# agent-custody

> Updated 2026-09-28 · type: tool · category: mcp-agents · status: active · rev 1

agent-custody gives AI agents signed receipts per tool call, a Cedar-policy MCP gateway, and a Merkle tamper-evident log with offline and browser verifiers.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing: self-hostable free; hosted log free to 10k appends/mo, then $50/mo for 1M
- Best for: A team that must PROVE what its agents did — signed, tamper-evident receipts for every tool call, gated by Cedar policy at an MCP boundary and verifiable offline or in a browser — using SDK adapters for LangChain, the OpenAI Agents SDK, or the Claude Agent SDK, self-hosted via container/compose/k8s.
- Not for: A low-stakes or hobby agent with no audit or compliance requirement, or a team unwilling to run a gateway and transparency log.
- Last verified: 2026-09-28

- **Canonical:** https://gtmstacker.com/registry/tool/agent-custody/
- **Source:** [ch4r10t33r · GitHub](https://github.com/ch4r10t33r/agent-custody)
- **Tags:** mcp-agents, agent-governance, audit-log, chain-of-custody, cedar-policy, self-hostable
- **Repository:** https://github.com/ch4r10t33r/agent-custody

## Is agent-custody open source?

Yes, agent-custody is open source under the Apache-2.0 license.

## How much does agent-custody cost?

self-hostable free; hosted log free to 10k appends/mo, then $50/mo for 1M (freemium).

## Can I self-host agent-custody?

Yes, agent-custody can be self-hosted (the source is available under the Apache-2.0 license).

## Alternatives & related

- [Provenance Gate](https://gtmstacker.com/registry/tool/provenance-gate/)
- [Chimera](https://gtmstacker.com/registry/tool/chimera/)
- [Agent Governance Toolkit](https://gtmstacker.com/registry/tool/agent-governance-toolkit/)


---

agent-custody is a chain-of-custody layer for AI agents providing signed receipts for every tool call, a Cedar-policy MCP gateway, a Merkle tamper-evident transparency log, and offline/browser verifiers, with SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK. Open source: yes (Apache-2.0); self-hostable; freemium. It is active (~217 commits) at the 0.6.x series.

## What it does

agent-custody builds a provable record of what an agent did. Every tool call gets a signed receipt; those receipts land in a Merkle-structured transparency log whose tamper-evidence anyone can check with the offline or browser verifiers; and a Cedar-policy MCP gateway sits at the boundary to authorize (or deny) each call against declarative policy before it runs. It plugs into existing agents through SDK adapters for LangChain, the OpenAI Agents SDK, and the Claude Agent SDK, and you self-host it with a container plus docker-compose or Kubernetes manifests. Open source: yes (Apache-2.0); self-hostable; freemium.

## Provenance

- Apache-2.0 per repo; 5 stars; active (~217 commits, 0.6.x). Signed receipts per tool call; Cedar-policy MCP gateway; Merkle tamper-evident transparency log; offline + browser verifiers; SDK adapters for LangChain, OpenAI Agents SDK, Claude Agent SDK; self-hostable via container + docker-compose + k8s (github.com/ch4r10t33r/agent-custody, verified 2026-09-28).
- Freemium: the layer is self-hostable and free; the hosted transparency log is free to 10k appends/month, then $50/month for 1M appends.
- No standalone benchmarks published; the tamper-evidence rests on the documented Merkle log and signing design, not on an independent audit here.
- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.

## Why it matters for a GTM stack

Once agents send outreach, edit the CRM, or move money, the question auditors and customers ask is "prove what your agent did, and prove nobody tampered with the record." agent-custody answers exactly that: signed per-call receipts, a Cedar-policy gate deciding what is even allowed at the MCP boundary, and a Merkle transparency log that anyone can verify — including offline or in a browser — with drop-in adapters for the SDKs GTM agents are actually built on. Open source: yes (Apache-2.0); self-hostable; freemium. The honest read: the primitives (policy gate + signed receipts + tamper-evident log + independent verifiers) are the right control surface for accountable agent actions, but at 5 stars it is early, there are no published benchmarks, and the tamper-evidence is a documented design rather than an audited guarantee — pilot the gateway and verifier on a low-stakes action flow before relying on it for compliance.
