
Gate Authority Network
io.github.Projetxanav0.1.0-dev.4Updated Oct 5, 2026
Live authority-state verification for agent actions at effect time.
Overview
GATE verifies at action time whether an agent still has a live authority path from a principal, returning ALLOW, DENY, or UNKNOWN.
- What it does
- GATE is an experimental network verifier for live, cross-domain authority state. It consumes authority state from external domains and answers whether a currently valid authority path still exists when an action is about to take effect. It returns VALID/ALLOW, INVALID/DENY, or UNKNOWN/DENY, and supports bounded and strict consistency contracts with caller-defined maximum staleness. It is not a policy engine and does not replace OAuth or existing authorization systems.
- When to use it
- Consider it when an agent workflow needs a live check that a principal's authority has not been revoked or changed before a sensitive action runs, especially across domains where a local signature and expiry check is not enough. It is a developer preview, so it suits evaluation and prototyping rather than production enforcement.
- Requirements
- Runs locally over stdio as the npm package @gate-avn/mcp, requiring Node.js 20 or newer. The GATE_URL environment variable is required for the edge endpoint, and the optional GATE_API_KEY secret supplies a bearer token. Network access to the GATE edge is needed.
Installation
In SourceWeft
- Open Gate Authority Network in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
GATE — Authority Verification Network
Developer Preview · 2026-10-02
Is this agent still authorized to act right now?
GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.
5-minute demo
Requirements: Node.js 20+.
The demo calls the public SDK shape:
What GATE verifies
GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.
It can return:
VALID / ALLOW— at least one live authority path exists.INVALID / DENY— the known paths are revoked/invalid.UNKNOWN / DENY— freshness or availability is insufficient for the requested consistency contract.
What GATE does not do
GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.
GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.
Why a network service?
A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.
Consistency contracts
bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.
Repository map
Install
SDK
Current SDK Developer Preview: 0.1.0-dev.2
MCP server
Current MCP Developer Preview: 0.1.0-dev.4
Official MCP Registry:
Status
GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.
The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.
This remains experimental Developer Preview software and is not production-ready.
Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.
License
Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.
Source: README.md at commit c2532f8
Tools
0Version history
1- v0.1.0-dev.4LatestOct 5, 2026


