Back to Browse

Tapeapi MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Signed BNB Chain reads (balances, tokens, NFTs, prices, TapeOut names) with verifiable receipts

About

Signed BNB Chain reads (balances, tokens, NFTs, prices, TapeOut names) with verifiable receipts

Remote endpoints: streamable-http: https://api.tapeapi.fun/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

8 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-brucelanlan-tapeapi": {
      "url": "https://api.tapeapi.fun/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

TapeAPI

A signed receipt for every AI call. Put a sidecar in front of your OpenAI- or Anthropic-compatible API, and every answer comes with a receipt anyone can check: who answered, to which request, with which bytes, and what usage and price were claimed. Your users keep their official SDKs and change only the base URL.

TapeAPI is the signed API layer of TapeOut. The same on-chain identity and signatures also cover MCP tools and end-to-end encrypted channels and groups, on BNB Chain, X Layer and Base.

CI Code: MIT Spec: CC0-1.0 Docs Playground Status

中文说明 · Website · Docs · Guides · Specifications · Examples · Changelog · Roadmap

Status: released, 1.3.0. Everything live today is free. From 1.0 on, TapeAPI follows semantic versioning: breaking changes come only in 2.0. Paid channels (TAPI-22) are experimental and not deployed. Nothing here has had a third-party audit.

Start here

You areYour first five minutesGuide
An AI provider or relay (new-api, a gateway, your own models)docker compose up in examples/new-api-sidecar, publish your price table in the holder console, point your users' base URL at the sidecarFor AI providers
An MCP server authorRun the signing proxy in front of your server, then publish the manifest with the consoleTape out your MCP server
An app developerRun the examples below; check AI receipts with createVerifyingFetch; start channels and groups from examples/group-chatCall a service · Channels · Groups
A TapeOut circuit holderOpen your circuit's container, then generate a service key, sign the delegation and publish the manifest in the consoleRun a service
A Claude, Cursor or other MCP userAdd https://api.tapeapi.fun/mcp as a connectorMCP

Try it

A signed answer. The public service 11.1013.tape answers eight free, block-pinned reads of BNB Chain:

curl -s https://api.tapeapi.fun/tapeapi/v1/bnbUsd -H 'content-type: application/json' -d '{"id":"1","params":{}}'

curl shows the signed envelope but checks nothing. The SDK checks it. It is not on npm yet; install it from the GitHub release (Node.js 20 or later):

npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz

The server package (@tapeapi/server: providers, the AI sidecar, the MCP proxy) depends on this SDK, which is not on npm either, so installed alone it fails with a 404: install both in one command, npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-server-1.3.0.tgz.

// try.mjs: node try.mjs
import { createTapeAPI, rpcUrlsFor } from '@tapeapi/sdk'

const api = createTapeAPI({ rpcUrls: rpcUrlsFor(56) })   // nodes of 3 distinct operators; 2 must agree
const service = await api.resolve('11.1013.tape')         // name, container, on-chain manifest, delegation
const { result, verified } = await api.call(service, 'bnbUsd', {})
console.log(result.bnbUsd, verified)                      // true only after the signature checked out

AI receipts. Plug createVerifyingFetch into the official OpenAI SDK (npm install openai; the Anthropic SDK takes a fetch too). Replace 42.1013.tape with the provider's TapeOut name:

import OpenAI from 'openai'
import { createTapeAPI, rpcUrlsFor, ai } from '@tapeapi/sdk'

const api = createTapeAPI({ rpcUrls: rpcUrlsFor(56) })
const service = await api.resolve('42.1013.tape')        // the AI provider's name (an example)
const { baseUrl } = service.manifest.ai.endpoints.find((e) => e.format === 'openai-chat')
const client = new OpenAI({
  baseURL: baseUrl,                                      // the address the provider published on chain
  apiKey: process.env.API_KEY,                           // your key with that provider, as before
  fetch: ai.createVerifyingFetch({ api, service }),      // checks every receipt; a bad one throws
})
const r = await client.chat.completions.create({ model: 'gpt-4o-mini', messages: [{ role: 'user', content: 'Hello' }] })
console.log(r.choices[0].message.content)

No outside provider has published a price table on chain yet, so this was run against the reference sidecar in examples/ai-proxy (local dev mode); with a real provider only the name changes.

Claude Code and Codex cannot read receipts themselves. Run the local verifying proxy and point them at it:

# Terminal 1 (it keeps running). 42.1013.tape is an example name: put your AI provider's TapeOut name here
npx -y --package=https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz tapeapi-verify 42.1013.tape
# Terminal 2, macOS or Linux
ANTHROPIC_BASE_URL=http://127.0.0.1:8790 claude
OPENAI_BASE_URL=http://127.0.0.1:8790/v1 codex             # Codex (or base_url in config.toml)
# Terminal 2, Windows PowerShell
$env:ANTHROPIC_BASE_URL="http://127.0.0.1:8790"; claude
$env:OPENAI_BASE_URL="http://127.0.0.1:8790/v1"; codex

Run as written, tapeapi-verify 42.1013.tape stops with "no file at /.well-known/tapeapi.json": the name is an example and no service is published under it. To watch a receipt verify end to end without any provider, run the local trial (no key, no circuit, no cost) from a checkout of this repository, after installing its dependencies once at its root:

git clone https://github.com/BruceLanLan/tapeapi.git && cd tapeapi
npm ci --no-audit --no-fund
node examples/relay-trial/trial.mjs

Running an AI service yourself? Start at From zero to live; the provider's check, tapeapi-doctor (experimental), ships in the same release package.

MCP. The same eight reads are tools at https://api.tapeapi.fun/mcp, with a signed receipt on every result:

claude mcp add --transport http tapeapi https://api.tapeapi.fun/mcp

No install at all: the playground runs the SDK in your browser.

How it fits together

flowchart LR
    client["Client<br/>official SDK, Claude Code, Codex"]
    sidecar["Signing sidecar or MCP proxy<br/>(you run it)"]
    upstream["Your API or MCP server"]
    chain[("On chain: BNB Chain, X Layer, Base<br/>identity, manifest, price table, signer delegation")]
    client -- "request" --> sidecar
    sidecar -- "same bytes" --> upstream
    sidecar -- "answer + signed receipt" --> client
    sidecar -. "published once by the holder" .-> chain
    client -. "verify against" .-> chain
LayerWhat it isSpec
IdentityA TapeOut circuit's ERC-6551 container. Whoever holds the circuit owns the service; transfer the circuit and the service moves with it.TAPI-20
Manifest.well-known/tapeapi.json in the container's on-chain site: endpoints, methods, the AI price table, the hash of MCP tool definitions, the signing key and the holder's delegation of it.TAPI-20
Signed answers and receiptsEvery answer is signed and bound to its request; AI calls get a usage receipt.TAPI-21
Channels and groupsEnd-to-end encrypted, over a relay or ChannelBus; the carrier sees ciphertext only.TAPI-26, TAPI-27

What a receipt proves, and what it does not

A receipt proves who answered (a key the circuit's holder delegated on chain), to exactly which request bytes, with exactly which response bytes, and what usage and price were claimed, priced from the table on chain.

It does not prove which model actually ran: a provider could label a cheaper model's answer as a dearer one. What the signature adds is accountability. A receipt cannot be disowned, so anyone running the spot-check probe and publishing the results leaves evidence.

Status and commitments

  • Live, free, no sign-up: the public service api.tapeapi.fun (8 methods), its MCP endpoint, the public relay relay.tapeapi.fun (relaySend, relayHandshake, relayRecv), ChannelBus, and the website's console, receipt checker, playground and status page.
  • Available, you run it: the AI signing sidecar and the new-api package, the MCP signing proxy, tapeapi-verify, tapeapi-mcp, the spot-check probe, and one-call group delivery (deliverGroupUpdate) in the SDK.
  • Experimental, not deployed: paid channels and the escrow (TAPI-22), the service directory, and circuit-verified methods (TAPI-25). None of them is part of the 1.0 stability promise.
  • What 1.0 promises: code written against the 1.0 docs keeps working in every 1.x release; everything is Stable except what is marked @experimental or @internal. Coming from 0.x: Upgrading to 1.0.
  • What we do not do: host the sidecar for anyone (it sees your users' API keys, so you run it); issue a token; help anyone get around an upstream provider's bans or regional limits (TapeAPI is for providers working within their upstream's terms).
  • Chains: BNB Chain (chainId 56) for everything, and the only chain where payments will run. X Layer (196) and Base (8453) are read-only: identity, resolution, receipts and MCP checks. X Layer has only two independent RPC operators.
  • No third-party audit. Tests: the JavaScript suite (npm test), the contract tests (forge test) and an independent Python implementation of every signature, hash and encoding (python3 spec/vectors/verify.py), all three run by CI on every push.

Privacy, plainly

  • Protected: channel and group content (end-to-end encrypted); AI receipts carry hashes only, and requests sent through the SDK or tapeapi-verify get 128 random bits of whitespace, so a short prompt cannot be confirmed from its hash; MCP verification links carry hashes only by default; the SDK's busPrivacyReader (experimental) reads all of ChannelBus and filters locally, so nodes cannot see your rooms.
  • Not hidden: a service sees what it processes (your request, your IP, your API key); public RPC nodes see your IP and which service you check; relays and the chain see channel rooms, timing and sizes; everything on chain is public, including future payments.

Fees

No mandatory protocol fee; a default 1% maintenance contribution that any provider can turn off; the operator has no fee switch. The contribution applies only when a paid channel settles, out of the provider's share, and the user's price does not change. The paid-call escrow is not deployed, so no call is charged today. AI providers bill their users off chain as they do now; the prices in their manifest are published, not settled. See docs/FEES.md.

Specifications

These are TapeAPI's own specifications, not TAPs. Parts of them have been submitted as TAP drafts to TapeOutProtocol/TAPs: #8 (service identity and manifest), #10 (signed responses) and #12 (private channels).

SpecTitleStatus
TAPI-1TapeAPI's document process and statusesDraft
TAPI-20Service identity and manifest, with the AI price table and multi-chain namesStable (v1); §3.5 Experimental
TAPI-21Signed response envelope, with AI usage receiptsStable (v1)
TAPI-22Metered payment: vouchers and escrowExperimental
TAPI-23Attested read, cross-checked by independent providersStable (v1)
TAPI-24Intent RFQWithdrawn
TAPI-25Circuit-verified methodsExperimental
TAPI-26Private channels between containersStable (v1)
TAPI-27Private groups of up to 32 containers (up to 128 in the experimental format 2)Stable (v1)

The specs are bilingual; English is authoritative. TAPI-1 and TAPI-20 to TAPI-27 are TapeAPI's own document names, not TAP numbers: TAPs are numbered by the editors of TapeOutProtocol/TAPs under TAP-01. Frozen constants that contain an old name, such as the TAP-26/… and TAP-27/… labels, never change.

Repository

sdk/ @tapeapi/sdk (resolve, call, verify, AI receipts, channels, groups, MCP) · server/ @tapeapi/server (providers, the AI sidecar, the MCP proxy) · contracts/ (ChannelBus, and the experimental escrow and directory) · spec/ (the specs, test vectors, the Python verifier) · examples/ · conformance/ · site/ (the website) · docs/. Contract addresses are in the introduction.

Report security issues privately as described in SECURITY.md. Issues and pull requests are welcome; see CONTRIBUTING.md and the Code of Conduct.

License

Code is MIT (LICENSE): contracts/, sdk/, server/, examples/, conformance/, scripts/, site/. The specifications in spec/ are CC0-1.0 (LICENSE-SPEC).

Credits

The idea of a service layer for TapeOut, "DeWEB is websites, TapeSend is messaging, TapeAPI is services", came from @Theairresearch. A permanent 10% of any revenue TapeAPI earns goes to them.

Built on TapeOut and TapeKit.

Reviews

No reviews yet

Be the first to review this server!