Skip to main content
Glama
vaibot-io

@vaibot/mcp-server

Official
by vaibot-io
README.md
# @vaibot/mcp-server

[![npm](https://img.shields.io/npm/v/@vaibot/mcp-server)](https://www.npmjs.com/package/@vaibot/mcp-server)
[![MCP Registry](https://img.shields.io/badge/MCP_Registry-io.github.vaibot--io%2Fmcp--server-blue)](https://registry.modelcontextprotocol.io)

VAIBot governance circuit-breaker as an MCP server.

Exposes 4 tools to any MCP-compatible AI agent (Claude Code, Codex, ChatGPT, OpenClaw):

| Tool | Description |
|---|---|
| `vaibot_decide` | Pre-execution risk + policy decision. Call before any risky action. |
| `vaibot_finalize` | Report actual outcome after execution. Closes the governance receipt. |
| `vaibot_receipts` | List recent governance receipts with optional filters. |
| `vaibot_approve` | Approve or deny a pending action from the dashboard or agent. |

## Quick start

```bash
VAIBOT_API_KEY=vb_live_xxx \
VAIBOT_API_BASE_URL=https://api.vaibot.io \
npx @vaibot/mcp-server
```

## Claude Desktop config

Add to `~/Library/Application Support/Claude/claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "vaibot": {
      "command": "npx",
      "args": ["-y", "@vaibot/mcp-server"],
      "env": {
        "VAIBOT_API_KEY": "vb_live_xxx",
        "VAIBOT_API_BASE_URL": "https://api.vaibot.io"
      }
    }
  }
}
```

## Claude Code / Codex (stdio)

```bash
# .mcp.json in your project root
{
  "mcpServers": {
    "vaibot": {
      "command": "npx",
      "args": ["-y", "@vaibot/mcp-server"],
      "env": {
        "VAIBOT_API_KEY": "vb_live_xxx"
      }
    }
  }
}
```

## OpenClaw gateway plugin (coming in Phase 6 final)

The `vaibot-guard-bridge` plugin will point `guardBaseUrl` at the MCP server endpoint instead of `localhost:39111`. Config change only — no plugin code changes needed.

## Remote URL transport (HTTP)

If your agent supports MCP over HTTP (Remote URL mode), connect directly to the VAIBot API without installing anything:

```
URL:   https://api.vaibot.io/v2/mcp
Token: Bearer <your-api-key>
```

The HTTP endpoint speaks JSON-RPC 2.0 and supports all 4 tools. Auth is the same API key as the stdio transport.

---

## Environment variables

| Variable | Required | Default | Description |
|---|---|---|---|
| `VAIBOT_API_KEY` | ✅ | — | VAIBot API key (`vb_stg_xxx` or `vb_live_xxx`) |
| `VAIBOT_API_BASE_URL` | — | `https://api.vaibot.io` | API base URL |

## Governance flow

```
Agent wants to run: curl -X POST https://deploy.example.com/release

1. Agent calls vaibot_decide:
   → VAIBot: APPROVAL_REQUIRED (high risk — outbound network call)
   → Returns: run_id, content_hash

2. Human reviews in dashboard, clicks Approve

3. Agent calls vaibot_approve (or dashboard fires callback):
   → VAIBot: ✅ APPROVED

4. Agent executes the action

5. Agent calls vaibot_finalize:
   → VAIBot: receipt updated, outcome=allowed
```

TDQS

A4.3/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a distinct role in the governance workflow: decide pre-checks actions, finalize reports outcomes, receipts lists history, and approve handles pending decisions. There is no overlap or ambiguity between them.

Naming Consistency4/5

All tools share the 'vaibot_' prefix and mostly use verb-based naming (decide, finalize, approve). 'receipts' is a noun rather than a verb, deviating slightly from the action-oriented pattern, but the prefix and clear purpose keep it readable.

Tool Count5/5

Four tools provide a well-scoped governance surface: pre-check, post-report, list, and approve. This is neither too thin nor excessive for the stated purpose.

Completeness5/5

The workflow is fully covered: initiate with decide, execute, finalize with the run_id, review via receipts, and handle pending approvals with approve. There are no obvious missing operations for the governance domain.

Maintenance

ActivityInactive
ResponsivenessNo issues