Home / Token cost / Agent Passport System — Cryptographic Identity for AI Agents

The Agent Passport System — Cryptographic Identity for AI Agents MCP server costs 23,268 tokens before the first call.

Connect Agent Passport System — Cryptographic Identity for AI Agents and its 150 tool definitions are loaded into the model's context on every request — 12% of a 200k window spent before your agent does anything.

QUICK ANSWER The Agent Passport System — Cryptographic Identity for AI Agents MCP server's tool definitions consume 23,268 tokens — 12× the median MCP server (1,905 tokens). A scoped grant exposing only the tools you use cuts that roughly in proportion.

MEASURED FROM SCHEMAS 150 tools · 23,268 tokens · 12% of 200k · 2.3% of 1M Method →

What that buys before your agent starts working.

Tool definitions are overhead: they occupy context on every request and compete with your code, documents and conversation history for the same window.

200K WINDOW 12%
1M WINDOW 2.3%

Corpus context: Agent Passport System — Cryptographic Identity for AI Agents ranks #47 of 3,213 measured MCP servers by definition cost. The median is 1,905 tokens, p90 is 7,952, and the heaviest (Fusionauth) is 183,337 — 92% of a 200k window on its own.

Where the 23,268 tokens go.

Each row is one tool definition as a tools/list entry — name, description and input schema — counted with o200k_base. Average: 155 tokens per tool.

ToolCategoryTokens% of server
mutualAuthBuildCertificate Execute 455 2.0%
create_charter Write 379 1.6%
create_task_brief Write 375 1.6%
aps_capability_evaluate_authority Read 333 1.4%
aps_compute_data_axis_weights Read 333 1.4%
aps_capability_issue_challenge Write 330 1.4%
create_decision_lineage_receipt Write 326 1.4%
aps_aggregate_settlement Execute 324 1.4%
aps_construct_attribution_primitive Execute 317 1.4%
create_derivation_receipt Write 306 1.3%
aps_create_attribution_receipt Write 304 1.3%
register_data_source Write 300 1.3%
aps_capability_sign_effect Read 297 1.3%
mutualAuthVerifyAttest Read 289 1.2%
generate_governance_block Write 274 1.2%
create_reserve_attestation Write 259 1.1%
generate_aps_txt Write 255 1.1%
governance_360 Execute 252 1.1%
review_evidence Read 249 1.1%
aps_compute_compute_axis_weights Execute 248 1.1%
submit_evidence Write 232 1.0%
create_chained_governance_block Write 228 1.0%
aps_create_provisional Write 221 0.9%
define_emergency_pathway Read 219 0.9%
review_promotion Write 210 0.9%
issue_passport Write 205 0.9%
create_intent Write 202 0.9%
rotate_key Read 198 0.9%
aps_verify_settlement Read 197 0.8%
create_artifact_provenance Write 197 0.8%
create_outcome_record Write 197 0.8%
aps_capability_mint_receipt Read 196 0.8%
aps_record_owner_confirmation Read 194 0.8%
register_agora_public Write 194 0.8%
create_principal Write 192 0.8%
verify_issuer Read 190 0.8%
aps_build_contributor_query Execute 186 0.8%
compare_timestamps Read 186 0.8%
create_access_receipt Write 185 0.8%
submit_deliverable Write 183 0.8%
create_agent_context Write 180 0.8%
endorse_agent Read 178 0.8%
create_delegation Write 176 0.8%
send_message Write 176 0.8%
execute_with_context Execute 172 0.7%
check_tier Read 170 0.7%
post_agora_message Write 170 0.7%
apply_reputation_downgrade Write 169 0.7%
assign_agent Write 169 0.7%
update_reputation Write 169 0.7%
aps_check_escalation_required Read 168 0.7%
mutualAuthVerifyTrustBundle Read 167 0.7%
evaluate_threshold Read 166 0.7%
request_intro Read 166 0.7%
mutualAuthDeriveSession Read 165 0.7%
supersede_v2_delegation Read 164 0.7%
is_evidence_fresh Read 161 0.7%
sub_delegate Read 160 0.7%
check_jurisdiction_transfer Read 159 0.7%
check_aggregate_constraints Read 154 0.7%
evaluate_intent Read 154 0.7%
create_approval_request Write 153 0.7%
handoff_evidence Read 150 0.6%
create_access_snapshot Write 150 0.6%
aps_withdraw_provisional Financial 149 0.6%
check_combination_permitted Read 149 0.6%
request_human_approval Read 148 0.6%
generate_settlement Write 148 0.6%
aps_verify_attribution_projection Read 147 0.6%
commerce_preflight Execute 146 0.6%
file_data_dispute Read 146 0.6%
create_v2_delegation Write 145 0.6%
vouch_reputation Write 145 0.6%
aps_project_attribution Read 143 0.6%
aps_promote_statement Write 142 0.6%
gateway_process_tool_call Read 139 0.6%
list_tools_for_scope Read 138 0.6%
complete_action Write 138 0.6%
add_principal_report Write 137 0.6%
broadcast Write 136 0.6%
aps_check_artifact_citations Read 135 0.6%
classify_evidence_quality Read 135 0.6%
resolve_authority Write 134 0.6%
compute_action_ref Read 133 0.6%
aps_check_projection_consistency Read 132 0.6%
aps_compute_attribution_action_ref Read 132 0.6%
search_matches Read 131 0.6%
sign_charter Write 131 0.6%
respond_to_intro Read 130 0.6%
validate_temporal_rights Read 129 0.6%
create_policy_context Write 129 0.6%
get_passport_grade Read 126 0.5%
revoke_delegation Destructive 122 0.5%
check_retention_expired Read 122 0.5%
gateway_approve Write 122 0.5%
aps_sign_attribution_consent Read 121 0.5%
check_purpose_permitted Read 120 0.5%
declare_reidentification_risk Read 120 0.5%
verify_governance_block Read 119 0.5%
detect_purpose_drift Read 117 0.5%
aps_verify_attribution_primitive Read 115 0.5%
identify Read 112 0.5%
add_approval_signature Write 111 0.5%
complete_task Write 111 0.5%
create_gateway Write 111 0.5%
aps_verify_promotion Read 108 0.5%
activate_emergency Write 108 0.5%
register_agora_agent Write 106 0.5%
get_commerce_spend Read 105 0.5%
is_key_active Read 104 0.4%
query_contributions Read 104 0.4%
revoke_endorsement Destructive 102 0.4%
create_hybrid_timestamp Write 102 0.4%
get_behavioral_sequence Read 101 0.4%
create_disclosure Write 101 0.4%
check_usage_permitted Read 100 0.4%
create_data_enforcement_gate Write 100 0.4%
resolve_lineage Write 99 0.4%
resolve_path_terms Write 99 0.4%
check_messages Read 98 0.4%
compute_governance_taint Read 98 0.4%
attest_to_floor Read 97 0.4%
verify_aps_txt Read 95 0.4%
aps_verify_attribution_consent Read 94 0.4%
resolve_rights_propagation Write 88 0.4%
aps_attribution_receipt_id Read 84 0.4%
evaluate_revocation_impact Read 84 0.4%
parse_governance_block_html Execute 79 0.3%
get_evidence Read 79 0.3%
verify_charter Read 79 0.3%
remove_intent_card Destructive 78 0.3%
verify_endorsement Read 78 0.3%
verify_rotation_chain Read 78 0.3%
list_agents Read 77 0.3%
accept_assignment Read 74 0.3%
get_task_detail Read 74 0.3%
verify_delegation Read 73 0.3%
get_agora_thread Read 72 0.3%
load_values_floor Read 72 0.3%
list_issuance_records Read 69 0.3%
get_digest Read 68 0.3%
get_agora_by_topic Read 66 0.3%
gateway_stats Read 58 0.2%
list_profiles Read 58 0.2%
get_my_role Read 49 0.2%
get_agora_topics Read 48 0.2%
get_fleet_status Read 48 0.2%
get_promotion_history Read 46 0.2%
generate_keys Write 46 0.2%
list_tasks Read 43 0.2%

Most agents use a handful of these tools. They pay for all 150.

A PolicyLayer grant exposes only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. Estimates below assume typical-weight tools (155 tokens each).

Grant scopeDefinition costReduction
All 150 tools (no gateway) 23,268 tokens
3 granted tools ~465 tokens −98%
5 granted tools ~776 tokens −97%
10 granted tools ~1,551 tokens −93%

Agent Passport System — Cryptographic Identity for AI Agents token-cost questions.

How many tokens does the Agent Passport System — Cryptographic Identity for AI Agents MCP server use?+

Its 150 tool definitions total 23,268 tokens — 12% of a 200k context window — measured with tiktoken o200k_base over the serialised tools/list payload. Exact counts vary slightly by client and model.

Why does Agent Passport System — Cryptographic Identity for AI Agents consume tokens before I send a message?+

MCP clients load every connected server's tool definitions — name, description, and input schema — into the model's context so it knows what it can call. That payload is charged against your context window on every request, whether or not a tool is used.

How do I reduce Agent Passport System — Cryptographic Identity for AI Agents's token usage?+

Expose fewer tools. A PolicyLayer grant scopes Agent Passport System — Cryptographic Identity for AI Agents to only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. A grant of 3 typical tools costs roughly 465 tokens, a 98% reduction.

Does deferred tool loading fix this?+

Partially, in some clients. Claude Code defers MCP tool schemas behind a tool-search step by default, and VS Code has experimental grouping — but you still pay tokens per search and reload, and Cursor, Windsurf and Gemini CLI load definitions upfront. Reducing the exposed tool set cuts the cost in every client.

How these numbers were measured.

01
Serialisation

Each tool is serialised as a tools/list entry — name, description, input schema — from the schemas in the PolicyLayer scan database. Clients differ slightly in framing, so treat counts as close estimates.

02
Tokeniser

tiktoken o200k_base (GPT-4o/o-series). Anthropic's current tokeniser isn't published, so Claude's exact counts will differ; for English text and JSON schemas the totals are close enough to treat these as estimates.

03
Deferred loading

Some clients now defer schema loading (Claude Code's tool search; VS Code experimental grouping). You still pay per search and reload — and Cursor, Windsurf and Gemini CLI load everything upfront.

Computed 07-06-2026 from the PolicyLayer scan database over all 150 catalogued Agent Passport System — Cryptographic Identity for AI Agents tools. Counts refresh with every site build.

Expose only the tools you use — the rest never enter your context.

A PolicyLayer grant scopes Agent Passport System — Cryptographic Identity for AI Agents to the tools you actually allow. Ungranted definitions never load, and every call that does run is checked against policy first.

Free to start. No card required.

4,600+ MCP servers and 31,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.