ERC-7303 token-controlled roles for AI agents: grant, check, and revoke permissions on-chain
Most developer tooling work still happens through a UI a human drives. Tctc MCP server moves it into the conversation instead. ERC-7303 token-controlled roles for AI agents: grant, check, and revoke permissions on-chain.
An MCP server exposing ERC-7303 (Token-Controlled Token Circulation) roles to AI agents: agents check their own on-chain permissions, and human principals grant/revoke them by minting/burning control tokens — no permission server required.
tctc-mcp on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.
The server publishes 7 tools. What each one is for:
list_roles — bothcheck_role — bothcheck_all_roles — bothdiscover_roles — bothresolve_agent — both*grant_role — adminrevoke_role — adminConfiguration is passed through the environment: TCTC_ADMIN_PRIVATE_KEY, ALCHEMY_API_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Tctc's toolset — list_roles, check_role, check_all_roles and 4 more — is a fair guide to whether it matches your workflow. It is maintained by kofujimura; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| list_roles | both |
| check_role | both |
| check_all_roles | both |
| discover_roles | both |
| resolve_agent | both* |
| grant_role | admin |
| revoke_role | admin |
Or in a project-scoped `.mcp.json`:
```json
{ "mcpServers": { "tctc": { "command": "npx",
"args": ["-y", "tctc-mcp", "--config", "examples/config.sepolia.agent.json"] } } }Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| TCTC_ADMIN_PRIVATE_KEY | Credential the server authenticates with. | Yes |
| ALCHEMY_API_KEY | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.