Content-addressed contracts and a verification cache that cut agent context by skipping proven code.
Content-addressed contracts and a verification cache that cut agent context by skipping proven code. That is what the heddle mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.
Because contracts are content-addressed and dependency-aware, agents reuse verification, compute blast radius precisely, and regenerate code from a few hundred tokens of context instead of re-reading whole files. Build systems ask which files changed. Hashloom asks which software obligations changed.
The server publishes 5 tools. What each one is for:
get_contract — the ~300-token context packet: contract + hash + one-line dep signatures + caller listput_contract — validate, write contracts/.yaml, return new hash, a semantic diff of what changed, and every invalidated dependentget_dependents — blast-radius query, direct or transitive, names + hashes; inferred (unreviewed) contracts flaggedverify — per-unit cached-pass / pass / fail plus a top-level ok gate bit; radius=true widens each name to its full blast radius; runs tests only on cachestatus — dirty contracts, stale verifications, cache hit-rate, resolved verify interpreter, cumulative token countersThe server ships on PyPI as hashloom, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Heddle's toolset — get_contract, put_contract, get_dependents and 2 more — is a fair guide to whether it matches your workflow. It is maintained by davet47; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Heddle's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| get_contract | the ~300-token context packet: contract + hash + one-line dep signatures + caller list |
| put_contract | validate, write contracts/<name>.yaml, return new hash, a semantic diff of what changed, and every invalidated dependent |
| get_dependents | blast-radius query, direct or transitive, names + hashes; inferred (unreviewed) contracts flagged |
| verify | per-unit cached-pass / pass / fail plus a top-level ok gate bit; radius=true widens each name to its full blast radius; runs tests only on cache misses; failures come back as a ≤40-token assertion summary, never a traceb |
| status | dirty contracts, stale verifications, cache hit-rate, resolved verify interpreter, cumulative token counters |
{
"mcpServers": {
"heddle": {
"command": "uvx",
"args": ["hashloom"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.