{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-28T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/agent-custody",
  "type": "tool",
  "slug": "agent-custody",
  "canonical_url": "https://gtmstacker.com/registry/tool/agent-custody/",
  "title": "agent-custody",
  "description": "agent-custody is a chain-of-custody layer for AI agents: signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with adapters for LangChain, OpenAI Agents SDK, and Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. Active (~217 commits, 0.6.x).",
  "category": "mcp-agents",
  "tags": [
    "mcp-agents",
    "agent-governance",
    "audit-log",
    "chain-of-custody",
    "cedar-policy",
    "self-hostable"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "2a10b387adce415d8ec1c615377bb93c31ecbce722b6fbd004911a52e845762c",
  "date_published": "2026-09-28T00:00:00Z",
  "date_modified": "2026-09-28T00:00:00Z",
  "source": {
    "name": "ch4r10t33r · GitHub",
    "url": "https://github.com/ch4r10t33r/agent-custody"
  },
  "license": "Apache-2.0",
  "one_liner": "agent-custody gives AI agents signed receipts per tool call, a Cedar-policy MCP gateway, and a Merkle tamper-evident log with offline and browser verifiers.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_signal": "self-hostable free; hosted log free to 10k appends/mo, then $50/mo for 1M",
  "pricing_model": "freemium",
  "who_its_for": "A team that must PROVE what its agents did — signed, tamper-evident receipts for every tool call, gated by Cedar policy at an MCP boundary and verifiable offline or in a browser — using SDK adapters for LangChain, the OpenAI Agents SDK, or the Claude Agent SDK, self-hosted via container/compose/k8s.",
  "who_its_not_for": "A low-stakes or hobby agent with no audit or compliance requirement, or a team unwilling to run a gateway and transparency log.",
  "aliases": [
    "agent-custody",
    "agent custody",
    "ch4r10t33r/agent-custody"
  ],
  "alternatives": [
    "provenance-gate",
    "chimera",
    "agent-governance-toolkit"
  ],
  "secondary_categories": [
    "ai-infrastructure"
  ],
  "last_verified": "2026-09-28",
  "evidence": {
    "claim_type": "vendor-claim",
    "source_id": "https://github.com/ch4r10t33r/agent-custody",
    "note": "Apache-2.0 per repo; 5 stars; active (~217 commits, 0.6.x). Provides signed receipts per tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers; SDK adapters for LangChain, OpenAI Agents SDK and Claude Agent SDK; self-hostable via container + docker-compose + k8s manifests. Freemium: hosted log free to 10k appends/mo, $50/mo for 1M. No standalone benchmarks (github.com/ch4r10t33r/agent-custody, verified 2026-09-28)."
  },
  "caveats": "Verified from the primary repo (2026-09-28); no independent testing here, and no standalone benchmarks published. Tamper-evidence rests on the Merkle transparency log and signing scheme as designed — not independently audited here. At 5 stars it is early despite active development; the hosted transparency log is a paid tier ($50/mo for 1M appends) above the 10k/mo free allowance, though the layer is self-hostable.",
  "lead": "agent-custody is a chain-of-custody layer for AI agents providing signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. It is active…",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 98,
      "text": "agent-custody is a chain-of-custody layer for AI agents providing signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. It is active (~217 commits) at the 0.6.x series."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "What it does"
      ],
      "est_tokens": 242,
      "text": "AI agents providing signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. It is active (~217 commits) at the 0.6.x series.\n\nagent-custody builds a provable record of what an agent did. Every tool call gets a signed receipt; those receipts land in a Merkle-structured transparency log whose tamper-evidence anyone can check with the offline or browser verifiers; and a Cedar-policy MCP gateway sits at the boundary to authorize (or deny) each call against declarative policy before it runs. It plugs into existing agents through SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK, and you self-host it with a container plus docker-compose or Kubernetes manifests. Open source: yes (Apache-2.0); self-hostable; freemium."
    },
    {
      "index": 2,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 276,
      "text": "boundary to authorize (or deny) each call against declarative policy before it runs. It plugs into existing agents through SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK, and you self-host it with a container plus docker-compose or Kubernetes manifests. Open source: yes (Apache-2.0); self-hostable; freemium.\n\n- Apache-2.0 per repo; 5 stars; active (~217 commits, 0.6.x). Signed receipts per tool call; Cedar-policy MCP gateway; Merkle tamper-evident transparency log; offline + browser verifiers; SDK adapters for LangChain, OpenAI Agents SDK, Claude Agent SDK; self-hostable via container + docker-compose + k8s (github.com/ch4r10t33r/agent-custody, verified 2026-09-28).\n- Freemium: the layer is self-hostable and free; the hosted transparency log is free to 10k appends/month, then $50/month for 1M appends.\n- No standalone benchmarks published; the tamper-evidence rests on the documented Merkle log and signing design, not on an independent audit here.\n- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28."
    },
    {
      "index": 3,
      "heading_path": [
        null,
        "Why it matters for a GTM stack"
      ],
      "est_tokens": 321,
      "text": "the hosted transparency log is free to 10k appends/month, then $50/month for 1M appends. - No standalone benchmarks published; the tamper-evidence rests on the documented Merkle log and signing design, not on an independent audit here. - Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.\n\nOnce agents send outreach, edit the CRM, or move money, the question auditors and customers ask is \"prove what your agent did, and prove nobody tampered with the record.\" agent-custody answers exactly that: signed per-call receipts, a Cedar-policy gate deciding what is even allowed at the MCP boundary, and a Merkle transparency log that anyone can verify — including offline or in a browser — with drop-in adapters for the SDKs GTM agents are actually built on. Open source: yes (Apache-2.0); self-hostable; freemium. The honest read: the primitives (policy gate + signed receipts + tamper-evident log + independent verifiers) are the right control surface for accountable agent actions, but at 5 stars it is early, there are no published benchmarks, and the tamper-evidence is a documented design rather than an audited guarantee — pilot the gateway and verifier on a low-stakes action flow before relying on it for compliance."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/agent-custody/index.md",
    "html": "https://gtmstacker.com/registry/tool/agent-custody/",
    "json": "https://gtmstacker.com/registry/tool/agent-custody/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/agent-custody/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/agent-custody/#software",
        "name": "agent-custody",
        "identifier": "ch4r10t33r/agent-custody",
        "description": "agent-custody is a chain-of-custody layer for AI agents: signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with adapters for LangChain, OpenAI Agents SDK, and Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. Active (~217 commits, 0.6.x).",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/agent-custody/",
        "datePublished": "2026-09-28T00:00:00Z",
        "dateModified": "2026-09-28T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "license": "https://spdx.org/licenses/Apache-2.0.html",
        "codeRepository": "https://github.com/ch4r10t33r/agent-custody",
        "keywords": "mcp-agents, ai-infrastructure, agent-governance, audit-log, chain-of-custody, cedar-policy, self-hostable",
        "author": {
          "@type": "Organization",
          "name": "ch4r10t33r",
          "url": "https://github.com/ch4r10t33r",
          "sameAs": [
            "https://github.com/ch4r10t33r/agent-custody"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "Provenance Gate",
            "url": "https://gtmstacker.com/registry/tool/provenance-gate/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Chimera",
            "url": "https://gtmstacker.com/registry/tool/chimera/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Agent Governance Toolkit",
            "url": "https://gtmstacker.com/registry/tool/agent-governance-toolkit/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/agent-custody/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "MCP Agents",
            "item": "https://gtmstacker.com/registry/category/mcp-agents/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "agent-custody",
            "item": "https://gtmstacker.com/registry/tool/agent-custody/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "ch4r10t33r/agent-custody",
    "repository": {
      "url": "https://github.com/ch4r10t33r/agent-custody",
      "source": "github"
    }
  }
}
