Skip to main content
ClaudeWave
MCP ServersOfficial Registry0 stars0 forksTypeScriptApache-2.0Updated today
ClaudeWave Trust Score
77/100
Trusted
Passed
  • Open-source license (Apache-2.0)
  • Actively maintained (<30d)
  • Documented (README)
Flags
  • !No description
Last scanned: 8/26/2026
Install in Claude Code / Claude Desktop
Method: NPX · tsc
Claude Code CLI
claude mcp add cedulon -- npx -y tsc
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "cedulon": {
      "command": "npx",
      "args": ["-y", "tsc"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

# Cedulon

Audit layer for agent-to-agent spend: signed trade manifest, fail-closed
policy, signed spend receipt (SCITT-anchorable).

Cedulon is **not** a payment rail. It sits above x402 and AP2.

The packages are on npm and the MCP server is in the MCP Registry, but nothing
here touches money: no real wallets and no network rails, only mock fixtures.
`cedulon_spend` settles on a mock rail and says so in its own description.

Core packages carry zero runtime dependencies; the MCP server package
depends only on the official MCP SDK.

## Requirements

- Node.js 22 or newer (20+ for the libraries; scripts use Node type stripping)
- npm 10 or newer

## Install and run (clean clone)

```bash
npm install
npx tsc --noEmit
npm run test:all
npm run demo
```

`npm run tamper` is expected to exit non-zero (tampered bytes fail verify).

`npm run demo:unguarded` shows the unprotected hole: 100/100 allows.

`npm run audit` must exit 0 (`audit: balanced`).

`npm run demo:bypass` must exit non-zero:
`audit: 1 settlement without receipt → FAIL`.

`npm run demo:bypasses` prints four FAIL lines (missing receipt, wrong
amount, null-ref, garbage chain head) and exits 0 only when every bypass
is caught; a missed bypass makes it exit non-zero.

`npm run demo:live` reconciles a real Base Sepolia USDC window instead of a
fixture. Read-only: it needs an RPC URL in `CEDULON_RPC_URL` and no wallet,
key, or transaction. Against an account whose receipts you do not hold, every
settlement the chain reports comes back as a gap.

A third party can reproduce this without trusting us:
`docs/RUN_AS_VERIFIER.md`.

Five-minute path, including the MCP host config: `docs/QUICKSTART.md`.

## MCP server

Cedulon can run as a local stdio MCP server. The host talks JSON-RPC on
stdin/stdout. The five tools are thin wrappers over the existing
packages; they do not reimplement policy, receipts, or audit.

| Tool | Arguments | Result |
| --- | --- | --- |
| `cedulon_spend` | `amount` (string), `currency`, `payee`, `nonce`, optional `tool` | Allow → signed receipt JSON. Deny → `{ ok: false, reason }` (for example `limit-amount`). |
| `cedulon_audit` | optional `extraSettlements[]` (`ref`, `amount`, `currency`, `timestampMs`) | `{ ok, summary, findings }`. Balanced books print `audit: balanced`. |
| `cedulon_verify_receipt` | `receipt` object, or `coseHex` + `publicKeyPem`, optional countersignature fields | `{ ok, receipt, countersignature }` |
| `cedulon_export_ledger` | none | Receipts + checkpoint + extract in the `demo:export` JSON shape |
| `cedulon_status` | none | `{ version, policy, receiptCount, chainHead }` |

Claude Desktop / Claude Code / Cursor. Nothing to clone and nothing to build:

```json
{
  "mcpServers": {
    "cedulon": {
      "command": "npx",
      "args": ["-y", "@cedulon/mcp-server"]
    }
  }
}
```

In Claude Code that config is one command:

```bash
claude mcp add cedulon -- npx -y @cedulon/mcp-server
```

Policy limits come from the environment: `CEDULON_MAX_AMOUNT`,
`CEDULON_MAX_CUMULATIVE`, `CEDULON_MAX_PAYMENTS`, `CEDULON_WINDOW_MS`,
`CEDULON_ALLOWED_PAYEES`, `CEDULON_ALLOWED_CURRENCIES`,
`CEDULON_ALLOWED_TOOLS`, `CEDULON_PAYER`. Set `CEDULON_STATE_PATH` to keep the
receipt chain across restarts; without it the ledger lives in memory.

Working inside this repository instead, against the sources:

```bash
npm run mcp
```

The server is listed in the MCP Registry as
`io.github.dogrucanemek-alt/cedulon`; `server.json` is the entry it is published
from. `smithery.yaml` is prepared but not submitted.


## Layout

```
packages/core           policy engine + Decision Token (workspace dep on @cedulon/cose)
packages/cose           deterministic CBOR + COSE_Sign1 (Ed25519)
packages/manifest       signed trade manifest
packages/receipts       spend receipt (COSE default, JSON legacy)
packages/checkpoint     epoch checkpoints + in-process transparency log
packages/audit          rail-extract completeness checker
packages/mcp-guard      MCP tools/call wrapper (mock)
packages/mcp-server     stdio MCP server (official SDK)
packages/x402-adapter   HTTP 402 adapter + mock rail extract
packages/base-extract   read-only Base Sepolia USDC → RailExtract
examples/demo           runaway, dispute, bypass, audit CLI
spec/                   draft-dogru-cedulon-01 (current), -00, plus the
                        reattestation and streaming drafts
THREAT_MODEL.md
docs/RUN_AS_VERIFIER.md
```

Brand names come from `packages/core/src/brand.ts` only.

## How to cite

Citation metadata is in `CITATION.cff`. The archived -00 release is
published as https://doi.org/10.5281/zenodo.22099792

## License

Apache-2.0

What people ask about cedulon

What is dogrucanemek-alt/cedulon?

+

dogrucanemek-alt/cedulon is mcp servers for the Claude AI ecosystem with 0 GitHub stars.

How do I install cedulon?

+

You can install cedulon by cloning the repository (https://github.com/dogrucanemek-alt/cedulon) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is dogrucanemek-alt/cedulon safe to use?

+

Our security agent has analyzed dogrucanemek-alt/cedulon and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains dogrucanemek-alt/cedulon?

+

dogrucanemek-alt/cedulon is maintained by dogrucanemek-alt. The last recorded GitHub activity is dated 2026-08-26, with 1 open issues.

Are there alternatives to cedulon?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy cedulon to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: dogrucanemek-alt/cedulon
[![Featured on ClaudeWave](https://claudewave.com/api/badge/dogrucanemek-alt-cedulon)](https://claudewave.com/repo/dogrucanemek-alt-cedulon)
<a href="https://claudewave.com/repo/dogrucanemek-alt-cedulon"><img src="https://claudewave.com/api/badge/dogrucanemek-alt-cedulon" alt="Featured on ClaudeWave: dogrucanemek-alt/cedulon" width="320" height="64" /></a>

More MCP Servers

cedulon alternatives