
Pranaxis Mcp Gateway
io.github.Anaciberv0.3.1更新于 Oct 8, 2026
Consistency verdicts for MCP tool calls: no two agents consume the same resource version twice.
概览
一个本地 stdio 代理,对消耗共享资源的 MCP 工具调用进行仲裁,拒绝重复消耗并给出证书。
- 功能
- Pranaxis MCP Gateway 作为透明 stdio 代理位于 MCP 客户端与 MCP 服务器之间。只读调用原样通过,而消耗共享资源的调用(启动一次运行、支付订单、按指定版本写入文件、更新某行数据)会先被仲裁。若另一代理已持有该资源版本,调用不会到达工具,代理会收到带证书的可读错误。工具描述会被标注,使代理知道写入会被仲裁,每次裁决都会追加到 JSONL 日志。
- 适用场景
- 当多个代理共用一个 MCP 服务器、可能重复消耗同一资源版本时使用,例如并发写入仓库文件或更新数据库某行。它用于避免多代理场景中的丢失更新问题,即每个代理各自按自己的策略行事。
- 运行要求
- 以 Python 包在本地通过 stdio 运行(pip install pranaxis-mcp-gateway,或 uvx pranaxis-mcp-gateway)。在 MCP 客户端中注册该网关而非服务器,并把服务器作为子命令,为每个代理指定各自的 --agent-id。规则为 JSON 文件,内置规则覆盖 vivado-ross、github-official 和 postgres-generic。可选的物理验证器需要单独购买的硬件产品和 --fam-endpoint host:port。
安装
在 SourceWeft 中
- 打开 控制台中的 Pranaxis Mcp Gateway,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Pranaxis MCP Gateway
Consistency verdicts for MCP tool calls. A transparent stdio proxy that sits between any MCP client (Claude Code, Cursor, Codex, custom agents) and any MCP server. Reads pass through untouched. Calls that consume a shared resource (launch a run, pay an order, write a file at a given sha, update a row) are arbitrated first: if another agent already holds that resource version, the call never reaches the tool and the agent gets a readable error with a certificate.
It solves the lost update of multi-agent systems: two agents, each inside its own policy, consuming the same thing twice.
Install
Use
Register the gateway in your MCP client instead of the server, with the server as the child command. One gateway per agent,
each with its own --agent-id; all gateways on a machine share the version state. Claude Code example, AMD Ross Vivado server:
GitHub MCP server:
A denied call returns isError: true with a message like:
Tool descriptions are annotated so the agent knows writes are arbitrated. In our tests, agents (two different models) did not retry blindly after a denial: they read the state and chose another action.
Rules: what counts as consumption
Rules are data, one JSON file per MCP server (src/pranaxis_gateway/rules/). Each rule names the tool, matches arguments
with regexes (named groups become fields), builds the resource name from a template, and optionally takes the version from
an argument (e.g. GitHub's previous blob sha). release rules say which responses show a resource complete.
A completed resource stays with its holder until the holder makes its next call (it collected the result) or a grace period
expires (--grace, default 600 s): nobody wipes someone else's result before they read it.
Bundled: vivado-ross (AMD Ross Vivado MCP server), github-official, postgres-generic. Calls matching no rule pass
through and are logged as passthrough. Contributions of rules for other servers are welcome.
Verifiers
--verifier stub(default): software reference. Holders shared through the state file; verdicts carry no physical measurement.--verifier fam --fam-endpoint host:port: the Pranaxis physical verifier, a ring-oscillator block on an AMD Zynq UltraScale+ / Kria device that measures the arbitration and returns a certificate with sieve, frequencies, tolerance and timing. The hardware is a separate product (https://pranaxis.eu); this repository contains only the gateway and the HTTP contract it speaks.
Certificates
Every verdict is appended to ross_demo_YYYYMMDD.jsonl (name configurable with --log-file): agent, resource, version, decision,
reason, conflicting request, certificate id, measurement data when physical, proxy latency. Read-only calls are logged as passthrough.
Tests
Status and roadmap
0.3: local mode (one proxy per agent, stdio), declarative rules, holder release / grace, jsonl log. Measured with the physical verifier on a ZUBoard 1CG (10/10 preregistered runs) and with two real agents on AMD Ross. Next: central mode (one network gateway for all agents, audit API), embedded mode on Kria K26.
Intellectual property and licence
Code: Apache-2.0. The arbitration procedure and the physical device are covered by Spanish patent applications P202631184 and P202631345 (Arignatxa S.L. as licensee); using this gateway with the software verifier is free; the physical verifier bitstream is not part of this repository. "Pranaxis" is a trademark application (M4406608).
来源:README.md,提交 88fb87e
工具
0版本历史
1- v0.3.1最新Oct 8, 2026


