
veto
io.github.aivetov0.1.4更新于 Oct 3, 2026
Turn OpenAPI services into tools an agent can call under your rules.
概览
把现有的 OpenAPI 服务变成助手可调用的工具目录,并附带策略检查、审批门禁与凭据处理。
- 功能
- Veto 通过三个工具向 MCP 客户端暴露由 OpenAPI 描述的服务:capabilities_search、capabilities_describe 和 capabilities_invoke。模型提出调用请求,Veto 检查策略、对破坏性调用要求审批、解析凭据,之后才让 API 执行。声明的关联可连接不同操作(例如订单的 customerId 指向 customers.get),并记录一条追踪。响应整形返回指定字段和有界列表,并标记分页或截断。
- 适用场景
- 当助手需要调用由 OpenAPI 描述的现有 HTTP API,而不是为每个端点手写工具时适用;也适用于需要策略执行、破坏性操作的人工审批,以及在模型之外解析凭据的场景。适合希望 MCP、CLI 与生成的 Go 客户端共用同一运行时的团队。
- 运行要求
- 以本地进程通过 stdio 运行,可通过 Homebrew、go install(需 Go 1.27.1)、GitHub Releases 二进制或 ghcr.io/aiveto/veto 镜像安装。需要一份 veto.yaml 指定 OpenAPI 文件或 URL,以及一个仍在监听的 API。凭据来自环境变量、OAuth、调用方提供的令牌、令牌交换、返回请求头的命令或 Go provider。该 MCP 服务器本身未声明认证。
安装
在 SourceWeft 中
- 打开 控制台中的 veto,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Turn existing OpenAPI services into tools AI agents can discover and call under your rules.
The model may request a call. Veto checks policy, requires approval for a destructive call, and resolves credentials before your API runs. Declared relations name a linked operation. A trace records the decision.
The model proposes. Veto decides. Your API executes.
Connect an MCP client, or embed the Go runtime. MCP, the CLI, eval, and a generated Go client share that runtime. The client calls the catalog through search, describe, and invoke. A hundred endpoints do not become a hundred tools. Your services stay where they already run.
brew does not need Go. go install needs Go 1.27.1. Binaries are on GitHub Releases. A release also pushes ghcr.io/aiveto/veto.
See veto in action
veto-demo is the full walk. Harbor sells home goods. Orders, customers, and billing are the APIs. The walk follows a customer from an order, holds a delete until a person approves it, and keeps the secret out of the trace. make demo runs the story. make mcp leaves Harbor listening and prints the config for Claude, Cursor, or ChatGPT.
This repo runs the relation, the held delete, and the redacted trace, then exits. No model key.
A delete waits
The approval is bound to the caller, the operation, and the parameters. Permission and confirmation run before credentials are fetched and before HTTP. An OPA allow does not skip those checks. A webhook or a command can notify your approval system. The server and veto approve share approval storage and signing configuration. confirmation: false in veto.yaml turns that gate off for the deployment. Unset leaves it on.
A per-caller limit stops a call before policy. Timeouts and retries apply to the call that is sent.
The next call is declared
Search returns the related operation. Describe returns the note, such as Order.customerId identifies customers.get. The Go Follow API walks that link. MCP invoke runs one operation. Relations.
What the agent receives
The tool names are capabilities_search, capabilities_describe, and capabilities_invoke. Direct pins add a few operations beside those three. Grouped mode adds one tool per resource. Search matches the summary, tags, the path noun, and synonyms such as retire for delete. An overlay can add a word of your own.
Response shaping returns named fields and a bounded list, and marks pagination and truncation. A Go context pack holds rules, operation summaries, the conversation, relations, and a pending confirmation, inside a byte budget. The raw OpenAPI document stays out of the pack.
Connect your services
veto init writes veto.yaml for the OpenAPI files or URLs you name, and a relations.yaml stub if you do not have one. If veto.yaml is already there, init stops.
veto serve --stdio speaks MCP on stdin. Authenticated Streamable HTTP serves the same runtime to a remote client.
Credentials come from the environment, OAuth, a caller-supplied token, token exchange, a command that returns headers, or a Go provider that signs the request. The agent does not perform that login. Authentication.
Check it
Traces are OpenTelemetry. OTLP export is optional. The Go model and memory interfaces, and sequential flows, run in-process. They are not a durable workflow service.
testdata/veto.yaml is already written, so these commands start at validate. eval runs the delete case in this repo. serve --stdio is the MCP process. A call needs an API that is still listening, which is what veto-demo keeps up.
Scope
Pre-1.0. Public APIs may change.
来源:README.md,提交 5e5b0cb
工具
0版本历史
1- v0.1.4最新Oct 3, 2026

