
Pranaxis Mcp Gateway
io.github.Anaciberv0.3.1Updated Oct 8, 2026
Consistency verdicts for MCP tool calls: no two agents consume the same resource version twice.
Overview
A local stdio proxy that arbitrates MCP tool calls which consume a shared resource, denying duplicate consumption with a certificate.
- What it does
- Pranaxis MCP Gateway sits between an MCP client and an MCP server as a transparent stdio proxy. Read-only calls pass through untouched, while calls that consume a shared resource (launching a run, paying an order, writing a file at a given version, updating a row) are arbitrated first. If another agent already holds that resource version, the call never reaches the tool and the agent receives a readable error with a certificate. Tool descriptions are annotated so the agent knows writes are arbitrated, and every verdict is appended to a JSONL log.
- When to use it
- Use it when several agents share one MCP server and could consume the same resource version twice, such as concurrent writes to a repository file or updates to a database row. It is meant to prevent the lost-update problem in multi-agent setups, where each agent acts inside its own policy.
- Requirements
- Runs locally as a Python package (pip install pranaxis-mcp-gateway, or uvx pranaxis-mcp-gateway) over stdio. Register the gateway in the MCP client instead of the server, with the server as the child command, and give each agent its own --agent-id. Rules are JSON files; bundled rules cover vivado-ross, github-official and postgres-generic. The optional physical verifier needs a separate hardware product and a --fam-endpoint host:port.
Installation
In SourceWeft
- Open Pranaxis Mcp Gateway in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Pranaxis MCP Gateway
Consistency verdicts for MCP tool calls. A transparent stdio proxy that sits between any MCP client (Claude Code, Cursor, Codex, custom agents) and any MCP server. Reads pass through untouched. Calls that consume a shared resource (launch a run, pay an order, write a file at a given sha, update a row) are arbitrated first: if another agent already holds that resource version, the call never reaches the tool and the agent gets a readable error with a certificate.
It solves the lost update of multi-agent systems: two agents, each inside its own policy, consuming the same thing twice.
Install
Use
Register the gateway in your MCP client instead of the server, with the server as the child command. One gateway per agent,
each with its own --agent-id; all gateways on a machine share the version state. Claude Code example, AMD Ross Vivado server:
GitHub MCP server:
A denied call returns isError: true with a message like:
Tool descriptions are annotated so the agent knows writes are arbitrated. In our tests, agents (two different models) did not retry blindly after a denial: they read the state and chose another action.
Rules: what counts as consumption
Rules are data, one JSON file per MCP server (src/pranaxis_gateway/rules/). Each rule names the tool, matches arguments
with regexes (named groups become fields), builds the resource name from a template, and optionally takes the version from
an argument (e.g. GitHub's previous blob sha). release rules say which responses show a resource complete.
A completed resource stays with its holder until the holder makes its next call (it collected the result) or a grace period
expires (--grace, default 600 s): nobody wipes someone else's result before they read it.
Bundled: vivado-ross (AMD Ross Vivado MCP server), github-official, postgres-generic. Calls matching no rule pass
through and are logged as passthrough. Contributions of rules for other servers are welcome.
Verifiers
--verifier stub(default): software reference. Holders shared through the state file; verdicts carry no physical measurement.--verifier fam --fam-endpoint host:port: the Pranaxis physical verifier, a ring-oscillator block on an AMD Zynq UltraScale+ / Kria device that measures the arbitration and returns a certificate with sieve, frequencies, tolerance and timing. The hardware is a separate product (https://pranaxis.eu); this repository contains only the gateway and the HTTP contract it speaks.
Certificates
Every verdict is appended to ross_demo_YYYYMMDD.jsonl (name configurable with --log-file): agent, resource, version, decision,
reason, conflicting request, certificate id, measurement data when physical, proxy latency. Read-only calls are logged as passthrough.
Tests
Status and roadmap
0.3: local mode (one proxy per agent, stdio), declarative rules, holder release / grace, jsonl log. Measured with the physical verifier on a ZUBoard 1CG (10/10 preregistered runs) and with two real agents on AMD Ross. Next: central mode (one network gateway for all agents, audit API), embedded mode on Kria K26.
Intellectual property and licence
Code: Apache-2.0. The arbitration procedure and the physical device are covered by Spanish patent applications P202631184 and P202631345 (Arignatxa S.L. as licensee); using this gateway with the software verifier is free; the physical verifier bitstream is not part of this repository. "Pranaxis" is a trademark application (M4406608).
Source: README.md at commit 88fb87e
Tools
0Version history
1- v0.3.1LatestOct 8, 2026


