FaultKey CausalLayer
About
Deterministic AI-liability attribution — signed, Bitcoin-anchored certificates that compute vendor/deployer/user fault splits for AI incidents. No LLMs, byte-identical reproducible.
Details
- Transport
- SSE
Explore
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
FaultKey CausalLayerCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"faultkey causallayer": {
"server": {
"command": "npx",
"args": [
"-y",
"causallayer-mcp"
]
}
}
}
}
McpServers
{
"server": {
"command": "npx",
"args": [
"-y",
"causallayer-mcp"
]
}
}
Transport
"stdio"
Package
"causallayer-mcp"
Registry
"npm"
Deterministic fault math for multi-party AI incidents.When an AI causes harm and three parties argue over who pays, FaultKey returns a signed, Bitcoin-anchored certificate of fault allocation in under 200 ms — no LLM, no probabilistic scoring, no vendor cooperation needed for a third party to verify.
If this saves you time,give it a star— it helps others find it and tells us people care.
🎮Try the Interactive Demo— No setup required. Pick a scenario, click "Run Analysis", see real-time liability attribution.
The public Worker is deployed on Cloudflare's global edge network and is fully functional in standalone demo mode (deterministic responses, watermarked, rate-limited 5 calls / IP / day):
- Endpoint:https://mcp.faultkey.com/mcp(live, custom domain)
- Mirror:https://causallayer-mcp-demo.zykm9qkk7j.workers.dev/mcp
- Healthcheck:/healthz
- Demand telemetry:/stats(public, aggregated, no PII)
Add this to~/Library/Application Support/Claude/claude_desktop_config.json(macOS) or%APPDATA%\Claude\claude_desktop_config.json(Windows):
{ "mcpServers": { "faultkey": { "command": "npx", "args": ["-y", "causallayer-mcp"] } } }
Restart Claude. Type"List the FaultKey tools."
- Name:faultkey
- Command:npx -y causallayer-mcp
{ "name": "faultkey", "command": "npx", "args": ["-y", "causallayer-mcp"] }
curl -X POST https://causallayer-mcp-demo.zykm9qkk7j.workers.dev/mcp \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":0,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0"}}}'
The response includes aMcp-Session-Idheader that you reuse for subsequent calls.
Insurers, banks, and APRA-regulated entities cannot accept LLM-based fault attribution because the same prompt produces different answers on different days. FaultKey uses a closed-form causal scoring algorithm (graph-theoretic, version-pinned, byte-identical reproducible across runs) so two adversarial parties get the same number — that's the whole point.
The math is published as an Australian Standards-aligned paper. The signed certificate, issuer registry, and Merkle anchor log are all independently verifiable by a third party using only Node's built-in crypto and thecausallayer-verifiertool — no network calls back to the vendor.
Guardrails (enforced at the Cloudflare edge)
- NO-PII— Payloads are regex-scanned for emails, Tax File Numbers, Medicare numbers, SSNs, and credit cards. Rejected unless the caller setspii_acknowledged: true(which is logged in the certificate as a compliance acknowledgement).
- DETERMINISTIC-ONLY— The engine rejects any request lackingdeterministic_only: true. This is the agent's binding acknowledgement that FaultKey output is closed-form, not probabilistic.
- EVIDENCE-REQ— At least one identified agent and one timestamped event with description must be supplied or the request is rejected with400 evidence_insufficient.
You can deploy your own copy to your own Cloudflare account if you want to enforce a corporate firewall, custom rate limits, or bring your own KV namespace:
git clone https://github.com/smq9sn5jck-coder/causallayer-mcp.git cd causallayer-mcp pnpm install pnpm wrangler kv namespace create LEDGER # paste the returned id into wrangler.jsonc pnpm wrangler deploy
The CausalLayer engine itself (the closed-form fault math) runs upstream and is available via API key. For self-hosted demos without an upstream, setSTANDALONE_DEMO=trueinwrangler.jsoncto short-circuit upstream calls and return deterministic, watermarked responses.
[Claude/Cursor/Cline] ←→ [npx causallayer-mcp] ←→ [Cloudflare Worker] ←→ [CausalLayer engine] (mcp-remote proxy) (this repo) (Fly.io Sydney) ↓ [KV: credit ledger] [DO: per-session state] [KV: telemetry buffer]
- Transport:Streamable HTTP (per the 2024-11-05 MCP spec — SSE is deprecated)
- Session state:Cloudflare Durable Object (CausalLayerMCP), SQLite-backed
- Billing:Cloudflare KV ledger, Stripe Checkout webhook, optional x402 USDC fallback
- Demo:Per-IP daily counter in KV, deterministic fixture responses with[DEMO]watermark
- Latency:p50 ≈ 60 ms (cold), 25 ms (warm) on Cloudflare's 300+ POPs
For enterprise tenants email[email protected](or open a GitHub issue with subject "enterprise inquiry").
Score any AI incident in seconds—faultkey.com/score— describe what happened, get a deterministic liability split with dollar exposure, jurisdiction analysis, and a shareable verdict card.
Compare vendor liability profiles—faultkey.com/compare— side-by-side comparison of AI vendors (OpenAI vs Anthropic vs Google etc.) across incident types.
Public accuracy ledger—faultkey.com/track-record— 7/7 direction match on backtested cases, 3 pending predictions on active litigation.
If FaultKey helped you understand AI liability, saved you research time, or you just think deterministic fault attribution should exist:
- ⭐ Star this repo—github.com/smq9sn5jck-coder/causallayer-mcp(takes 2 seconds, helps others find it)
- Share it— post on LinkedIn, X, or your team Slack
- Score an incident—faultkey.com/score
- Compare vendors—faultkey.com/compare
- Join the discussion—GitHub Discussions
FaultKey is built in Brisbane, Australia, with data residency in Sydney for APRA-regulated buyers. The team can be reached at[email protected].
Verify HMAC-signed compliance attestations from any MEOK MCP server — checks cryptographic signatures, validates timestamps, and produces verifiable trust chains for AI compliance audits.
Post-quantum, tamper-evident receipts for consequential agent actions (Ed25519 + ML-DSA-65, verifiable offline).
KHEPRA MCP Server smithery badge MCP Registry License Container PQC Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings. Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact. The only MCP compliance server that runs on your metal — with the World's First DoD PQC STIG built in. PQC-01-STIG-V1R1 — Full Whitepaper → 17 controls covering CNSA 2.0, FIPS 203/204/205, and the NSA's May 2026 MCP security advisory. The world's first DoD-style Post-Quantum Cryptography STIG, including the first PQC controls for agentic AI and MCP deployments.
Comprehensive audit logging for agent-to-agent interactions — immutable event trails, tamper-evident hashing, structured log export (SIEM-compatible), and compliance-grade retention for regulated industries.
Cryptographic runtime governance for AI agents. 20 tools. Sealed policy artifacts, continuous measurement, tamper-evident proof. Ed25519 + SHA-256.
AI Agent Supply Chain Security - Intercepts and validates every package installation, git clone, and script download triggered by AI coding agents before it executes.
AI Bill of Materials generation — model cards, dataset provenance, supply chain transparency, CycloneDX format by MEOK AI Labs
Structured AI incident reporting for EU AI Act Article 62 — generates mandatory incident reports, severity classification, root cause analysis, and regulator-ready submissions for serious AI incidents.
AI incident detection, classification, and regulatory reporting — covers EU AI Act Article 62, NIST AI RMF, and OECD frameworks
Enforces organisational AI usage policies at the agent layer — blocks prohibited model calls, enforces data residency rules, logs policy violations, and ensures AI governance policies are machine-executable.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



