Command Palette

Search for a command to run...

UnylyUnyly
Browse all

Governed Gateway

FreeMaintained

Enforces authenticated identity on every tool call and SSE frame, rotates vaulted credentials in place, and restricts tools via allowlists.

GitHubEmbed

About

Enforces authenticated identity on every tool call and SSE frame, rotates vaulted credentials in place, and restricts tools via allowlists.

README

npm MCP Registry License: MIT

HTTP MCP control plane (default port 7474). Principal on every tools/call and every SSE frame — not a tool catalog.

Production MCP auth often dies when work hops threads or workers. This gateway resolves a Bearer credential to a Principal, injects it into params._meta.cubiczan.principal, repeats it on SSE, enforces allowlists, rotates vaulted secrets in place, and runs a lightweight CHP spend gate before priced tools.

Install / run

npm i -g @cubiczan/governed-mcp-gateway   # or use npx
npx -y @cubiczan/governed-mcp-gateway
# → http://127.0.0.1:7474

From source:

npm install
npm run build
npm start
npm test

Cursor / Claude config

Start the gateway in a terminal (or a process manager), then point the client at the HTTP MCP endpoints:

{
  "mcpServers": {
    "governed-gateway": {
      "url": "http://127.0.0.1:7474/mcp",
      "headers": {
        "Authorization": "Bearer mcp_agt_payops_demo"
      }
    },
    "chp": {
      "command": "npx",
      "args": ["-y", "@cubiczan/chp-mcp"]
    },
    "conductor": {
      "command": "npx",
      "args": ["-y", "@cubiczan/agent-conductor"]
    }
  }
}

Demo keys: mcp_agt_payops_demo, mcp_agt_research_demo, mcp_human_controller_demo.

Stack

┌─────────────────┐     ┌──────────────────────────┐     ┌────────────────────┐
│ Cursor / Claude │────▶│ governed-mcp-gateway     │────▶│ spend-mandate-plane│
│ (MCP client)    │ SSE │ :7474  principal+vault   │ opt │ :7475              │
└────────┬────────┘     └────────────┬─────────────┘     └────────────────────┘
         │                           │
         │ stdio                     │ CHP gate (embedded)
         ▼                           ▼
┌─────────────────┐     ┌──────────────────────────┐
│ @cubiczan/      │     │ @cubiczan/chp-mcp        │
│ agent-conductor │     │ Profile B spend / HITL   │
└─────────────────┘     └──────────────────────────┘

Sister packages: @cubiczan/chp-mcp, @cubiczan/agent-conductor, consensus-hardening-protocol.

API

Method Path Auth What
GET /health { ok, service }
POST /mcp Bearer JSON-RPC initialize, tools/list, tools/call
GET /mcp/sse Bearer SSE with principal on _meta
POST /v1/credentials Human Put a named secret
POST /v1/credentials/:name/rotate Human New hash, same name
POST /v1/credentials/verify { ok }
POST /v1/locks Human CHP approve / reject
curl -sS -H "Authorization: Bearer mcp_agt_payops_demo" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"echo.ping","arguments":{"hello":"world"}}}' \
  http://127.0.0.1:7474/mcp

Notes

  • This is an HTTP MCP gateway (JSON-RPC + SSE), not a stdio MCP process. The governed-mcp-gateway bin starts the HTTP server.
  • Shared CHP / HTTP / ledger helpers are vendored under src/shared/ (no @cubiczan/shared workspace dep).
  • Optional: set SPEND_PLANE_URL to hook the spend-mandate plane before priced tools.

License

MIT

from github.com/icohangar-ops/governed-mcp-gateway

Installing Governed Gateway

This server has no published package — it is built from source. Open the repository and follow its README.

▸ github.com/icohangar-ops/governed-mcp-gateway

FAQ

Is Governed Gateway MCP free?

Yes, Governed Gateway MCP is free — one-click install via Unyly at no cost.

Does Governed Gateway need an API key?

No, Governed Gateway runs without API keys or environment variables.

Is Governed Gateway hosted or self-hosted?

A hosted option is available: Unyly runs the server in the cloud, no local setup required.

How do I install Governed Gateway in Claude Desktop, Claude Code or Cursor?

Open Governed Gateway on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.

Related MCPs

Compare Governed Gateway with

Not sure what to pick?

Find your stack in 60 seconds

Author?

Embed badge for your README

Browse similar

All development MCPs