": ["mcp-remote", "https://tillpad.cnrcode.com/mcp", "--header", "Authorization: Bearer tp_…"]
}
}
}
Generic remote MCP
{
"url": "https://tillpad.cnrcode.com/mcp",
"headers": {
"Authorization": "Bearer tp_…"
}
}
Discovery manifests on the product host:
Tools
Schemas in src/server.ts match the hosted server.
| Tool | What it does |
|---|---|
get_usage | Usage for one month (view=summary), paged history (view=periods), or remaining quotas (view=budget) |
estimate_usage | Preflight 402/429 before a meter spend (textLength / byteLength for rag_index) |
manage_billing | MPP machine-pay instructions (action=machine_pay), Stripe portal URL, or purchase history |
bootstrap_agent | Zero-human onboarding: bootstrap token from email (no outbound mail) |
create_api_key | Mint a run or sub key from an account tp_ key |
manage_kv | Put, get, delete, or list a namespaced string |
manage_memory | Put or get memory scope prefs / facts / run |
search_documents | Semantic search over indexed documents or a memory scope |
index_document | Index a named UTF-8 file (kind=file) or a short note (kind=note) |
list_files | List uploads (view=files) or supported types (view=supported_types) |
get_storage_summary | Namespace inventory (scoped to the key when applicable) |
finish_run | Wipe namespaces bound to this run key; returns a signed wipe receipt |
contact_support | Contact Tillpad support from a Pro account; replies go to the account email |
manage_inbox | Create, list, get, delete, or audit receive-only inboxes |
read_inbox_message | List metadata, get one message, download raw MIME, or fetch an attachment |
manage_inbox_webhook | Register, list, disable, or inspect email.received webhook deliveries |
manage_inbox_blocklist | List, add, or remove a blocked sender address or domain |
manage_schedule | Create, list, get, disable, or list runs for HTTPS interval jobs |
Typical agent loop
- Mint a run key with
create_api_key(or the dashboard): dedicated namespace, TTL, optional op budget. - Store working state with
manage_memory/manage_kvand/orindex_document. - Retrieve with
manage_memory/manage_kvandsearch_documents. - Call
finish_runto wipe run namespaces and keep the signed receipt.
Use estimate_usage before large index jobs. get_usage shows what is left in the period.
Auth and errors
- 401 — missing or invalid
Authorization: Bearer tp_… - 402 / 429 — plan or quota. JSON includes
code,status,actions, andbudgetactions[].type: "checkout"— hosted Stripe Checkout URL for a recurring human subscriptionactions[].type: "machine_pay"— agent prepaid Pro (30/90 days) or top-up SKUs via Stripe MPP; default skupro_prepaid_30dat $9.00
This is Stripe Machine Payments Protocol, not ChatGPT Instant Checkout / ACP.
Product docs
- App: tillpad.cnrcode.com
- Docs: tillpad.cnrcode.com/docs
- Scratchpad: tillpad.cnrcode.com/docs/scratchpad
- OpenAPI: tillpad.cnrcode.com/openapi.json
The Tillpad product (Worker, billing, storage) is closed source. This catalog is MIT-licensed so directories can list tools and install snippets.
Directory listing
Registry name: com.cnrcode/tillpad (domain namespace via cnrcode.com).
-
Ensure
https://cnrcode.com/.well-known/mcp-registry-authis deployed (cnrcode-siterepo). -
Set GitHub repo secret
MCP_PRIVATE_KEY(hex; seecnrcode-sitekey generation script). -
Push a version tag so GitHub Actions publishes
server.jsonto the official MCP Registry:git tag v0.1.1 git push origin v0.1.1 -
Optionally submit https://github.com/CNR-Consulting/tillpad-mcp at mcp.directory/submit.
Glama
This repo includes a stdio catalog stub (src/main.ts) so Glama can build a container, start the process, and introspect the 18 tool definitions. It does not implement storage or billing — clients still connect to the hosted endpoint above.
Listing: glama.ai/mcp/servers/number1101/tillpad-mcp
After claiming via glama.json, configure the Dockerfile admin page:
| Field | Value |
|---|---|
| Build steps | ["npm ci", "npm run build"] |
| CMD arguments | ["node", "dist/main.js"] |
| Env schema | default (empty — no credentials needed) |
| Placeholder params | {} |
Glama generates its own Dockerfile from that form; the repo Dockerfile is for local smoke tests only.
Score badge (for awesome-mcp-servers and similar lists):
[](https://glama.ai/mcp/servers/number1101/tillpad-mcp)
Local verify:
npm ci && npm run build && npm start # hangs on stdio — expected
docker build -t tillpad-mcp-stub . && docker run -i tillpad-mcp-stub
Full step-by-step (claim, admin Dockerfile, release, awesome-mcp PR): docs/glama-release.md.
License
MIT — catalog, documentation, and schema stub only.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 90 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
