PluginBench
MCP Server
Active
Apache-2.0

Model Ledger MCP Server

io.github.block/model-ledger

Git for models—track deployed models, dependencies, and changes as an immutable append-only log.

What is the Model Ledger MCP server?

Model Ledger is a model inventory and governance system that discovers deployed models across platforms, maps their dependency graph automatically, and records every change as an immutable event. It spans multiple platforms (MLflow, SageMaker, W&B, SQL, REST, GitHub) as one connected graph and is built to be driven by AI agents through a native MCP server.

Model Ledger helps organizations track what models are deployed, where they run, what they depend on, and what changed. It automatically discovers models from multiple platforms, builds a dependency graph by matching input/output ports, and maintains a complete audit trail. The MCP server surface lets Claude and other AI agents query your model inventory—answering questions like "if we deprecate this model, what breaks?" in seconds.

How to install Model Ledger

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "model-ledger": {
      "command": "uvx",
      "args": [
        "model-ledger",
        "--from",
        "model-ledger[mcp,cli]==0.7.13",
        "mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Dependency tracing — Trace upstream and downstream dependencies of a model to understand impact of changes
  • Model discovery — Automatically discover models from SQL, REST, GitHub, Prefect, and other connectors
  • Change history — Query the append-only event log to see what changed and when
  • Compliance validation — Validate models against SR 11-7, SR 26-2, EU AI Act Annex IV, and NIST AI RMF profiles
  • Point-in-time reconstruction — Reconstruct the full model inventory state at any past point in time
  • Dependency graph queries — Query the automatically-built dependency graph to understand model relationships

Use cases

  • Determine what models will break if you deprecate a specific model or dataset
  • Audit which models depend on a particular data source or feature
  • Track model deployments and changes across multiple ML platforms as a single source of truth
  • Validate model governance compliance with regulatory frameworks (SR 11-7, EU AI Act, NIST AI RMF)
  • Reconstruct the state of your model inventory at any point in the past for incident investigation

Model Ledger MCP server FAQ

What is Model Ledger?

Model Ledger is a model inventory system that discovers deployed models across platforms, automatically builds their dependency graph, and records every change as an immutable event. It's designed to work with AI agents via MCP.

Is Model Ledger free?

Yes, Model Ledger is open-source under the Apache 2.0 license. Install via `pip install model-ledger`.

How do I use it with Claude or Cursor?

Install the MCP extra (`pip install "model-ledger[mcp]"`) and add it to Claude with `claude mcp add model-ledger -- model-ledger mcp --demo`. Then ask Claude questions about your model inventory.

What platforms does it support?

Model Ledger discovers models from SQL, REST APIs, GitHub, Prefect, and custom connectors. It stores data in-memory, SQLite, JSON, Snowflake, or remote HTTP backends.

Does it require authentication?

Authentication depends on your data sources and backend. Connectors for SQL, REST, and GitHub require appropriate credentials; the in-memory demo mode requires none.

What compliance frameworks does it support?

Model Ledger includes validation profiles for SR 11-7, SR 26-2, EU AI Act Annex IV, and NIST AI RMF.

README (reference)

Source of truth, from the repository.

model-ledger

git for models — know what models you have deployed, where they run, what they depend on, and what changed.

CI License Python PyPI Downloads Docs

📖 Documentation · Quickstart · Concepts · Governance


model-ledger is a model inventory for any organization with deployed models. It discovers models, heuristic rules, and ETL across your platforms, maps the dependency graph automatically, and records every change as an immutable event. Unlike registries tied to a single platform (MLflow, SageMaker, W&B), it spans all of them — as one connected graph — and it's built to be driven by AI agents through a native MCP server.

Benchmarked at production scale: full inventory reconstruction over a ledger of 28.8k models and 212k events runs in under a second (CHANGELOG, v0.7.4).

Install

pip install model-ledger

The graph builds itself

Every model is a DataNode with typed input and output ports. When an output port name matches an input port name, connect() creates the dependency edge — no hand-wiring.

from model_ledger import Ledger, DataNode

ledger = Ledger()

ledger.add([
    DataNode("segmentation", platform="etl",      outputs=["customer_segments"]),
    DataNode("fraud_scorer", platform="ml",       inputs=["customer_segments"], outputs=["risk_scores"]),
    DataNode("fraud_alerts", platform="alerting", inputs=["risk_scores"]),
])
ledger.connect()

ledger.trace("fraud_alerts")
# ['segmentation', 'fraud_scorer', 'fraud_alerts']

Every mutation is recorded as an immutable Snapshot — an append-only event log that gives you full history and point-in-time reconstruction, because nothing is overwritten.

Talk to your inventory

The MCP server is a first-class surface — point Claude (or any MCP agent) at it:

pip install "model-ledger[mcp]"
claude mcp add model-ledger -- model-ledger mcp --demo

You: if we deprecate customer_features, what breaks?

Claude: 3 models consume it directly, 2 more transitively.

Documentation

Everything lives at block.github.io/model-ledger — and it can't drift, because the API reference is generated from source and every example runs in CI:

  • Quickstart — install to your first dependency trace in 60 seconds
  • Concepts — DataNode, Snapshot, and Composite, in three ideas
  • Agents (MCP) — the eight-tool agent surface, with a worked transcript
  • Connectors — discover from SQL, REST, GitHub, or your own platform
  • Backends — in-memory, SQLite, JSON, Snowflake, or remote HTTP
  • Governance — how the primitives map to SR 11‑7/SR 26‑2, the EU AI Act, and NIST AI RMF
  • API reference — generated from the source

Architecture

flowchart LR
    subgraph Sources
        C1[SQL / REST / GitHub / Prefect<br/>connectors]
    end
    subgraph Core
        L[Ledger<br/>append-only event log,<br/>point-in-time reconstruction]
        G[Dependency graph]
        V[Compliance profiles<br/>SR 11-7/SR 26-2 · EU AI Act · NIST AI RMF]
    end
    subgraph Surfaces
        S1[Python SDK]
        S2[CLI]
        S3[REST API]
        S4[MCP server · 8 tools]
    end
    B1[(in-memory · SQLite · JSON ·<br/>Snowflake · remote HTTP)]
    C1 --> L
    L --> G
    L --> V
    L --- B1
    S1 --> L
    S2 --> L
    S3 --> L
    S4 --> L

For organizations

The OSS core handles discovery, graph building, change tracking, storage, the agent protocol, and compliance validation — the SR 11‑7/SR 26‑2, EU AI Act Annex IV, and NIST AI RMF profiles ship in model_ledger.validate. Your internal package provides only the thin layer on top: connector configs, custom connectors for internal platforms, and credentials. Thin config, not reimplemented logic.

Contributing

See CONTRIBUTING.md. All commits require DCO sign-off.

Security

See SECURITY.md for how to report vulnerabilities privately.

License

Apache-2.0. See LICENSE.

Created and maintained by Vignesh Narayanaswamy at Block.

<!-- mcp-name: io.github.block/model-ledger -->

Related MCP servers

Crypto MCP — 99 tools across news, market, on-chain, sentiment, indicators, agent generation.

1
TypeScript
MIT
View repository →

Bitcoin on-chain analytics — 109 metrics: MVRV, SOPR, NUPL, HODL Waves, CDD, cycles & more

0
JavaScript
View repository →

Air-gapped Markdown/PDF to Word converter with brand templates and audit logging.

Persistent memory for AI agents — audio intelligence + Music Memory ingestion and recall

0
JavaScript
View repository →
NOnoHumansShop logo

Affiliate marketplace for AI agents: find tools, publish verified guides, earn. OAuth, no keys.

0
TypeScript
View repository →

The open chart format an LLM writes and the browser renders — to interactive, accessible SVG.

0
TypeScript
MIT
View repository →