Governed MCP Gateway
Cubiczan Agent Platform
Identität, Geld und Nachweise für Agents, die tatsächlich liefern.
Drei SKUs, ein Workspace. MCP-Clients behalten ein Bearer-Prinzipal durch tools/call und SSE. Ausgaben können ohne Mandat und, über dem Limit, ohne einen zweiten menschlichen Schlüssel nicht abgerechnet werden. Board-Claims können ohne Agent, CHP-Sperre und gehashtes Dokument nicht versiegelt werden.

SKU | Port | Repo | Job |
| Prinzipal bei jedem Tool-Aufruf und SSE-Frame. Vault-basierte Credential-Rotation. Tool-Allowlists. | ||
| Vorschlagen → Mandat → Gegenzeichnung → Abrechnung. Stripe standardmäßig; x402 ist ein Rail. | ||
| Claim → Agent → Sperre → Dokument. ASC-842-/606-/718-Engines. HMAC-verkettetes Evidence-Pack. |
Gemeinsame Primitive (packages/shared): CHP-Gate, HMAC-Ledger, HTTP/SSE-Helfer. Null npm-Laufzeitabhängigkeiten. Stripe und x402 sind Rails – Tests rufen niemals Live-Netzwerke auf.
Schnellstart
npm install
npm test
npm run gateway # :7474
npm run spend # :7475
npm run cfo # :7476Demo-Bearer-Keys (auch in .env.example):
Rolle | Key |
Gateway-Agent |
|
Gateway-Mensch |
|
Gateway-Recherche (kein |
|
Spend-Agent |
|
Spend-Mensch |
|
CFO-Agent |
|
CFO-Mensch |
|
README-Karten aus den lokalen Live-APIs neu generieren:
npm run shotsRelated MCP server: governed-mcp-gateway
1. Governed MCP Gateway
Produktions-MCP verwirft Identität. listTools läuft im Request-Thread; tools/call und SSE laufen woanders. Dieses Gateway löst eine Bearer-Credential zu einem Prinzipal auf, injiziert es bei jedem JSON-RPC-Aufruf und wiederholt es bei jedem SSE-Frame. Benannte Vault-Inputs rotieren an Ort und Stelle – github_token bleibt github_token.



curl -sS -H "Authorization: Bearer mcp_agt_payops_demo" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"echo.ping","arguments":{"hello":"world"}}}' \
http://127.0.0.1:7474/mcpMethode | Pfad | Was |
|
| JSON-RPC |
|
| SSE-Benachrichtigung mit |
|
| Nur-menschliche Vault-Rotation; alter Hash stirbt |
|
| Ein Secret gegen den aktuellen Hash prüfen |
2. Agent Spend & Mandate Plane
Agents schlagen vor. Mandate autorisieren. Ein Mensch zeichnet gegen, wenn der Betrag über dem Auto-Limit liegt. Der vorschlagende Agent kann nicht selbst gegenzeichnen. Abrechnung ist ein Rail: Stripe-Meter-Event standardmäßig, x402 payment-required auf Wunsch. Keine Chain-Aufrufe in diesem MVP.



curl -sS -H "Authorization: Bearer spend_agt_payops_demo" \
-H "Content-Type: application/json" \
-d '{"agent":"agt_payops","merchant":{"name":"Stripe","url":"https://stripe.com","country":"US"},"total":"12.00","rationale":"tool meter"}' \
http://127.0.0.1:7475/v1/proposalsMethode | Pfad | Was |
|
| Operator erstellt Abdeckung für Restcents |
|
| Agent schlägt vor; Lane |
|
| Menschlicher zweiter Schlüssel; Agents werden abgelehnt |
|
|
|
3. Auditable CFO Agent Mesh
Ein Board-Claim ist erst abgeschlossen, wenn er einen Agent, einen LOCKED-CHP-Zustand und mindestens einen Quell-Dokument-Hash hat. Engines messen (ASC-842-Lease-Rollforward, ASC-606-beschränkter POC, ASC-718-SBC). Sie entscheiden keine Rechtsfragen. Token-Ausgaben werden als Quelle im selben HMAC-verketteten Ledger angehängt.



curl -sS -H "Authorization: Bearer cfo_agt_lease_demo" \
-H "Content-Type: application/json" \
-d '{"title":"AI spend is $12.00 this period","narrative":"Token ledger supports the board claim.","agentId":"agt_lease"}' \
http://127.0.0.1:7476/v1/claimsMethode | Pfad | Was |
|
| Einen Claim öffnen |
|
| Benannte Quelle anhängen; SHA-256 gespeichert |
|
| Menschliche Sperre → |
|
| ASC-842-Klassifizierung + Rollforward |
|
| Versiegeln; |
Spezifikationen
OpenSpec-Änderung: openspec/changes/ship-three-sku-platform/.
Lizenz
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
- FullmaktOAuthai.fullmakt
Credential broker for AI agents: scoped, revocable API access with policy enforcement and audit.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Runtime permission, approval, and audit layer for AI agent tool execution.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.1-
- AlicenseAqualityBmaintenanceThis MCP server preserves a Bearer principal on every tool call and SSE frame, rotates vaulted credentials in place, and enforces per-tool allowlists for agents.3MIT
- AlicenseNot gradedqualityCmaintenanceEnables secure support-ticket and customer-account operations with signed JWT authentication, prompt-injection and tool-poisoning guardrails, and human-in-the-loop confirmation for destructive actions.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to securely invoke tools by enforcing identity proof, capability verification, and risk scoring on every request, blocking unsafe calls before they execute.MIT