Get a key
- Sign in to the workspace and top up your balance with USDC (Buy points).
- Open Agent API, name a key, and set a daily cap: the most that key may spend per day, whatever your balance.
- Copy the key (it starts with
grisoco_sk_). It is shown once; store it as a secret, never in source code.
Connect an MCP client
The MCP server lives at https://grisoco.com/mcp (Streamable HTTP). Send your key as a bearer token. In Claude Code:
claude mcp add --transport http grisoco https://grisoco.com/mcp \
--header "Authorization: Bearer grisoco_sk_..."
Or in any client that reads an mcpServers config:
{
"mcpServers": {
"grisoco": {
"type": "http",
"url": "https://grisoco.com/mcp",
"headers": { "Authorization": "Bearer grisoco_sk_..." }
}
}
}
Your agent then has six tools:
quote_audit: the price, before anything is charged.submit_audit: starts the audit. It requiresmax_price_cents, so an agent always states what it agreed to pay.get_audit: status, polled every 30 seconds or so.get_audit_report: the finished report in Markdown or JSON.get_balanceandlist_audits.
Call the REST API
Submit. The answer comes back in about a second with an id, and the audit runs in the background:
curl https://grisoco.com/v1/audits \
-H "Authorization: Bearer $GRISOCO_KEY" \
-H "Content-Type: application/json" \
-d '{
"project_name": "Acme Vault",
"product": "deep_review",
"language": "solidity",
"max_price_cents": <price_cents from /v1/audits/quote>,
"files": [{"path": "src/Vault.sol", "content": "pragma solidity ^0.8.24; ..."}]
}'
Poll until status is succeeded, then fetch the report:
curl https://grisoco.com/v1/audits/aud_... -H "Authorization: Bearer $GRISOCO_KEY"
curl "https://grisoco.com/v1/audits/aud_.../report?format=markdown" \
-H "Authorization: Bearer $GRISOCO_KEY"
POST /v1/audits/quote: same body, returns the price, charges nothing.GET /v1/audits: your recent audits.GET /v1/balance: your balance in cents.productisdeep_review(the full audit, Solidity or DAML) ortools(the deterministic tools only, Solidity).- Send every file the audited contracts import. Files that are only imported are compiled for free; you are billed for the contracts you audit (
audit_targets, default: all of them).
How you are charged
The same prices as the workspace (see pricing), paid from the balance you top up with USDC.
- The price is reserved when you submit and is final when the report is ready.
- If an audit fails on our side, the full price goes back to your balance automatically.
- If the balance or the key's daily cap does not cover an audit, it is refused before anything is charged.
Your agent can never spend more than you prepaid, and never more per day than the key's cap.
Keys, limits and your data
- A key can quote, run and read audits and see the balance. It cannot top up, create keys or change any setting.
- Keys are stored only as a hash. Revoke one in the workspace and it stops working at once.
- Your source code is deleted when the audit ends. The report is kept for about an hour for your agent to collect, then deleted, as our privacy policy describes.
Create a key and connect your agent
Everything an agent needs is one key and a funded balance.