Baton is answering right now. Last checked 1 min ago. 40 installs a week from npm. It exposes 45 tools. Last commit 14 Jul 2026.
Hand off AI work with a signed Verification Receipt — an independent verifier proves it runs.
We read the source, 19 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
…err').textContent='';let[m,h,a]=await Promise.all([api('/memory/search'),api('/hub/list'),api('/agent/list')]);$('mem').innerHTML=m.memories.map(x=>`<div class=item><b>${esc(x.title)}</b><div class=m>${esc(x.tags.join(', '))}</div></div>`).join('')||'<p class=m>저장된 기억…
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 1 min ago.
claude mcp add baton --transport http https://baton-mcp-production.up.railway.app/mcp
{
"mcpServers": {
"baton": {
"url": "https://baton-mcp-production.up.railway.app/mcp"
}
}
}
[mcp_servers.baton]
url = "https://baton-mcp-production.up.railway.app/mcp"
{
"mcpServers": {
"baton": {
"url": "https://baton-mcp-production.up.railway.app/mcp"
}
}
}
{
"mcpServers": {
"baton": {
"url": "https://baton-mcp-production.up.railway.app/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
baton_account
baton_agent_list
baton_agent_record_result
baton_agent_register
baton_approve
baton_close_room
baton_confirm_payment
baton_consolidate
baton_cost_record
baton_cost_summary
baton_create_room
baton_diff
baton_git_evidence
baton_git_record
baton_hub_list
baton_hub_observe
baton_hub_register
baton_inbox
baton_join
baton_kick
baton_leave
baton_memory_delete
baton_memory_get
baton_memory_put
baton_memory_search
baton_new_invite
baton_pass
baton_receive
baton_revoke
baton_send
baton_signup
baton_task_create
baton_task_graph
baton_task_link
baton_task_update
baton_upgrade
baton_verify
baton_verify_plan
baton_who
spider_checklist
spider_classify_tier
spider_plan
spider_pull_corpus
spider_record_pattern
spider_signals
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://baton-mcp-production.up.railway.app/mcp | streamable-http | answering | 279 ms | 1 min ago |
Independent effect verification and signed receipts for consequential AI agent actions.
Signed time and SHA-256 witness receipts for agents, with offline verification and x402 payment.
Offline receipt verifier. Ed25519 signature verification without contacting any server.
Offline Ed25519 verification of signed receipts, bundles, and trust artifacts.
Offline Ed25519 verification of signed receipts, bundles, and trust artifacts.
Agent leases, signed receipts, watchdogs, and optional paid source-verification evidence.
Governed AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.
Finds and verifies work emails on your own provider keys, with real per-provider spend.
Answers built from our own checks of this server.