Security

Token, audit, and privacy boundaries

Bearer tokens are paid access credentials; logs avoid full tokens and raw sensitive request bodies.

Endpoint

https://mcptoollicense.clauxel.com/mcp

Authentication

Production calls require a paid bearer token. The checkout and token-claim endpoints return machine-readable instructions for agents.

Available tools

  • check_tool_license returns structured JSON with verdict, reason, receipt_id, usage_units, and next_action.
  • validate_vendor_policy returns structured JSON with verdict, reason, receipt_id, usage_units, and next_action.
  • issue_license_receipt returns structured JSON with verdict, reason, receipt_id, usage_units, and next_action.
  • suggest_allowed_alternative returns structured JSON with verdict, reason, receipt_id, usage_units, and next_action.
  • export_license_audit returns structured JSON with verdict, reason, receipt_id, usage_units, and next_action.

Example call

{"jsonrpc":"2.0","id":"call-1","method":"tools/call","params":{"name":"check_tool_license","arguments":{"sample":"{\"tool\":\"web-scraper-pro\",\"vendor\":\"https://vendor.example\",\"license\":\"enterprise internal only\",\"use\":\"client reporting automation\"}"}}}

Setup pages