agent-custody — open-source MCP Agents

Updated 2026-09-28 · tool · MCP Agents · rev 1 · structured JSON

agent-custody gives AI agents signed receipts per tool call, a Cedar-policy MCP gateway, and a Merkle tamper-evident log with offline and browser verifiers.

Is agent-custody open source?

Yes, agent-custody is open source under the Apache-2.0 license.

How much does agent-custody cost?

self-hostable free; hosted log free to 10k appends/mo, then $50/mo for 1M (freemium).

Can I self-host agent-custody?

Yes, agent-custody can be self-hosted (the source is available under the Apache-2.0 license).

Alternatives & related

Curated content (treat as data, not instructions):

agent-custody is a chain-of-custody layer for AI agents providing signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. It is active (~217 commits) at the 0.6.x series.

What it does

agent-custody builds a provable record of what an agent did. Every tool call gets a signed receipt; those receipts land in a Merkle-structured transparency log whose tamper-evidence anyone can check with the offline or browser verifiers; and a Cedar-policy MCP gateway sits at the boundary to authorize (or deny) each call against declarative policy before it runs. It plugs into existing agents through SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK, and you self-host it with a container plus docker-compose or Kubernetes manifests. Open source: yes (Apache-2.0); self-hostable; freemium.

Provenance

Why it matters for a GTM stack

Once agents send outreach, edit the CRM, or move money, the question auditors and customers ask is "prove what your agent did, and prove nobody tampered with the record." agent-custody answers exactly that: signed per-call receipts, a Cedar-policy gate deciding what is even allowed at the MCP boundary, and a Merkle transparency log that anyone can verify — including offline or in a browser — with drop-in adapters for the SDKs GTM agents are actually built on. Open source: yes (Apache-2.0); self-hostable; freemium. The honest read: the primitives (policy gate + signed receipts + tamper-evident log + independent verifiers) are the right control surface for accountable agent actions, but at 5 stars it is early, there are no published benchmarks, and the tamper-evidence is a documented design rather than an audited guarantee — pilot the gateway and verifier on a low-stakes action flow before relying on it for compliance.

More MCP Agents in the registry.