Gate Authority Network

io.github.Projetxanav0.1.0-dev.4更新於 Oct 5, 2026

Live authority-state verification for agent actions at effect time.

已驗證STDIO僅桌面AI & MLSecurity & Monitoring

概覽

AI 產生的概覽

GATE 在動作發生時驗證代理是否仍擁有來自主體的有效授權路徑,並回傳 ALLOW、DENY 或 UNKNOWN。

功能
GATE 是一個實驗性的網路驗證器,用於即時、跨網域的授權狀態。它從外部網域取得授權狀態,並在動作即將生效時回答是否仍存在目前有效的授權路徑。它回傳 VALID/ALLOW、INVALID/DENY 或 UNKNOWN/DENY,並支援 bounded 與 strict 兩種一致性契約,最大陳舊時間由呼叫方指定。它不是政策引擎,也不取代 OAuth 或現有授權系統。
適用情境
當代理工作流程需要在執行敏感操作前即時確認主體的授權未被撤銷或變更時,可以考慮使用,尤其是在本機簽章與到期檢查不足的跨網域情境。它屬於開發者預覽版,適合評估與原型驗證,而非正式環境的強制管控。
執行需求
以 npm 套件 @gate-avn/mcp 透過 stdio 在本機執行,需要 Node.js 20 或更新版本。必須設定 GATE_URL 環境變數指向邊緣端點,選用的 GATE_API_KEY 密鑰提供 bearer 權杖。需要能連線至 GATE 邊緣服務的網路。
安裝前請注意
此伺服器是實驗性開發者預覽軟體,尚未達到正式可用。它會將主體、執行者與動作詳情傳送到外部 GATE 邊緣服務,請評估因此暴露的資訊。選用的 GATE_API_KEY bearer 權杖屬於憑證,應視為機密處理。DENY 或 UNKNOWN 結果會以失敗關閉方式處理,需事先規劃工作流程的應對方式。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Gate Authority Network,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

GATE — Authority Verification Network

Developer Preview · 2026-10-02

Is this agent still authorized to act right now?

GATE is an experimental network verifier for live, cross-domain authority. It does not mint a proprietary delegation token, replace OAuth, or replace your policy engine. It consumes authority state from external domains and answers whether a currently valid authority path still exists at action time.

5-minute demo

Requirements: Node.js 20+.

bash
npm installnpm testnpm run demo

The demo calls the public SDK shape:

js
import { GateClient } from './packages/sdk/dist/index.js';
const gate = new GateClient({ endpoint: process.env.GATE_URL });
const result = await gate.verify({  principal: 'user:jerome',  actor: 'agent:C@company-c',  action: {    protocol: 'mcp',    name: 'delete_customer_data',    resource: 'customer:3456'  },  consistency: 'bounded',  maxStalenessMs: 200});
if (result.decision !== 'ALLOW') throw new Error(result.reason);

What GATE verifies

GATE answers a deliberately narrow question: whether the actor still has at least one live authority path from the principal, according to verified external authority state.

It can return:

  • VALID / ALLOW — at least one live authority path exists.
  • INVALID / DENY — the known paths are revoked/invalid.
  • UNKNOWN / DENY — freshness or availability is insufficient for the requested consistency contract.

What GATE does not do

GATE is not your business-policy PDP. The action object is carried for integration/audit context in this preview; policy such as "may this principal delete customer 3456?" belongs in AuthZEN, Cedar, OPA, Permit, Cerbos, OpenFGA, or your existing authorization system.

GATE is also not trying to replace OAuth, MCP, A2A, OpenID Federation, Security Event Tokens, or Shared Signals. The intended role is to sit underneath/alongside them as a live authority-state verifier.

Why a network service?

A local verifier can validate signatures, expiry, scopes and token chains. It cannot independently know every external issuer's current revocation state, trust changes, alternate delegation paths, or freshness across domains. GATE's hypothesis is that the defensible value is the shared, low-latency state network — not a secret verification algorithm.

Consistency contracts

  • bounded: edge-local verification against a signed replica lease, with caller-defined maximum staleness; stale replicas fail closed.
  • strict: synchronous control-plane confirmation; higher latency and lower partition availability in exchange for current-state confirmation.

Repository map

text
packages/sdk/      public developer-facing clientexamples/          minimal SDK demonstrationservices/          experimental control plane / edge / trust servicessrc/               PoC verification primitivesmcp/               MCP enforcement harnesstest/              SDK + distributed consistency testsdocs/              architecture, integration contract, due diligence

Install

SDK

bash
npm install @gate-avn/sdk@dev

Current SDK Developer Preview: 0.1.0-dev.2

MCP server

bash
npm install @gate-avn/mcp@dev

Current MCP Developer Preview: 0.1.0-dev.4

Official MCP Registry:

text
io.github.Projetxana/gate-authority-network

Status

GATE is publicly available as a Developer Preview on npm and in the Official MCP Registry.

The SDK and MCP server are installable independently from the public npm registry. The MCP server is discoverable through the Official MCP Registry.

This remains experimental Developer Preview software and is not production-ready.

Read next: docs/DUE-DILIGENCE-2026-10-02.md and docs/PUBLIC-VALIDATION-PLAN.md.

License

Apache-2.0. This repository is intended to make the verification logic easy to inspect and challenge; the long-term product hypothesis is the shared live authority network, not proprietary verifier code.

來源:README.md,提交 c2532f8

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0-dev.4最新Oct 5, 2026