Back to Browse

Gate Authority Network MCP Server

Developer ToolsLow Risk9.7MCP RegistryLocal
Free

Server data from the Official MCP Registry

Live authority-state verification for agent actions at effect time.

About

Live authority-state verification for agent actions at effect time.

Security Report

9.7
Low Risk9.7Low Risk

Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

13 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

GATE edge URLOptional

Environment variable: GATE_URL

Optional GATE API bearer tokenRequired

Environment variable: GATE_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-projetxana-gate-authority-network": {
      "env": {
        "GATE_URL": "your-gate-url-here",
        "GATE_API_KEY": "your-gate-api-key-here"
      },
      "args": [
        "-y",
        "@gate-avn/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

GATE — Authority Verification Network

Developer Preview · 2026-10-02

Is this agent still authorized to act right now?

GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.

5-minute demo

Requirements: Node.js 20+.

npm install
npm test
npm run demo

The demo calls the public SDK shape:

import { GateClient } from './packages/sdk/dist/index.js';

const gate = new GateClient({ endpoint: process.env.GATE_URL });

const result = await gate.verify({
  principal: 'user:jerome',
  actor: 'agent:C@company-c',
  action: {
    protocol: 'mcp',
    name: 'delete_customer_data',
    resource: 'customer:3456'
  },
  consistency: 'bounded',
  maxStalenessMs: 200
});

if (result.decision !== 'ALLOW') throw new Error(result.reason);

What GATE verifies

GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.

It can return:

  • VALID / ALLOW — at least one live authority path exists.
  • INVALID / DENY — the known paths are revoked/invalid.
  • UNKNOWN / DENY — freshness or availability is insufficient for the requested consistency contract.

What GATE does not do

GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.

GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.

Why a network service?

A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.

Consistency contracts

  • bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.
  • strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.

Repository map

packages/sdk/      public developer-facing client
examples/          minimal SDK demonstration
services/          experimental control plane / edge / trust services
src/               PoC verification primitives
mcp/               MCP enforcement harness
test/              SDK + distributed consistency tests
docs/              architecture, integration contract, due diligence

Install

SDK

npm install @gate-avn/sdk@dev

Current SDK Developer Preview: 0.1.0-dev.2

MCP server

npm install @gate-avn/mcp@dev

Current MCP Developer Preview: 0.1.0-dev.4

Official MCP Registry:

io.github.Projetxana/gate-authority-network

Status

GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.

The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.

This remains experimental Developer Preview software and is not production-ready.

Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.

License

Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.

Reviews

No reviews yet

Be the first to review this server!