MCP Server for OpenTTT — Proof of Time tools for AI agents AI Agent A and Agent B both trigger a payment at the same time. Who was first? OpenTTT answers this with cryptographic Proof of Time — synthesized from multiple independent time sources, verified through GRG integrity shards, and signed with Ed25519 for non-repudiation.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
esbuild allows arbitrary file read when running the development server on Windows
process.env. You'll be asked to provide them before it can run.FREE_TIER_LIMITOPENTTT_SERVER_URLPORT— HTTP mode (Glama / Smithery container, set): the per-IP free tier limit (100 calls/day) is enforced locally in the server process.REDIS_URL— server_restart: the server restarted and the in-memory DAG was cleared. If Redis is available and is set, the DAG is rebuilt from Redis on startup — reducing restart gaps.TTT_API_KEY— claude mcp add ttt -e =your-key -- npx -y @helm-protocol/ttt-mcp@0.3.0[](https://m8ven.ai/mcp/helm-protocol-openttt-mcp-dnsvqu)