Warrant runs on your own machine — the client starts it, so there is no endpoint to ping. 170 installs a week from pypi. Last commit 18 Sep 2026.
Record an agent's decisions with reasons anyone can re-execute offline — verify recomputes them.
We read the source, 22 h ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
const content = fs.readFileSync(filePath, 'utf8');
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
for local in sorted((HERE / 'evidence/holder').rglob('*.json')):
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
этот файл ставится пользователю, но в репозитории его нет
proc = subprocess.run(argv, input=payload, stdout=subprocess.PIPE,
"canon_hex": "7b226163746f72223a7b226964223a226167656e742d784076656e646f72227d2c2262656361757365223a5b5d2c226465636973696f6e223a2270726f706f7365222c2265766964656e6365223a5b5d2c227072696f72223a5b5d2c227375626a656374223a7b2268617368223a22616161616161616161616161616161616161…
env = dict(os.environ)
for local in sorted((HERE / 'evidence/holder').rglob('*.json')):
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add warrant -- uvx warrant-verify
{
"mcpServers": {
"warrant": {
"args": [
"warrant-verify"
],
"command": "uvx"
}
}
}
[mcp_servers.warrant]
command = "uvx"
args = ["warrant-verify"]
{
"mcpServers": {
"warrant": {
"args": [
"warrant-verify"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"warrant": {
"args": [
"warrant-verify"
],
"command": "uvx"
}
}
}
This one needs environment variables set before it will start:
WARRANT_STORE (Absolute path to the warrant store this server files into and verifies. Defaults to .warrants relative to the server process's working directory, which an MCP host does not guarantee.), WARRANT_KEY (Ed25519 signing key. If unset, one is generated next to the store on the first filing and the result says so; any process that can read it can sign as this actor.), WARRANT_ACTOR (Actor id written into filed warrants. Defaults to mcp-client@<hostname>.).
The author declared them in the registry entry; get the values from the project itself.
Tamper-evident records of AI agent decisions. Verify offline, or publish a proof link.
A local causality ledger: records decisions and the reasons, for an agent to recall.
Verify agent actions against the system of record and get signed completion receipts.
Attest agent decisions and verify records on a public ledger. Evidence, not just data.
Execution-verified code generation and verification with signed, offline-checkable certificates.
Verifiable agent memory with signed ledger receipts — verify every write offline.
Scope changes against a work order, each with a reason, a date and the client's approval on record.
Issue signed receipts for AI agent actions; verify any receipt offline - free, no account.
Answers built from our own checks of this server.