Back to Browse

Packages MCP Server

Developer ToolsLow Risk9.7MCP RegistryLocal
Free

Server data from the Official MCP Registry

Kill switch + spend guard for AI agents that spend money, across every wallet vendor at once.

About

Kill switch + spend guard for AI agents that spend money, across every wallet vendor at once.

Security Report

9.7
Low Risk9.7Low Risk

Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

15 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Base URL of the Countersign Core to govern (hosted or self-hosted).Optional

Environment variable: COUNTERSIGN_URL

API key for the Core (self-serve one at https://app.countersign.network/start or POST /signup).Required

Environment variable: COUNTERSIGN_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-countersign-network-countersign": {
      "env": {
        "COUNTERSIGN_URL": "your-countersign-url-here",
        "COUNTERSIGN_API_KEY": "your-countersign-api-key-here"
      },
      "args": [
        "-y",
        "@countersign/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Countersign

CI npm — @countersign/sdk npm — @countersign/mcp npm downloads License: Apache-2.0

A neutral, cross-vendor control plane for AI agents that spend money. Countersign holds the policy, the freeze, and the audit ledger across multiple agent-wallet backends at once — the one thing no single wallet vendor can do, because each only governs its own rail. That aggregation is the moat.

Countersign — one policy, one sub-second freeze, one signed ledger, across every wallet vendor

Live version of this loop: countersign.network/demo.html · 60s video

One falsifiable test defines it: can Countersign freeze agents across many backends at once, in under a second, with a unified tamper-evident ledger of every attempt? Proven LIVE across four rails (Coinbase, Turnkey, Openfort, and a Lithic Visa card) in ~432ms on testnet.

This repository is the open-core front door — the Apache-2.0 packages you build against: the integration contract, the typed client, the MCP tools, and the x402 guard. The control-plane "brain" (the policy compiler, the hash-chained ledger, the vendor adapters, and the hosted Core) is separate and proprietary; you reach it over the network via the SDK/MCP, hosted at app.countersign.network.

Quickstart

Drop the kill switch + spend guard into any MCP client (Claude, Cursor, …) — one line:

// claude / cursor mcp config
{ "mcpServers": { "countersign": {
  "command": "npx", "args": ["-y", "@countersign/mcp"],
  "env": { "COUNTERSIGN_URL": "https://app.countersign.network", "COUNTERSIGN_API_KEY": "csk_…" }
}}}

Or wire it into your own agent with the SDK:

import { CountersignClient } from "@countersign/sdk";
const cs = new CountersignClient({ baseUrl, apiKey });

await cs.evaluate({ agentId, amount, asset, venue }); // may this spend happen? (allow / deny / needs_approval)
await cs.freeze();                                     // the kill switch — every backend, < 1s

Get a free testnet key at https://app.countersign.network/start?ref=gh-readme.

Agents paying agents? See examples/guarded-payee — the A2A/AP2 pattern where a payee advertises it is governed and the payer verifies that (and guards its own payment) before any mandate is signed.

Packages (this repo — all Apache-2.0)

PackageRole
@countersign/corethe EnforcementProvider interface, branded ids, the unified policy schema, the fail-closed freeze controller — the integration contract every backend implements
@countersign/api-contractOpenAPI + typed REST/ws schema — the single source of truth for the Client↔Core wire interface
@countersign/sdktyped client over the Core API + live ledger subscribe
@countersign/mcpCountersign as MCP tools — kill switch + spend guard inside any MCP client
@countersign/x402govern x402 (HTTP-402 machine payments) — guard a payment before it pays
@countersign/verifyverify a ledger entry offline — hash chain, RFC 6962 Merkle inclusion, Ed25519 signatures
@countersign/ap2govern AP2 (Agent Payments Protocol) — guard an agent-payment mandate before it executes

The proprietary brain (policy compiler to each backend's native controls, ledger, Coinbase / Turnkey / Openfort / Lithic adapters, the hosted Core) lives in a separate private repository.

Prime directives (invariants)

  1. Don't build cryptography — integrate vendor MPC/TEE; session keys, never master keys.
  2. Build the layer above the wallets; cross-vendor aggregation is the product.
  3. Fail-closed: no decision / no backend response ⇒ the transaction does not execute.
  4. Backend-agnostic core; no vendor logic leaks past the EnforcementProvider interface.
  5. Append-only, hash-chained ledger is the source of truth.
  6. Testnet only — mainnet follows a third-party security audit.

Links

Apache-2.0. Countersign holds policy, freeze, and a tamper-evident ledger — it never takes custody of funds.

Reviews

No reviews yet

Be the first to review this server!