Skip to main content

safeact-mcp

Make any MCP tool exactly-once and auditable — one decorator.

Your MCP tools do real things: charge a card, send an email, book a slot. When the agent crashes and retries — and agents crash and retry a lot — a naive tool fires the action twice. And there's no record of what actually happened, so you can't prove it or check it.

safeact-mcp fixes both, in one line on top of the MCP SDK.

pip install safeact-mcp

Quickstart

from mcp.server.mcpserver import MCPServer
from safeact_mcp import safe_tool

server = MCPServer("payments")

@server.tool()
@safe_tool(store="agent.db")
def charge_card(idempotency_key: str, customer: str, amount: int) -> dict:
    stripe.charge(customer, amount)          # the real, irreversible action
    return {"charged": amount}

That's it. Now charge_card:

  • Runs at most once per idempotency key — even across crashes and retries.
  • Records every attempt to a durable store — that's your audit trail.
  • Refuses to guess. If the process dies after the charge but before it's recorded, the key is marked IN_DOUBT and the next call raises InDoubtError instead of blindly charging again. (An honest "we don't know, go check" beats a silent double-charge.)

Reading the audit trail

from safeact_mcp import audit_record, in_doubt

audit_record("agent.db", "order-42")   # the durable record for one call
in_doubt("agent.db")                   # keys stuck in the gap — your review queue

The one honest limitation

MCP has no crash-safe idempotency key of its own. So the caller supplies one via the idempotency_key argument — pass a stable value (e.g. your agent's tool-call id) so retries deduplicate. No key → you still get the audit trail, but not the exactly-once guarantee. We're upfront about that.

How it works

safeact-mcp is a thin adapter over safeact, the correctness core (exactly-once · honest in-doubt · saga compensation), mutation-tested. safe_tool composes under MCPServer.tool() and preserves your tool's signature, so the MCP server still generates the correct input schema.

See examples/payments_server.py for a complete, runnable server.

License

Apache-2.0. Part of SafeAct — the trust layer for AI agents.

Metadata

Release files for safeact-mcp 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for safeact-mcp 0.0.1
File Size Uploaded
safeact_mcp-0.0.1.tar.gz 13.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for safeact-mcp 0.0.1
File Interpreter ABI Platform
safeact_mcp-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 26.2 kB

Release files / safeact_mcp-0.0.1.tar.gz

Download URL safeact_mcp-0.0.1.tar.gz
Size 13.0 kB
Tags Source
SHA-256 checksum
How to use checksums
33c4d6cbce63836575e50de63f800fad60029efa6d7f07cca143f9c7a8c899ea
BLAKE2b-256 checksum
How to use checksums
e35f5f75ef486dbbc440840bcaaed5a48ba73b5e45667703eae7abdb133f5e68
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / safeact_mcp-0.0.1-py3-none-any.whl

Download URL safeact_mcp-0.0.1-py3-none-any.whl
Size 13.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fb7e6d5d07ae6d01931c19f1816f14236124157f30cc55cf43dfac7a6caf2890
BLAKE2b-256 checksum
How to use checksums
af059e201ef76f88532b0967346cd2e2ad2d4ec2dda5d5027d1351e2bfd4b11e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page