Remit
MCP serverAI & modelsChecked language for AI-written agent workflows: limits, cost and data flows known before running.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the remit guide tool from Remit
Install Remit
The server’s own address, for the clients that take one directly. Or connect ahel once and every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.
Claude Code
claude mcp add --transport http --scope user remit 'https://77-68-52-20.sslip.io/mcp'Run it once in your project, then open /mcp to approve any sign-in the server asks for.
Claude Desktop
https://77-68-52-20.sslip.io/mcpAdd a custom connector in Settings, paste this address, and approve the sign-in.
Cursor
cursor://anysphere.cursor-deeplink/mcp/install?name=remit&config=eyJ1cmwiOiJodHRwczovLzc3LTY4LTUyLTIwLnNzbGlwLmlvL21jcCJ9Open the link and Cursor adds the server at that address.
ChatGPT
https://77-68-52-20.sslip.io/mcpIn Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.
Codex
codex mcp add remit --url 'https://77-68-52-20.sslip.io/mcp'Run it once, then sign in with codex mcp login remit if the server asks for an account.
From the project's README
As published by mrpacstar2-oss/remit in README.md.
Know what an AI-written program can do before it runs.
Remit is a small, statically checked language for agent workflows, meaning programs that call tools and models. It is meant to be written and edited by AI agents. Before a program runs, the checker reports:
- which capabilities it can use, from a host-controlled list;
- at most how many times it can call each one, and its worst-case spend;
- whether untrusted data (documents, web pages, model output) or private data can reach sensitive parameters, such as payment details or email recipients. Each such flow is rejected outright, or sent to a human for approval bound to the exact arguments.
A runtime broker then enforces the same rules and records a replayable trace.
payments.schedule(vendor_id: vendor.id, iban: inv.iban_on_invoice, amount: inv.amount, ...)
error[E0301]: data tagged untrusted flows into 'payments.schedule' parameter 'iban', which denies it
note: 'inv.iban_on_invoice' is untrusted because it derives from inbox.read (line 20)
For AI agents
-
MCP server, local:
remit mcp(stdio). -
MCP server, hosted:
remit mcp --http, with optional API keys and usage metering. -
Tools:
Tool What it does remit_guidethe guide or the full spec remit_checkerrors plus the authority manifest remit_formatcanonical formatting remit_authority_diffdid an edit widen authority? remit_examplescomplete example programs remit_run_fixturesoffline test runs -
Quick guide: docs/AI_GUIDE.md.
-
Full specification: docs/LANGUAGE_SPEC.md.
-
llms.txt: site/llms.txt, plus site/llms-full.txt.
Claude Code configuration example:
{ "mcpServers": { "remit": { "command": "remit", "args": ["mcp"] } } }
Quick start
python3 -m venv .venv && .venv/bin/pip install -e ".[mcp]" pytest pydantic
.venv/bin/python -m pytest -q tests baselines
cd examples/invoices
../../.venv/bin/remit check invoices.rmt # manifest and policy check
../../.venv/bin/remit run invoices.rmt # offline fixtures; stops for approval
../../.venv/bin/remit approve <digest> && ../../.venv/bin/remit resume <run-id> # approve that exact call, continue
Evidence
docs/BENCHMARKS.md compares Remit with a Python baseline that uses the same runtime, so runtime features are not credited to the language. Samples are small, use one model family and include no human trials.
- Safety:
- Of 17 unsafe program mutations, 14 were rejected before running. Python on the same runtime executed 8 of them.
- Asked to make unsafe changes, Haiku 4.5 agents shipped executable unsafe code 0/6 times in Remit and 6/6 in Python. Sonnet 5.5 refused in both languages.
- Review: every agent-written feature change (20 of 20) was mechanically shown not to widen authority.
- Ease:
- Agents modified programs (15/15 against 14/15) and built a new workflow from a spec (5/5 against 5/5) equally well in both languages, so there is no penalty for a language the models had never seen.
- Agents that only had the MCP server built correct programs 5/5.
- Recovery: crash-and-resume behaviour is identical in both, as expected, since it is a runtime property.
Status
This is a research prototype.
- Implemented and tested: the parser, checker, interpreter, broker, CLI (
check,build,run,test,fmt,replay,approve,resume,diff,ask,mcp), the MCP server and five example apps. - Not implemented: an OS sandbox (run it inside your own isolation), modules, concurrency and a language server. See LANGUAGE_SPEC §13.
Deploying the website and hosted MCP server is covered in deploy/PUBLISHING.md.
Licence: Apache-2.0.
Tools it offers (6)
What this server listed when ahel dialed its public endpoint in Oct 2026, with no key and no account of yours. The names are the server’s own.
remit_guideremit_checkremit_formatremit_authority_diffremit_examplesremit_run_fixtures
Signals
- Last commit
- Oct 2026
Advanced
- Delivery
- remit MCP server → your ahel connector (mcp.ahel.ai) → your AI.
- Item type
- mcp-server
- Key
io-github-mrpacstar2-oss-remit- Source
- github.com/mrpacstar2-oss/remit
- Hosted endpoint
https://77-68-52-20.sslip.io/mcp
github.com/mrpacstar2-oss/remit