🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

ari-mcp-py

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ari-mcp-py

MCP server for ARI (Agentic Rate Indicators). Live fair-market-value lookups, leaderboards, and signed-receipt verification for x402/MPP services · usable from any MCP-aware agent (Claude Desktop, Cursor, Continue, Windsurf, Zed, ChatGPT desktop, Gemini CLI).

Source
pipPyPI
Version
0.1.3
Weekly downloads
19
Maintainers
1
Weekly downloads
 

ari-mcp-py · Python MCP server for ARI

PyPI version License: Apache 2.0

MCP server for Agentic Rate Indicators. Gives any MCP-aware agent (Claude Desktop, Cursor, Continue, Windsurf, Zed, ChatGPT desktop, Gemini CLI) live fair-market-value lookups, leaderboards, observation history, and Ed25519 signed-receipt verification for x402/MPP services.

pipx install ari-mcp-py
ari-mcp install     # print copy-paste config blocks for popular hosts

Functionally identical to ari-mcp on npm. Use whichever you prefer · both expose the same eleven tools, the same JSON shapes, and verify receipts with the same Ed25519 wire format.

The published name differs (ari-mcp on npm vs ari-mcp-py on PyPI) only because ari is already taken on PyPI · the installed command, configuration, and tool surface are identical.

Why

LLM agents that pay for things need a pricing oracle they can cite, not a number a seller asserts. ARI indexes services that charge over x402 (Coinbase HTTP 402) and MPP (Stripe + Tempo Machine Payments Protocol), tracks observed prices, computes a Fair Market Value with a low/high band, and returns a green/amber/red verdict before any agent pays. Every JSON response is signed with an Ed25519 key and stamped with a citable receipt id, so an agent can refuse to overpay and a human auditor can re-verify any decision weeks later.

Install in 30 seconds

Claude Desktop

~/Library/Application Support/Claude/claude_desktop_config.json (macOS) · %APPDATA%/Claude/claude_desktop_config.json (Windows)

{
  "mcpServers": {
    "ari": {
      "command": "uvx",
      "args": ["ari-mcp-py"]
    }
  }
}

Cursor

~/.cursor/mcp.json

{
  "mcpServers": {
    "ari": {
      "command": "uvx",
      "args": ["ari-mcp-py"]
    }
  }
}

Continue, Windsurf, Zed, ChatGPT desktop, Gemini CLI

Run ari-mcp install to print the right config block for each host. Add --client cursor (or any other slug) to print only one.

The eleven tools

ToolWhat it does
is_fair_priceGreen/amber/red verdict for a quoted price
refuse_if_overpricedConvenience wrapper to call right before paying
prepay_verdictFull pre-pay decision · FMV band, deviation, receipt id
get_fmvMedian plus low/high band plus sample size for a service
get_serviceFull detail row · sources, related services, last observation
list_servicesBrowse or filter the index by protocol or category
get_leaderboardCheapest, most expensive, biggest movers
recent_observationsRaw observed price history for a service
verify_receiptRe-verify a previously issued receipt id
get_signed_receiptRe-fetch the signed body for a receipt
subscribe_alertSet up a webhook or email price alert

Why signed receipts

An agent that pays for things needs to trust two parties at once · the seller quoting a price, and any oracle telling it whether that price is fair. ARI signs every response with an Ed25519 key whose public half ships embedded in this client at build time. There is no first-call trust window · the very first request a fresh install makes is verified against the pinned key id, and any mismatch fails closed with a clear error. If the publisher rotates keys, the new id is added to an accepted-id list one release before the old one is removed, so stale installs keep verifying correctly until they upgrade.

Pass --insecure-skip-pin to accept any key id the server returns (use this only during a rotation). Pass --insecure-skip-verify to skip Ed25519 verification entirely (test setups only).

Self-hosting

ari-mcp --api-base-url https://ari.example.corp

When the base URL is overridden, the client falls back to fetching the publisher key from <base>/.well-known/ari-pubkey.pem on first call · a single trust-on-first-use step that the operator opted in to by choosing the mirror.

CLI reference

ari-mcp [serve]            Start the MCP stdio server (default)
ari-mcp install            Print install snippets for popular MCP hosts
ari-mcp ping               Send a one-shot opt-in install ping
ari-mcp --version          Print the server version

OPTIONS
  --api-base-url URL       Override the ARI API base URL
  --api-key KEY            Bearer token for paid tiers (optional)
  --transport stdio|http   Transport for `serve`. Default: stdio
  --port N                 HTTP port (with --transport http). Default: 8765
  --host HOST              HTTP bind host. Default: 127.0.0.1
  --insecure-skip-verify   Skip Ed25519 receipt verification
  --insecure-skip-pin      Skip the build-time key-id pin (allow rotation)

Documentation

License

Apache-2.0 · contact hello@agenticrates.org.

Keywords

mcp

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts