Back to Browse

Dcl Webhook MCP Server

Developer ToolsModerate5.3MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Deterministic AI audit layer for LLM/agent outputs: policy checks, tamper-evident log, x402.

About

Deterministic AI audit layer for LLM/agent outputs: policy checks, tamper-evident log, x402.

Remote endpoints: streamable-http: https://mcp.fronesislabs.com/mcp

Security Report

5.3
Moderate5.3Moderate Risk

DCL Trust Oracle is a deterministic audit system with reasonable security architecture, but has several code quality and permission scope concerns that warrant attention. The codebase includes proper authentication via x402 protocol, stateless crypto detectors with appropriate regex-based patterns, and metadata-only storage design. However, incomplete input validation in regex patterns, overly broad exception handling, potential information leakage through verbose error messages, and excessive permissions for the stated purpose lower the score into the moderate range. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity).

3 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

DCL Trust Oracle — x402 MCP Server

Python 3.11+ MCP x402 License: MIT dcl-webhook MCP server Smithery Score

Deterministic AI audit layer with cryptographic micropayments via x402 protocol.

What It Does

DCL Trust Oracle provides deterministic policy evaluation for LLM outputs with a tamper-evident audit chain. The system stores only cryptographic hashes and decision metadata — never raw content — enabling verifiable, post-action forensic analysis across distributed AI agents.

Available two ways, both metered per call via x402:

  • REST API (webhook_server.py) — direct HTTP integration, x402-gated with fastapi-x402.
  • MCP Server (mcp_server.py) — native Model Context Protocol integration for AI agents, hosted on Smithery, x402-gated with paymcp.

Both servers share the same evaluation logic and tamper-evident chain (dcl_core.py), and are priced identically.

Quick Start

REST API

pip install -r requirements.txt
python webhook_server.py

Server runs on http://localhost:8080

MCP Server

pip install -r requirements.txt
python mcp_server.py

Server runs on http://localhost:8081 (streamable-http transport)

Tools & Endpoints

Pre-Action Evaluation

REST EndpointMCP ToolPriceDescription
POST /evaluate/fastdcl_evaluate_fast$0.01Fast policy check for low-risk outputs. Returns tamper-evident tx_hash.
POST /evaluate/strictdcl_evaluate_strict$0.05Deep analysis for high-stakes outputs with higher confidence thresholds.
POST /evaluate/jailbreakdcl_evaluate_jailbreak$0.02Instruction adherence check — detects prompt injection patterns and role-hijacking attempts.
POST /evaluate/safetydcl_evaluate_safety$0.01Baseline screening for known harmful text patterns. Optimized for high throughput.
POST /evaluate/qualitydcl_evaluate_quality$0.03Content quality & drift check — evaluates format adherence and contextual drift.
POST /evaluate/batchdcl_evaluate_batch$0.10Bulk processing — up to 20 items per transaction. Cost-effective for multi-turn history.

Session Management

REST EndpointMCP ToolPriceDescription
POST /pipeline/startdcl_pipeline_start$0.05Initializes a long-running audit session for continuous drift tracking. Returns pipeline_id.

Post-Action Forensics

REST EndpointMCP ToolPriceDescription
GET /audit/{tx_hash}dcl_audit_decode$0.10Basic post-action audit — returns verdict, confidence, agent_id, reason by tx_hash.
GET /audit/{tx_hash}/deepdcl_audit_decode_deep$0.50Deep forensic audit — includes drift context, tamper-evidence indices, environmental metadata.

Utility (free, REST only)

EndpointDescription
GET /healthService status and chain length
GET /policiesList of built-in policy names
GET /chain/statusChain integrity, drift mode, drift score
GET /chain/exportFull chain export with integrity verification

Example Response

{
  "verdict": "COMMIT",
  "confidence": 0.95,
  "reason": "All policy checks passed",
  "tx_hash": "0x7a8f3b2c...",
  "chain_index": 42,
  "input_hash": "0x9d4e1f...",
  "policy_version": "1.0.0",
  "timestamp": 1721635200.123,
  "pipeline_id": "abc123",
  "drift_mode": "NORMAL",
  "drift_score": 0.15
}

x402 Integration

All paid endpoints and tools require payment via the x402 protocol before returning a result — no free tier, no bypass. Both the REST API and MCP server settle to the same wallet.

  • Networks: Base, Avalanche, IoTeX
  • Asset: USDC
  • Facilitator (REST): https://x402.org/facilitator (via fastapi-x402)
  • Facilitator (MCP): paymcp in Mode.AUTO — automatic on-chain payment for x402-aware MCP clients, guided payment link (ELICITATION/RESUBMIT) for clients without a wallet. No path skips payment.

Metadata-Only Architecture

DCL Trust Oracle is designed around a hash-based audit trail:

  • Raw content never stored — only SHA-256 hashes and decision metadata
  • Tamper-evident cryptographic chain (SQLite-backed, WAL mode)
  • Chain survives server restarts — audit records persist indefinitely
  • Verifiable integrity via GET /chain/status
  • Full export via GET /chain/export
  • Shared chain across REST and MCP — a tx_hash returned by one interface can be audited through the other

Each audit record contains: tx_hash, prev_hash, verdict, input_hash, policy_hash, agent_id, reason, confidence, task_type, timestamp, and drift_context.

Built-in Policies

PolicyMin ConfidencePurpose
default0.70General-purpose evaluation
anti_jailbreak0.80Detects prompt injection, role-hijacking, DAN-style attacks
safety0.75Baseline harmful-pattern screening
content_quality0.85Quality assurance, format adherence, drift detection

Custom policies can be passed inline as YAML via the policy field.

Links

Contact

partnership@fronesislabs.com

Reviews

No reviews yet

Be the first to review this server!