Pranaxis Mcp Gateway

io.github.Anaciberv0.3.1Updated Oct 8, 2026

Consistency verdicts for MCP tool calls: no two agents consume the same resource version twice.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

A local stdio proxy that arbitrates MCP tool calls which consume a shared resource, denying duplicate consumption with a certificate.

What it does
Pranaxis MCP Gateway sits between an MCP client and an MCP server as a transparent stdio proxy. Read-only calls pass through untouched, while calls that consume a shared resource (launching a run, paying an order, writing a file at a given version, updating a row) are arbitrated first. If another agent already holds that resource version, the call never reaches the tool and the agent receives a readable error with a certificate. Tool descriptions are annotated so the agent knows writes are arbitrated, and every verdict is appended to a JSONL log.
When to use it
Use it when several agents share one MCP server and could consume the same resource version twice, such as concurrent writes to a repository file or updates to a database row. It is meant to prevent the lost-update problem in multi-agent setups, where each agent acts inside its own policy.
Requirements
Runs locally as a Python package (pip install pranaxis-mcp-gateway, or uvx pranaxis-mcp-gateway) over stdio. Register the gateway in the MCP client instead of the server, with the server as the child command, and give each agent its own --agent-id. Rules are JSON files; bundled rules cover vivado-ross, github-official and postgres-generic. The optional physical verifier needs a separate hardware product and a --fam-endpoint host:port.
Before you install
The gateway sits in the path of tool calls and can block calls it judges to be consuming, so a denied call never reaches the tool. It writes a JSONL log of verdicts (agent, resource, version, decision, reason, conflicting request, certificate id, latency) to a configurable file. A completed resource stays held until the holder's next call or a grace period (default 600 s). The physical verifier is a separate product; this repository contains only the gateway and the HTTP contract.

Installation

In SourceWeft

  1. Open Pranaxis Mcp Gateway in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

Pranaxis MCP Gateway

Consistency verdicts for MCP tool calls. A transparent stdio proxy that sits between any MCP client (Claude Code, Cursor, Codex, custom agents) and any MCP server. Reads pass through untouched. Calls that consume a shared resource (launch a run, pay an order, write a file at a given sha, update a row) are arbitrated first: if another agent already holds that resource version, the call never reaches the tool and the agent gets a readable error with a certificate.

It solves the lost update of multi-agent systems: two agents, each inside its own policy, consuming the same thing twice.

agent ──stdio──▶ pranaxis-mcp ──stdio──▶ your MCP server ──▶ tool                     │                     └── verdict (software, or the Pranaxis chip)

Install

pip install pranaxis-mcp-gateway      # or: uvx pranaxis-mcp-gateway

Use

Register the gateway in your MCP client instead of the server, with the server as the child command. One gateway per agent, each with its own --agent-id; all gateways on a machine share the version state. Claude Code example, AMD Ross Vivado server:

claude mcp add vivado-mcp --scope project --transport stdio --env VIVADO_PATH=/path/to/vivado -- \  pranaxis-mcp --agent-id agent-a --rules vivado-ross -- vivado-mcp-server --stdio-bridge

GitHub MCP server:

pranaxis-mcp --agent-id agent-a --rules github-official -- npx -y @modelcontextprotocol/server-github

A denied call returns isError: true with a message like:

DENIED by the Pranaxis consistency verifier.Resource 'owner/repo/main/README.md' version abc123 is being consumed by another agent(holder: agent-a; their request: agent-a-3f2c...). Certificate: ...Your call did NOT reach the tool. Do not retry the same write; read the current state and work from it.

Tool descriptions are annotated so the agent knows writes are arbitrated. In our tests, agents (two different models) did not retry blindly after a denial: they read the state and chose another action.

Rules: what counts as consumption

Rules are data, one JSON file per MCP server (src/pranaxis_gateway/rules/). Each rule names the tool, matches arguments with regexes (named groups become fields), builds the resource name from a template, and optionally takes the version from an argument (e.g. GitHub's previous blob sha). release rules say which responses show a resource complete. A completed resource stays with its holder until the holder makes its next call (it collected the result) or a grace period expires (--grace, default 600 s): nobody wipes someone else's result before they read it.

Bundled: vivado-ross (AMD Ross Vivado MCP server), github-official, postgres-generic. Calls matching no rule pass through and are logged as passthrough. Contributions of rules for other servers are welcome.

Verifiers

  • --verifier stub (default): software reference. Holders shared through the state file; verdicts carry no physical measurement.
  • --verifier fam --fam-endpoint host:port: the Pranaxis physical verifier, a ring-oscillator block on an AMD Zynq UltraScale+ / Kria device that measures the arbitration and returns a certificate with sieve, frequencies, tolerance and timing. The hardware is a separate product (https://pranaxis.eu); this repository contains only the gateway and the HTTP contract it speaks.

Certificates

Every verdict is appended to ross_demo_YYYYMMDD.jsonl (name configurable with --log-file): agent, resource, version, decision, reason, conflicting request, certificate id, measurement data when physical, proxy latency. Read-only calls are logged as passthrough.

Tests

python tests/test_two_agents.py --verifier stub        # two agents, Vivado-like server: P1..P4python tests/test_rules_generic.py                      # GitHub and SQL rule files

Status and roadmap

0.3: local mode (one proxy per agent, stdio), declarative rules, holder release / grace, jsonl log. Measured with the physical verifier on a ZUBoard 1CG (10/10 preregistered runs) and with two real agents on AMD Ross. Next: central mode (one network gateway for all agents, audit API), embedded mode on Kria K26.

Intellectual property and licence

Code: Apache-2.0. The arbitration procedure and the physical device are covered by Spanish patent applications P202631184 and P202631345 (Arignatxa S.L. as licensee); using this gateway with the software verifier is free; the physical verifier bitstream is not part of this repository. "Pranaxis" is a trademark application (M4406608).

Source: README.md at commit 88fb87e

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.3.1LatestOct 8, 2026