Skip to main content
Model Context Protocol servers, from the client side.
That is the whole integration. From here every call the client makes is recorded on the open trajectory.

What is distinctive

Records a manifest digest of the server’s tools on every session. A server that gains a tool between sessions is drift the platform can see, which is the supply-chain question MCP otherwise leaves open. For governing an MCP server without touching the agent, use the proxy instead.

In context

The witness block opens the trajectory and closes it on exit, including when the body raises — an episode that ended badly is exactly the one worth having a record of.

Recording without content

Shape and metadata only: model, latency, token counts, tool names. No prompt or response text. The governed facts are unchanged.
Authority is never asked for by an adapter. It stays an explicit trajectory.authorize(...) call, so importing a middleware can never become a spend decision. See authorise an action.