# Verifiable Random Free MCP endpoint: https://random.cipblujdea.com/mcp Free tools: random_int and status. They work in a standard remote-MCP client without a wallet. Copyable setup prompt for a coding agent: Add https://random.cipblujdea.com/mcp as a Streamable HTTP MCP server, list its tools, then call random_int with min 0 and max 1. Do not call random_int_signed unless an MPP-capable client and a locally controlled Tempo wallet are configured. Claude Code free-MCP setup: claude mcp add --transport http verifiable-random https://random.cipblujdea.com/mcp Codex free-MCP setup: codex mcp add --transport http verifiable-random https://random.cipblujdea.com/mcp The commands above provide only free random_int and status. Paid MCP random_int_signed needs a locally controlled, funded Tempo wallet. Download the audited MCP payer client from https://random.cipblujdea.com/client/pay-mcp-client.mjs after installing @modelcontextprotocol/sdk@1.30.0, mppx@0.9.3, and viem@2.56.3. It makes one signed push credential, saves recovery evidence before its one paid retry, and refuses another payment challenge. Paid HTTP endpoint: POST https://random.cipblujdea.com/v1/random Paid client setup: https://random.cipblujdea.com/client Late-payment recovery: POST https://random.cipblujdea.com/v1/random/recover with the exact original challenge and Tempo transaction hash. Recovery is fail-closed and ends 24 hours after challenge expiry. OpenAPI: https://random.cipblujdea.com/openapi.json MPP metadata: https://random.cipblujdea.com/mpp.json Built-in same-origin paid-client setup: https://random.cipblujdea.com/client Download the exact HTTP ESM from https://random.cipblujdea.com/client/pay-client.mjs. Install with npm init -y && npm install --save-exact mppx@0.9.3 viem@2.56.3, then set SERVICE_URL=https://random.cipblujdea.com, PAYER_PRIVATE_KEY=, and REQUEST_ID=, and run node pay-client.mjs. Download the exact MCP ESM from https://random.cipblujdea.com/client/pay-mcp-client.mjs after installing @modelcontextprotocol/sdk@1.30.0, mppx@0.9.3, and viem@2.56.3; set MCP_URL, PAYER_PRIVATE_KEY, and REQUEST_ID, then run node pay-mcp-client.mjs. Both clients save an owner-only recovery record before their one paid retry; recover with RECOVER=true RECOVERY_FILE= node .mjs. Never put the payer key in a request or on the service. An approved client must print the requestId, recovery-record path, and payment terms, then ask the user to type yes before creating a payment credential. Preserve both the requestId and the owner-only recovery record. If the response is lost, use that record to submit the exact challenge and transaction hash to the recovery endpoint without buying another draw. A retry with the same requestId and bounds recovers an already-completed result, but the UUID alone is not proof of an unsettled payment. Noninteractive automation of the reference client must set APPROVE_PAYMENT=true as an explicit local spending policy. Mainnet separately requires ALLOW_MAINNET=true, so automated mainnet use needs both flags. Draws use a signature-verified drand quicknet round. When a consenting KiwiSDR receiver supplies a suitable sample, the service mixes it into the draw and reports its provenance. Radio-noise provenance is operator-reported and is not an independent proof of operator fairness. Do not use this service to generate cryptographic keys.