Chron
About
AI tools show when you sent a message. Chron logs when the AI responded too — and keeps a permanent, queryable record of every exchange across every tool you use. Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool. Every exchange is stored wi
Details
- Author
- SirinivasK
- Downloads
- 272
- Categories
- Developer Tools
Jump to
- Logs user and assistant timestamps with timezone offset
- Stores audit trail in a local SQLite file you own
- Tamper-evident SHA-256 hash chaining
- Companion skill file for automatic logging
- HTTP+SSE mode for remote/team usage
- Works with any MCP-compatible AI tool
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
ChronCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Add the server to your AI tool’s MCP configuration by setting command to npx and args to ["-y", "chron-mcp"]. First run automatically creates ~/.chron/chron.db. For Claude Code, additionally install the companion skill hook to enable automatic session logging. Run as HTTP+SSE for team/self-hosted use by setting CHRON_TRANSPORT=http.
init_session
Initialize or resume an audit session. Returns session_id, message_count, first_message_at, and recent messages in a single call — use this instead of calling start_session + get_session_history separately.
start_session
Create a new audit session or resume an existing one by title. Call this at the start of every conversation.
log_message
Record a single message (user or assistant) with the current local datetime and timezone offset. Call before responding for user messages, and before sending for assistant messages.
log_tool_call
Record an AI tool invocation as a first-class audit event (event_type=tool_call). Call immediately before executing a tool. Returns tool_call_id to pass to log_tool_result.
log_tool_result
Record the result of a tool call as a first-class audit event (event_type=tool_result). Call immediately after receiving tool output. Links back to log_tool_call via tool_call_id.
log_code_change
Record a file edit as a first-class audit event (event_type=code_change). Call after every Edit or Write tool call with the unified diff. Diff content is included in the hash chain.
log_exchange
Record a user+assistant exchange from historical or batch imports only. Do NOT use for live conversations — both timestamps are captured at the same instant with no real gap. For live sessions always call log_message twice: once for the user message, once for the assistant response.
list_sessions
List all audit sessions ordered by most recently active. Returns id, title, ai_tool, message_count, created_at, updated_at.
get_session_history
Retrieve the full timestamped audit log for a session, oldest first.
verify_session
Verify the tamper-evident hash chain for a session. Returns valid=true if no rows were edited after logging, or the first broken link if tampering is detected.
scan_prompt
Scan a prompt for secrets and sensitive data before sending to any AI. Returns detected secrets, a redacted version with tokens, and a token_map to restore the real values after the AI responds.
delete_session
Permanently delete a session and all its messages. Cascades to secrets_detected. Returns deleted=true or deleted=false if not found.
search_sessions
Full-text search across all logged AI conversations. Returns matching sessions with excerpts. Uses SQLite FTS5 with porter stemming — supports phrases ("exact match"), boolean (term1 OR term2), and prefix (migrat*).
summarize_session
Return a structured summary of a session: timeline with latencies, mutations detected, secrets touched, and possible prod-account references. Useful for compliance review and change-control evidence.
rehydrate_response
Restore real secret values into an AI response that contains $CHRON_* tokens. Pass the token_map returned by scan_prompt.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"chron": {
"chron": {
"command": "npx",
"args": [
"-y",
"chron-mcp"
]
}
}
}
}
McpServers
{
"chron": {
"command": "npx",
"args": [
"-y",
"chron-mcp"
]
}
}
<div align="center">
![]()
<h1>Chron</h1>
<p>A timestamped audit trail for every AI conversation — stored locally, owned by you.</p>
</div>
AI tools show when you sent a message. Chron logs when the AI responded too — and keeps a permanent, queryable record of every exchange across every tool you use.
Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool.
---
Why
AI tools produce no audit trail by default. You cannot answer:
- What did the AI say, and when exactly?
- How long did the AI take to respond?
- What was the full conversation that produced this output?
- What did I ask Claude last week about this codebase?
Chron fixes that. Every exchange is logged with a precise local datetime (including timezone offset) to a SQLite file you own. No cloud, no vendor lock-in, no data leaving your machine.
---
Install
Add to your AI tool's MCP config:
{
"mcpServers": {
"chron": {
"command": "npx",
"args": ["-y", "chron-mcp"]
}
}
}
First run creates ~/.chron/chron.db automatically. No database setup, no env vars, no migrations.
---
What it logs
Every exchange is recorded with precise local timestamps — user message when received, assistant response when sent:
[user: 2026-05-08 14:32:11 +02:00 | assistant: 2026-05-08 14:32:43 +02:00]
The main risks of deploying this contract are...
The gap between user and assistant timestamps is real generation time. Both are stored in your local SQLite DB with full timezone offset.
---
Config by tool
Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"chron": {
"command": "npx",
"args": ["-y", "chron-mcp"]
}
}
}
Claude Code
claude mcp add chron -- npx -y chron-mcp
Then add the skill hook to ~/.claude/settings.json:
{
"hooks": {
"SessionStart": [
{
"hooks": [
{
"type": "command",
"command": "cat ~/.chron/chron.skill.md"
}
]
}
]
}
}
Cursor
Edit ~/.cursor/mcp.json:
{
"mcpServers": {
"chron": {
"command": "npx",
"args": ["-y", "chron-mcp"]
}
}
}
Windsurf
Edit ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"chron": {
"command": "npx",
"args": ["-y", "chron-mcp"]
}
}
}
---
Companion skill file
Chron ships with skills/chron.skill.md — a plain-text instruction file that tells the AI how to use the MCP tools automatically. Load it into your AI tool once. After that, the AI:
1. Creates or resumes a named session at the start of every conversation
2. Logs your message before it starts responding (captures the real user timestamp)
3. Logs its response after composing it (captures the real assistant timestamp)
4. Shows [user: YYYY-MM-DD HH:MM:SS ±HH:MM | assistant: YYYY-MM-DD HH:MM:SS ±HH:MM] at the top of every response
5. Retrieves prior session history so context is never lost across conversations
---
MCP Tools
| Tool | Description |
|---|---|
| start_session | Create or resume a named audit session |
| log_message | Record a single message with the current local datetime |
| log_exchange | Log a user/assistant pair atomically (for batch imports) |
| list_sessions | List all sessions ordered by most recently active |
| get_session_history | Retrieve the full timestamped log for a session |
| verify_session | Verify the tamper-evident hash chain — detects any post-log edits |
---
Tamper-evident hash chaining
Every message is linked to the previous one via a SHA-256 chain:
content_hash = SHA256(session_id | role | content | created_at | prev_hash)
verify_session walks the chain and returns:
- valid: true — no messages were modified after logging
- valid: false, first_break: <id> — exact row ID of the first tampered message
This turns your local log into a verifiable audit artifact. Any edit to a stored message — content, timestamp, or role — breaks the chain and is detected immediately.
---
Configuration
| Env var | Default | Description |
|---|---|---|
| CHRON_DB_PATH | ~/.chron/chron.db | Path to SQLite database file |
| CHRON_TRANSPORT | stdio | Set to http to enable HTTP+SSE mode |
| CHRON_API_KEY | _(none)_ | Bearer token for HTTP mode |
| PORT | 3001 | Port for HTTP mode |
---
HTTP+SSE mode (team / self-hosted)
For teams or remote use, run Chron as an HTTP server:
CHRON_TRANSPORT=http CHRON_API_KEY=your-key PORT=3001 npx chron-mcp
Point your MCP config at the URL:
{
"mcpServers": {
"chron": {
"url": "https://your-server/mcp",
"headers": {
"Authorization": "Bearer your-key"
}
}
}
}
---
Your data
Your audit log lives at ~/.chron/chron.db — a single SQLite file on your machine. Query it directly with any SQLite tool:
sqlite3 ~/.chron/chron.db \
"SELECT s.title, m.role, m.content, m.created_at
FROM messages m JOIN sessions s ON s.id = m.session_id
ORDER BY m.created_at"
No cloud, no telemetry, no data leaving your machine. Change the location with CHRON_DB_PATH.
---
License
Copyright (c) 2026 Nivaya. All rights reserved.
Source code is public for transparency only. Cloning, forking, modification, and redistribution are not permitted without explicit written permission. See LICENSE for full terms.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





