Gate Authority Network

io.github.Projetxanav0.1.0-dev.4更新于 Oct 5, 2026

Live authority-state verification for agent actions at effect time.

已验证STDIO仅桌面AI & MLSecurity & Monitoring

概览

AI 生成的概览

GATE 在动作发生时验证代理是否仍拥有来自主体的有效授权路径,并返回 ALLOW、DENY 或 UNKNOWN。

功能
GATE 是一个实验性的网络验证器,用于实时、跨域的授权状态。它从外部域获取授权状态,并在动作即将生效时回答是否仍存在当前有效的授权路径。它返回 VALID/ALLOW、INVALID/DENY 或 UNKNOWN/DENY,并支持 bounded 与 strict 两种一致性契约,最大陈旧时间由调用方指定。它不是策略引擎,也不替代 OAuth 或现有授权系统。
适用场景
当代理工作流需要在执行敏感操作前实时确认主体的授权未被撤销或变更时可以考虑使用,尤其是在本地签名与过期检查不足的跨域场景。它属于开发者预览版,适合评估和原型验证,而非生产环境的强制管控。
运行要求
以 npm 包 @gate-avn/mcp 通过 stdio 在本地运行,需要 Node.js 20 或更高版本。必须设置 GATE_URL 环境变量指向边缘端点,可选的 GATE_API_KEY 密钥提供 bearer 令牌。需要能访问 GATE 边缘服务的网络。
安装前请注意
该服务器是实验性开发者预览软件,尚未达到生产可用。它会把主体、执行者和动作详情发送到外部 GATE 边缘服务,请评估由此暴露的信息。可选的 GATE_API_KEY bearer 令牌属于凭据,应按机密处理。DENY 或 UNKNOWN 结果按失败关闭处理,需预先规划工作流的应对方式。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Gate Authority Network,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

GATE — Authority Verification Network

Developer Preview · 2026-10-02

Is this agent still authorized to act right now?

GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.

5-minute demo

Requirements: Node.js 20+.

bash
npm installnpm testnpm run demo

The demo calls the public SDK shape:

js
import { GateClient } from './packages/sdk/dist/index.js';
const gate = new GateClient({ endpoint: process.env.GATE_URL });
const result = await gate.verify({  principal: 'user:jerome',  actor: 'agent:C@company-c',  action: {    protocol: 'mcp',    name: 'delete_customer_data',    resource: 'customer:3456'  },  consistency: 'bounded',  maxStalenessMs: 200});
if (result.decision !== 'ALLOW') throw new Error(result.reason);

What GATE verifies

GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.

It can return:

  • VALID / ALLOW — at least one live authority path exists.
  • INVALID / DENY — the known paths are revoked/invalid.
  • UNKNOWN / DENY — freshness or availability is insufficient for the requested consistency contract.

What GATE does not do

GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.

GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.

Why a network service?

A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.

Consistency contracts

  • bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.
  • strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.

Repository map

text
packages/sdk/      public developer-facing clientexamples/          minimal SDK demonstrationservices/          experimental control plane / edge / trust servicessrc/               PoC verification primitivesmcp/               MCP enforcement harnesstest/              SDK + distributed consistency testsdocs/              architecture, integration contract, due diligence

Install

SDK

bash
npm install @gate-avn/sdk@dev

Current SDK Developer Preview: 0.1.0-dev.2

MCP server

bash
npm install @gate-avn/mcp@dev

Current MCP Developer Preview: 0.1.0-dev.4

Official MCP Registry:

text
io.github.Projetxana/gate-authority-network

Status

GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.

The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.

This remains experimental Developer Preview software and is not production-ready.

Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.

License

Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.

来源:README.md,提交 c2532f8

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0-dev.4最新Oct 5, 2026