Back to Browse

Causallayer MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Deterministic AI-liability attribution: signed, Bitcoin-anchored vendor/deployer/user fault split.

About

Deterministic AI-liability attribution: signed, Bitcoin-anchored vendor/deployer/user fault split.

Remote endpoints: streamable-http: https://causallayer-mcp-demo.zykm9qkk7j.workers.dev/mcp

Security Report

4.2
Use Caution4.2High Risk

The CausalLayer MCP server implements a billing-protected API for deterministic AI liability attribution with appropriate guardrails (PII scanning, deterministic-only acknowledgement, evidence requirements). Authentication and authorization are properly scoped for different billing modes. However, there are several code quality and security concerns: incomplete error handling in the Stripe webhook verification, a potential timing-based side-channel vulnerability in the HMAC constant-time comparison, insufficient input validation on critical API calls, and risky patterns in secret handling. These issues do not constitute immediate compromise but should be addressed before production deployment. Supply chain analysis found 2 known vulnerabilities in dependencies (2 critical, 0 high severity).

5 files analyzed ยท 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

kv_read

Check that this permission is expected for this type of plugin.

kv_write

Check that this permission is expected for this type of plugin.

durable_objects

Check that this permission is expected for this type of plugin.

crypto_sign

Check that this permission is expected for this type of plugin.

crypto_hash

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

FaultKey ยท CausalLayer MCP Server

CI CodeQL OpenSSF Scorecard License npm version Cloudflare Workers Model Context Protocol Live Demo GitHub Stars TypeScript OpenAPI security: ed25519 anchored: Bitcoin

Deterministic fault math for multi-party AI incidents. When an AI causes harm and three parties argue over who pays, FaultKey returns a signed, Bitcoin-anchored certificate of fault allocation in under 200 ms โ€” no LLM, no probabilistic scoring, no vendor cooperation needed for a third party to verify.

This is the official Model Context Protocol (MCP) server for the CausalLayer engine, packaged as a Cloudflare Worker. It lets AI agents (Claude Desktop, Cursor, Cline, Continue, Windsurf) call the four core liability-attribution tools without writing a single line of integration code.

If this saves you time, give it a star โ€” it helps others find it and tells us people care.

Live demo

๐ŸŽฎ Try the Interactive Demo โ€” No setup required. Pick a scenario, click "Run Analysis", see real-time liability attribution.

The public Worker is deployed on Cloudflare's global edge network and is fully functional in standalone demo mode (deterministic responses, watermarked, rate-limited 5 calls / IP / day):

  • Endpoint: https://mcp.faultkey.com/mcp (live, custom domain)
  • Mirror: https://causallayer-mcp-demo.zykm9qkk7j.workers.dev/mcp
  • Healthcheck: /healthz
  • Demand telemetry: /stats (public, aggregated, no PII)

Quick start

Claude Desktop

Add this to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "faultkey": {
      "command": "npx",
      "args": ["-y", "causallayer-mcp"]
    }
  }
}

Restart Claude. Type "List the FaultKey tools."

Cursor

Settings โ†’ MCP Servers โ†’ Add new:

  • Name: faultkey
  • Command: npx -y causallayer-mcp

Cline / Continue / Windsurf

{
  "name": "faultkey",
  "command": "npx",
  "args": ["-y", "causallayer-mcp"]
}

Direct HTTP (no CLI)

curl -X POST https://causallayer-mcp-demo.zykm9qkk7j.workers.dev/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":0,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0"}}}'

The response includes a Mcp-Session-Id header that you reuse for subsequent calls.

Tools

ToolDescriptionDemo limitPaid cost
submit_incidentSubmit an AI incident for deterministic liability attribution. Returns a signed CausalCertificateV1 with per-agent fault allocation, evidence-chain completeness, and Bitcoin-anchored proof.5 / IP / day50 credits
verify_certificateIndependently verify a certificate (signature, Merkle integrity, issuer status) without calling FaultKey.50 / IP / day1 credit
get_anchor_statusReturn the index of all Tessera anchor batches or one batch's full JSON (signed Merkle root, OpenTimestamps proof reference).UnlimitedFree
query_issuer_registryList all trusted CausalLayer issuer public-key fingerprints, status, and validity windows.UnlimitedFree

Why deterministic?

Insurers, banks, and APRA-regulated entities cannot accept LLM-based fault attribution because the same prompt produces different answers on different days. FaultKey uses a closed-form causal scoring algorithm (graph-theoretic, version-pinned, byte-identical reproducible across runs) so two adversarial parties get the same number โ€” that's the whole point.

The math is published as an Australian Standards-aligned paper. The signed certificate, issuer registry, and Merkle anchor log are all independently verifiable by a third party using only Node's built-in crypto and the causallayer-verifier tool โ€” no network calls back to the vendor.

Guardrails (enforced at the Cloudflare edge)

  1. NO-PII โ€” Payloads are regex-scanned for emails, Tax File Numbers, Medicare numbers, SSNs, and credit cards. Rejected unless the caller sets pii_acknowledged: true (which is logged in the certificate as a compliance acknowledgement).
  2. DETERMINISTIC-ONLY โ€” The engine rejects any request lacking deterministic_only: true. This is the agent's binding acknowledgement that FaultKey output is closed-form, not probabilistic.
  3. EVIDENCE-REQ โ€” At least one identified agent and one timestamped event with description must be supplied or the request is rejected with 400 evidence_insufficient.

Self-hosting

You can deploy your own copy to your own Cloudflare account if you want to enforce a corporate firewall, custom rate limits, or bring your own KV namespace:

git clone https://github.com/smq9sn5jck-coder/causallayer-mcp.git
cd causallayer-mcp
pnpm install
pnpm wrangler kv namespace create LEDGER
# paste the returned id into wrangler.jsonc
pnpm wrangler deploy

The CausalLayer engine itself (the closed-form fault math) runs upstream and is available via API key. For self-hosted demos without an upstream, set STANDALONE_DEMO=true in wrangler.jsonc to short-circuit upstream calls and return deterministic, watermarked responses.

Architecture

[Claude/Cursor/Cline]  โ†โ†’  [npx causallayer-mcp]  โ†โ†’  [Cloudflare Worker]  โ†โ†’  [CausalLayer engine]
                              (mcp-remote proxy)         (this repo)            (Fly.io Sydney)
                                                              โ†“
                                                    [KV: credit ledger]
                                                    [DO: per-session state]
                                                    [KV: telemetry buffer]
  • Transport: Streamable HTTP (per the 2024-11-05 MCP spec โ€” SSE is deprecated)
  • Session state: Cloudflare Durable Object (CausalLayerMCP), SQLite-backed
  • Billing: Cloudflare KV ledger, Stripe Checkout webhook, optional x402 USDC fallback
  • Demo: Per-IP daily counter in KV, deterministic fixture responses with [DEMO] watermark
  • Latency: p50 โ‰ˆ 60 ms (cold), 25 ms (warm) on Cloudflare's 300+ POPs

Pricing

TierCredits$AUDNotes
Demo5 incidents / IP / dayFreeWatermarked responses
Starter1,000$99Stripe Checkout, no SLA
Growth10,000$749+ 50 verify, 99.5% SLA
EnterpriseUnmeteredContact+ dedicated namespace, 99.95% SLA, audit log access

For enterprise tenants email sales@faultkey.com (or open a GitHub issue with subject "enterprise inquiry").

Interactive Tools

Score any AI incident in seconds โ€” faultkey.com/score โ€” describe what happened, get a deterministic liability split with dollar exposure, jurisdiction analysis, and a shareable verdict card.

Compare vendor liability profiles โ€” faultkey.com/compare โ€” side-by-side comparison of AI vendors (OpenAI vs Anthropic vs Google etc.) across incident types.

Public accuracy ledger โ€” faultkey.com/track-record โ€” 7/7 direction match on backtested cases, 3 pending predictions on active litigation.

License

Apache 2.0. See LICENSE.

Support the Project

If FaultKey helped you understand AI liability, saved you research time, or you just think deterministic fault attribution should exist:

Built in Brisbane

FaultKey is built in Brisbane, Australia, with data residency in Sydney for APRA-regulated buyers. The team can be reached at hello@faultkey.com.

Reviews

No reviews yet

Be the first to review this server!

Causallayer MCP Server - Deterministic AI-liability attribution: signed, | MCP Marketplace