Acp Mcp Server

com.agenticcontrolplanev0.3.0更新於 Sep 30, 2026

See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.

已驗證Streamable HTTP可網頁執行AI & ML

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Acp Mcp Server,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "acp-mcp-server": {
      "type": "http",
      "url": "https://api.agenticcontrolplane.com/mcp"
    }
  }
}

README

ACP Governance MCP Server

Model Context Protocol server that lets Claude, ChatGPT, Cursor, Lovable, and any MCP client check tool calls against Agentic Control Plane governance — policy decisions, rate limits, audit logs, identity attribution.

One sentence: before your AI agent runs a sensitive tool, it asks ACP whether the call is allowed. ACP says yes, no, or asks for confirmation, and writes an audit row attributable to the human behind the agent.

What it exposes

Two tools, callable via MCP:

ToolWhat it does
acp_checkAnswer "would this call be allowed?" for a specific call — for explicit questions or pre-flight planning. If ACP hooks are installed in the harness, tool calls are already governed automatically and this doesn't need to be called per tool. Returns allow / deny / ask plus a reason.
acp_statusVerify the connection and your workspace identity.

That's the whole surface. Everything else — policies, audit logs, scope intersection, delegation chains — runs server-side at api.agenticcontrolplane.com. This MCP server is just the bridge.

Install (hosted — recommended)

The server is hosted at https://mcp.agenticcontrolplane.com/mcp. Add it as a connector in your MCP client:

Claude Desktop / Claude.ai connector:

URL: https://mcp.agenticcontrolplane.com/mcpAuth: OAuth (sign in with Google through ACP)

ChatGPT, Cursor, Lovable, Cline: Same URL, same OAuth flow. Most clients have a one-click "Add MCP Server" UI.

Programmatic clients (your own agent code):

http
POST https://mcp.agenticcontrolplane.com/mcpAuthorization: Bearer gsk_<your-acp-api-key>Content-Type: application/json

You'll need an ACP workspace. The free tier is unlimited tool-call logging — sign up at cloud.agenticcontrolplane.com/login.

Install (self-host)

If you want to run the bridge yourself — for air-gapped deployments, or to point at a self-hosted ACP gateway — clone and run:

bash
git clone https://github.com/davidcrowe/acp-mcp-servercd acp-mcp-servernpm installnpm run build
# Point at the ACP API (default: https://api.agenticcontrolplane.com)export ACP_API_BASE=https://your-acp-gateway.example.com
# Optional: service-level API key for OAuth users (ChatGPT, Claude.ai)# whose JWTs aren't directly usable as ACP tokensexport ACP_SERVICE_KEY=gsk_workspace_...
npm start# → MCP endpoint: POST http://0.0.0.0:3000/mcp# → OAuth discovery: GET /.well-known/oauth-protected-resource

The bridge speaks streamable-HTTP MCP and proxies to ACP's /govern/tool-use endpoint.

How it fits

your AI client            this MCP server          ACP gateway─────────────            ─────────────────         ───────────Claude / ChatGPT  ──►  mcp.agenticcontrolplane  ──►  api.agenticcontrolplaneCursor / Lovable    POST /mcp (acp_check)         POST /govern/tool-use                                                      ↓                                                   policy + audit + identity                                                      ↓                                                   allow / deny / ask

Every call writes an audit row attributable to the human identity behind the OAuth session — so you get a complete log of every governed tool call across every MCP client your team uses, in one workspace.

Auth model

The server supports two authentication paths:

  1. OAuth (recommended for human-driven clients) — Claude.ai, ChatGPT, etc. complete an OAuth flow against ACP's identity provider; the resulting Auth0 JWT identifies the human. The bridge uses an ACP_SERVICE_KEY to authorize the underlying governance call on the human's behalf.
  2. Bearer gsk_ API key (recommended for programmatic clients) — pass an ACP API key directly as Authorization: Bearer gsk_.... The key's identity is the ACP-side actor. Skip OAuth.

OAuth discovery metadata is served at /.well-known/oauth-protected-resource per the MCP authorization spec.

Local development

bash
npm installnpm run dev        # tsx-based hot reload

Tools are defined in src/tools/tools.ts. The MCP JSON-RPC handler is in src/handlers/mcpHandler.ts. The Express entry point and rate limits are in src/server/expressServer.ts.

License

MIT — see LICENSE.

Links

來源:README.md,提交 f68f087

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.0最新Sep 16, 2026