Give AI agents authority to act.

Agents can request authority through MCP or the API for payments, releases, or any other action your service can describe and verify. TKeeper checks the exact request and signs proof for the service that performs it.

MCP tools.

One example: an agent prepares a package release. A swapped package could reach every customer that installs it. Before publication, the agent asks TKeeper through MCP to sign the package name, version, registry, and file hash. A release owner approves it; your publisher checks the signature and package file before publishing.

01

Agent requests

The agent submits the package name, version, registry, and file hash through TKeeper’s MCP tool.

02

TKeeper checks

The rule limits the package and registry and requires the release owner’s approval.

03

Publisher releases

Your publisher verifies the signed request and checks the package file against its hash before publishing.

Agentic payments.

An agent setting up a customer project buys hosting from an approved provider. TKeeper checks the provider, company card, and spend limits, then signs an AP2 or Mastercard Verifiable Intent credential for checkout.

Agent purchaseHosting
SupplierApproved providerPayment methodCompany cardSpendWithin company limit
Payment credential signed

Protect agent payments and tools.

MPC keeps one compromised signing host from authorizing a purchase or tool action on its own.

How MPC works