
Gate Authority Network
io.github.Projetxanav0.1.0-dev.4更新于 Oct 5, 2026
Live authority-state verification for agent actions at effect time.
概览
GATE 在动作发生时验证代理是否仍拥有来自主体的有效授权路径,并返回 ALLOW、DENY 或 UNKNOWN。
- 功能
- GATE 是一个实验性的网络验证器,用于实时、跨域的授权状态。它从外部域获取授权状态,并在动作即将生效时回答是否仍存在当前有效的授权路径。它返回 VALID/ALLOW、INVALID/DENY 或 UNKNOWN/DENY,并支持 bounded 与 strict 两种一致性契约,最大陈旧时间由调用方指定。它不是策略引擎,也不替代 OAuth 或现有授权系统。
- 适用场景
- 当代理工作流需要在执行敏感操作前实时确认主体的授权未被撤销或变更时可以考虑使用,尤其是在本地签名与过期检查不足的跨域场景。它属于开发者预览版,适合评估和原型验证,而非生产环境的强制管控。
- 运行要求
- 以 npm 包 @gate-avn/mcp 通过 stdio 在本地运行,需要 Node.js 20 或更高版本。必须设置 GATE_URL 环境变量指向边缘端点,可选的 GATE_API_KEY 密钥提供 bearer 令牌。需要能访问 GATE 边缘服务的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 Gate Authority Network,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
GATE — Authority Verification Network
Developer Preview · 2026-10-02
Is this agent still authorized to act right now?
GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.
5-minute demo
Requirements: Node.js 20+.
The demo calls the public SDK shape:
What GATE verifies
GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.
It can return:
VALID / ALLOW— at least one live authority path exists.INVALID / DENY— the known paths are revoked/invalid.UNKNOWN / DENY— freshness or availability is insufficient for the requested consistency contract.
What GATE does not do
GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.
GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.
Why a network service?
A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.
Consistency contracts
bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.
Repository map
Install
SDK
Current SDK Developer Preview: 0.1.0-dev.2
MCP server
Current MCP Developer Preview: 0.1.0-dev.4
Official MCP Registry:
Status
GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.
The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.
This remains experimental Developer Preview software and is not production-ready.
Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.
License
Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.
来源:README.md,提交 c2532f8
工具
0版本历史
1- v0.1.0-dev.4最新Oct 5, 2026


