{"_id":"captchakraken-mcp","_rev":"3-2428d4db057ae112f02c08d30eb99a12","name":"captchakraken-mcp","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"captchakraken-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","captcha","captchakraken"],"author":{"name":"Jake Writer"},"license":"SEE LICENSE IN LICENSE","_id":"captchakraken-mcp@0.1.0","maintainers":[{"name":"jwriter20","email":"jawhackercode@gmail.com"}],"homepage":"https://github.com/JWriter20/CaptchaKraken#readme","bugs":{"url":"https://github.com/JWriter20/CaptchaKraken/issues"},"bin":{"captchakraken-mcp":"dist/index.js"},"dist":{"shasum":"7d40c5e1455a0495d5ac9bda424c6ce43bafa711","tarball":"https://registry.npmjs.org/captchakraken-mcp/-/captchakraken-mcp-0.1.0.tgz","fileCount":11,"integrity":"sha512-53ngFGrmVLUyZuQLKMYo3yfo2wgHwIErP4MRNLtH9kSWmz1oZ1ys/hBAVmElgRkdDf7e0eeD1UoJNXBQIf8r3Q==","signatures":[{"sig":"MEUCIDMWeDKHEDFtDM9Xlp3zcDs7Ln38roZkJKIhHISQ30P9AiEAjlsUgeLJE4y814UaCE+sQwHS+ne32+qRAmdg8moAAew=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78320},"type":"module","engines":{"node":">=20"},"scripts":{"build":"tsc -p tsconfig.json","start":"node dist/index.js","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"jwriter20","email":"jawhackercode@gmail.com"},"repository":{"url":"git+https://github.com/JWriter20/CaptchaKraken.git","type":"git","directory":"mcp"},"_npmVersion":"10.8.2","description":"MCP server for CaptchaKraken: sign in with GitHub, mint API keys for the Abyss model, and read your usage and spending.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/captchakraken-mcp_0.1.0_1785307590156_0.4492435186465864","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"captchakraken-mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","captcha","captchakraken"],"author":{"name":"Jake Writer"},"license":"SEE LICENSE IN LICENSE","_id":"captchakraken-mcp@0.1.1","maintainers":[{"name":"jwriter20","email":"jawhackercode@gmail.com"}],"homepage":"https://github.com/JWriter20/CaptchaKraken#readme","bugs":{"url":"https://github.com/JWriter20/CaptchaKraken/issues"},"bin":{"captchakraken-mcp":"dist/index.js"},"dist":{"shasum":"38eb531dd4a549dd72137b6232b4c10cc35fe6ed","tarball":"https://registry.npmjs.org/captchakraken-mcp/-/captchakraken-mcp-0.1.1.tgz","fileCount":11,"integrity":"sha512-st3QZMuclRedeh8DFF4urnW8/yrNpOBrxeiCSn4n6fYu9IgpCW3lDhX5AfVCemfmYcn2YnOW0+ltkXZlV+Hsug==","signatures":[{"sig":"MEQCIHs6fGJuLf04M+kQwn678ns+PJKkCagxltBU4GcsiMedAiAVsSjJvyK000nZwvWHGm3x02gVkEvhPOMFXJMvczUx0g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/captchakraken-mcp@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":82821},"type":"module","engines":{"node":">=20"},"gitHead":"026c3d10b2215748c3a255d14d8bf95d510e4cc4","scripts":{"build":"tsc -p tsconfig.json","start":"node dist/index.js","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e3566a6-e106-4a3e-986d-e56661873853"}},"repository":{"url":"git+https://github.com/JWriter20/CaptchaKraken.git","type":"git","directory":"mcp"},"_npmVersion":"11.17.0","description":"MCP server for CaptchaKraken: sign in with GitHub, mint API keys for the Abyss model, and read your usage and spending.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/captchakraken-mcp_0.1.1_1787462504473_0.7215990478749619","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"captchakraken-mcp","version":"0.1.2","description":"MCP server for the CaptchaKraken account: sign in with GitHub, mint and revoke API keys for the captcha-solving endpoint, and read your usage and balance. Writes the key to disk so the solver needs no environment variables.","type":"module","author":{"name":"Jake Writer"},"license":"SEE LICENSE IN LICENSE","bin":{"captchakraken-mcp":"dist/index.js"},"engines":{"node":">=20"},"repository":{"type":"git","url":"git+https://github.com/JWriter20/CaptchaKraken.git","directory":"mcp"},"keywords":["mcp","model-context-protocol","captcha","captchakraken","claude","api-keys","llm-tools"],"bugs":{"url":"https://github.com/JWriter20/CaptchaKraken/issues"},"homepage":"https://github.com/JWriter20/CaptchaKraken#readme","scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc --noEmit","prepublishOnly":"npm run build","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.30.0","zod":"^3.25.76"},"devDependencies":{"@types/node":"^22.20.1","typescript":"^5.9.3"},"gitHead":"a0dcc4c3505be91a3a3aa4ecd4314d9739fee3ed","_id":"captchakraken-mcp@0.1.2","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-gUglOfyzpK2a0OY9Kh5fg3wqIXyZisohucCD0D4jpFJE504TlblNS1tWKKfCPm8+uh4p5fNomyIyfbhMncwnYg==","shasum":"c06756d1dd7a99b6da19fc8252b8c79d2e33c7a7","tarball":"https://registry.npmjs.org/captchakraken-mcp/-/captchakraken-mcp-0.1.2.tgz","fileCount":11,"unpackedSize":83201,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/captchakraken-mcp@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIB2bN/7It94Ue5adxqaNPOglp8JUmmGIuFeSrIty77lEAiEAoP8T8ZYsv3Mq1O4lG47uBK1jNEo9V21bOPc79hacCx8="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e3566a6-e106-4a3e-986d-e56661873853"}},"directories":{},"maintainers":[{"name":"jwriter20","email":"jawhackercode@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/captchakraken-mcp_0.1.2_1787464200204_0.6780358725314646"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T06:46:29.928Z","modified":"2026-08-23T05:50:00.688Z","0.1.0":"2026-07-29T06:46:30.309Z","0.1.1":"2026-08-23T05:21:44.660Z","0.1.2":"2026-08-23T05:50:00.352Z"},"bugs":{"url":"https://github.com/JWriter20/CaptchaKraken/issues"},"author":{"name":"Jake Writer"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/JWriter20/CaptchaKraken#readme","keywords":["mcp","model-context-protocol","captcha","captchakraken","claude","api-keys","llm-tools"],"repository":{"type":"git","url":"git+https://github.com/JWriter20/CaptchaKraken.git","directory":"mcp"},"description":"MCP server for the CaptchaKraken account: sign in with GitHub, mint and revoke API keys for the captcha-solving endpoint, and read your usage and balance. Writes the key to disk so the solver needs no environment variables.","maintainers":[{"name":"jwriter20","email":"jawhackercode@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://raw.githubusercontent.com/JWriter20/CaptchaKraken/main/docs/assets/logo-card.png\" alt=\"CaptchaKraken\" width=\"128\" height=\"128\">\n</p>\n\n<h1 align=\"center\">captchakraken-mcp</h1>\n\n<p align=\"center\">\n  <b>The CaptchaKraken account, driven from an MCP client.</b>\n</p>\n\nIt signs you in through GitHub, mints and revokes API keys for the solving\nendpoint, and reads back what you have spent.\n\n**It does not solve captchas.** The key it mints is what does that, against the\nOpenAI-compatible endpoint at `api.captchakraken.com/v1`.\n\n```bash\nclaude mcp add captchakraken -- npx -y captchakraken-mcp\n```\n\n## Tools\n\n| Tool | What it does |\n| --- | --- |\n| `sign_in` | Prints a code and a link; the human approves in a browser. Creates the account if it does not exist, with trial credits and a first key. |\n| `sign_out` | Revokes this client's token on the server and deletes it from disk. |\n| `get_account` | Who is signed in, the balance, and the base URL to point a solver at. |\n| `get_balance` | The balance, and nothing else. |\n| `get_usage` | Billable responses and credits, per day and in total, plus purchases. |\n| `list_api_keys` | The account's solving keys, masked. |\n| `create_api_key` | Mints one and **saves it to disk; the secret is never shown.** |\n| `revoke_api_key` | Kills one by id. Effective within ~30 seconds. |\n| `get_topup_link` | A Stripe URL for the human to open. Charges nothing. |\n| `get_pricing` | The rate card, and how many responses a captcha typically takes. |\n| `get_models` | The lineup, so an agent can decide whether to self-host instead. |\n\n## Signing in\n\nThe MCP server runs on a laptop, inside an editor, with no browser it controls\nand nowhere for an OAuth redirect to land. It also cannot hold our GitHub client\nsecret — it is distributed to customers, so anything baked into it is public.\n\nSo it uses the device flow (RFC 8628):\n\n```\nsign_in  ──▶  \"Open http://…/device?code=ABCD-EFGH, code ABCD-EFGH\"\n                    │\n                    ├─ the human opens it, signs in with GitHub, approves\n                    │\nsign_in  ──▶  \"Signed in as <login>. Balance: $0.50\"\n```\n\n`sign_in` waits about 25 seconds and then hands control back rather than\nblocking — MCP clients time tool calls out, and a call killed mid-wait would\nstrand the code. **Calling it again resumes the same request**; it does not\nprint a second code at a human who is already looking at the first.\n\n## Two credentials, two blast radii\n\nThe token this server holds (`ckm_…`) manages the account: it reads the balance\nand usage, mints and revokes API keys, and opens a checkout page. **It cannot\nsolve a captcha.**\n\nAn API key (`ck_live_…`) solves captchas. **It cannot manage the account** — the\naccount API returns 401 for one, exactly as it does for a random string.\n\nThat split is the point. If they were one credential, a key leaked from a\nscraper could mint its own replacements faster than anyone could revoke them,\nand the balance would stop being a bound on the damage. Either can be revoked\nfrom the dashboard.\n\nNothing here can spend money. `get_topup_link` returns a URL; a person clicks\nit, on a page Stripe hosts. There is no tool that charges a card.\n\n## Where the credentials live\n\nTwo files, because they are two credentials.\n\n**The management token** (`ckm_…`) is in `~/.config/captchakraken/mcp.json`,\nmode 0600 in a 0700 directory, keyed by the control-plane origin — so\nrehearsing against a staging deployment and then running against production\nswitches identity cleanly instead of presenting a staging token to production\nand 401ing with no explanation.\n\n**The solving key** (`ck_live_…`) is in `~/.captchakraken/credentials`, also\n0600, written by `create_api_key` and read by the solver itself. It carries the\nendpoint alongside the key, so after `create_api_key` a solve works with **no\nenvironment variables set at all**.\n\nThe secret is never returned through a tool result. It goes straight to that\nfile and the tool reports the path, because a key in a tool result is a key in\nthe transcript the moment an agent repeats it back in a summary — and asking an\nagent nicely not to do that is not a control. If you need the key in an env var\ninstead, read it out of the file yourself; nothing in this server will print it.\n\nIt is not encrypted. A local secret encrypted with a local key is ceremony, not\nprotection: whoever can read the file can read the key. The real defences are\nthe file mode, the token's one-year expiry, and the dashboard's disconnect\nbutton.\n\nDelete the file to forget everything, or run `sign_out`, which also revokes the\ntoken server-side. Prefer `sign_out` — deleting the file alone leaves a live\ncredential that nothing can reach to revoke.\n\n## Configuration\n\n| Variable | Default | Why |\n| --- | --- | --- |\n| `CAPTCHAKRAKEN_BASE_URL` | `https://captchakraken.com` | Point at a staging or self-hosted control plane. |\n| `CAPTCHAKRAKEN_CLIENT_NAME` | `MCP client` | Shown on the approval page. A person approving a code should see something they recognise. |\n\n## Development\n\n```bash\nnpm install\nnpm run typecheck\nnpm run build\nCAPTCHAKRAKEN_BASE_URL=http://127.0.0.1:3000 node dist/index.js\n```\n\nThe server it talks to is `captchakraken-cloud`; the endpoints are documented in\nthat package's README under **The MCP surface**, and covered by\n`test/mcp-api.test.ts` there. Nothing on stdout but MCP frames — stdout *is* the\nprotocol channel on this transport, and one stray `console.log` corrupts the\nstream and presents as a broken server.\n","readmeFilename":"README.md"}