Gate Authority Network

io.github.Projetxanav0.1.0-dev.4Updated Oct 5, 2026

Live authority-state verification for agent actions at effect time.

VerifiedSTDIODesktop onlyAI & MLSecurity & Monitoring

Overview

AI-generated overview

GATE verifies at action time whether an agent still has a live authority path from a principal, returning ALLOW, DENY, or UNKNOWN.

What it does
GATE is an experimental network verifier for live, cross-domain authority state. It consumes authority state from external domains and answers whether a currently valid authority path still exists when an action is about to take effect. It returns VALID/ALLOW, INVALID/DENY, or UNKNOWN/DENY, and supports bounded and strict consistency contracts with caller-defined maximum staleness. It is not a policy engine and does not replace OAuth or existing authorization systems.
When to use it
Consider it when an agent workflow needs a live check that a principal's authority has not been revoked or changed before a sensitive action runs, especially across domains where a local signature and expiry check is not enough. It is a developer preview, so it suits evaluation and prototyping rather than production enforcement.
Requirements
Runs locally over stdio as the npm package @gate-avn/mcp, requiring Node.js 20 or newer. The GATE_URL environment variable is required for the edge endpoint, and the optional GATE_API_KEY secret supplies a bearer token. Network access to the GATE edge is needed.
Before you install
The server is experimental developer-preview software and is not production ready. It sends principal, actor, and action details to an external GATE edge service, so consider what that exposes. The optional GATE_API_KEY bearer token is a credential and should be handled as a secret. A DENY or UNKNOWN result is meant to fail closed, so plan how your workflow reacts.

Installation

In SourceWeft

  1. Open Gate Authority Network in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

GATE — Authority Verification Network

Developer Preview · 2026-10-02

Is this agent still authorized to act right now?

GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.

5-minute demo

Requirements: Node.js 20+.

bash
npm installnpm testnpm run demo

The demo calls the public SDK shape:

js
import { GateClient } from './packages/sdk/dist/index.js';
const gate = new GateClient({ endpoint: process.env.GATE_URL });
const result = await gate.verify({  principal: 'user:jerome',  actor: 'agent:C@company-c',  action: {    protocol: 'mcp',    name: 'delete_customer_data',    resource: 'customer:3456'  },  consistency: 'bounded',  maxStalenessMs: 200});
if (result.decision !== 'ALLOW') throw new Error(result.reason);

What GATE verifies

GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.

It can return:

  • VALID / ALLOW — at least one live authority path exists.
  • INVALID / DENY — the known paths are revoked/invalid.
  • UNKNOWN / DENY — freshness or availability is insufficient for the requested consistency contract.

What GATE does not do

GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.

GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.

Why a network service?

A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.

Consistency contracts

  • bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.
  • strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.

Repository map

text
packages/sdk/      public developer-facing clientexamples/          minimal SDK demonstrationservices/          experimental control plane / edge / trust servicessrc/               PoC verification primitivesmcp/               MCP enforcement harnesstest/              SDK + distributed consistency testsdocs/              architecture, integration contract, due diligence

Install

SDK

bash
npm install @gate-avn/sdk@dev

Current SDK Developer Preview: 0.1.0-dev.2

MCP server

bash
npm install @gate-avn/mcp@dev

Current MCP Developer Preview: 0.1.0-dev.4

Official MCP Registry:

text
io.github.Projetxana/gate-authority-network

Status

GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.

The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.

This remains experimental Developer Preview software and is not production-ready.

Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.

License

Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.

Source: README.md at commit c2532f8

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0-dev.4LatestOct 5, 2026