Claude Code gains TLA+ model checking via tla-mcp MCP server

tla-mcp is a Model Context Protocol server that exposes the tla-rs TLA+ model checker as a tool for Claude Code. With it registered, you can validate formal specifications, run bounded model checks, request counterexample traces, and replay specific scenarios — all from inside the AI chat.
What it does
TLA+ is a formal specification language for designing concurrent and distributed systems. The model checker exhaustively explores reachable states to catch invariant violations, deadlocks, and race conditions. tla-mcp translates Claude's requests into checker commands and returns results as structured tool responses.
Tool design philosophy
The tool descriptions are deliberately opinionated about how the LLM should use the checker:
- Budget all limits upfront (bounded checking parameters)
- Treat
limit_reachedas inconclusive — it means the checker ran out of states before completing the search - When analyzing a counterexample trace, look at the last transition first (that's usually where the violation occurs)
These guardrails help the behavior survive context truncation and keep the model from drawing false conclusions from partial results.
Four tools
The server exposes four commands (exact names from the landing page):
- validate — check that a TLA+ spec is syntactically and structurally correct
- bounded_check — run model checking with a fixed depth limit, returns pass/fail or
limit_reached - trace — retrieve a counterexample trace for a failed check
- replay — replay a specific scenario step by step
Getting started
Head to the project page for installation instructions and the Claude Desktop/Code client config snippet. The server is an experiment — feedback and bug reports are welcome.
Who this is for
Developers who use formal methods for distributed systems and want to integrate model checking into their AI-assisted workflow.
📖 Read the full source: r/ClaudeAI
👀 See Also

Local Code Index for Coding Agents: Resolves Imports Without Language Server
Basemind is an MIT-licensed Rust tool that indexes local code and resolves imports without a language server, supporting real resolution for JS/TS, Python, and Java.

GrapeRoot Pro Adds Undo Shield to Prevent Claude Code from Deleting Your Project
After Reddit reports of Claude Code deleting entire projects, GrapeRoot Pro introduces an Undo Shield that watches Claude's session graph and blocks destructive commands like rm -rf on heavily edited files.

dead-letter: Local .eml to .md Converter with CLI, Web UI, and MCP Server
dead-letter normalizes email exports into Markdown with YAML front matter, customisable. It offers four access modes: CLI, Python library, Web UI, and an MCP server for direct integration with Claude Desktop, Claude Code, and Codex.

ClawDeckX: Open-Sourced macOS-Style Web Platform for OpenClaw Agent Management
ClawDeckX is an open-source web platform for installing, configuring, and monitoring OpenClaw agents. It provides visual management tools, real-time monitoring, and supports 13 languages.