
Gate Authority Network
io.github.Projetxanav0.1.0-dev.4更新於 Oct 5, 2026
Live authority-state verification for agent actions at effect time.
概覽
GATE 在動作發生時驗證代理是否仍擁有來自主體的有效授權路徑,並回傳 ALLOW、DENY 或 UNKNOWN。
- 功能
- GATE 是一個實驗性的網路驗證器,用於即時、跨網域的授權狀態。它從外部網域取得授權狀態,並在動作即將生效時回答是否仍存在目前有效的授權路徑。它回傳 VALID/ALLOW、INVALID/DENY 或 UNKNOWN/DENY,並支援 bounded 與 strict 兩種一致性契約,最大陳舊時間由呼叫方指定。它不是政策引擎,也不取代 OAuth 或現有授權系統。
- 適用情境
- 當代理工作流程需要在執行敏感操作前即時確認主體的授權未被撤銷或變更時,可以考慮使用,尤其是在本機簽章與到期檢查不足的跨網域情境。它屬於開發者預覽版,適合評估與原型驗證,而非正式環境的強制管控。
- 執行需求
- 以 npm 套件 @gate-avn/mcp 透過 stdio 在本機執行,需要 Node.js 20 或更新版本。必須設定 GATE_URL 環境變數指向邊緣端點,選用的 GATE_API_KEY 密鑰提供 bearer 權杖。需要能連線至 GATE 邊緣服務的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Gate Authority Network,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
GATE — Authority Verification Network
Developer Preview · 2026-10-02
Is this agent still authorized to act right now?
GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.
5-minute demo
Requirements: Node.js 20+.
The demo calls the public SDK shape:
What GATE verifies
GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.
It can return:
VALID / ALLOW— at least one live authority path exists.INVALID / DENY— the known paths are revoked/invalid.UNKNOWN / DENY— freshness or availability is insufficient for the requested consistency contract.
What GATE does not do
GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.
GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.
Why a network service?
A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.
Consistency contracts
bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.
Repository map
Install
SDK
Current SDK Developer Preview: 0.1.0-dev.2
MCP server
Current MCP Developer Preview: 0.1.0-dev.4
Official MCP Registry:
Status
GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.
The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.
This remains experimental Developer Preview software and is not production-ready.
Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.
License
Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.
來源:README.md,提交 c2532f8
工具
0版本歷史
1- v0.1.0-dev.4最新Oct 5, 2026


