veto

io.github.aivetov0.1.4更新於 Oct 3, 2026

Turn OpenAPI services into tools an agent can call under your rules.

概覽

AI 產生的概覽

把現有的 OpenAPI 服務變成助理可呼叫的工具目錄,並附帶政策檢查、審批關卡與憑證處理。

功能
Veto 透過三個工具向 MCP 用戶端暴露由 OpenAPI 描述的服務:capabilities_search、capabilities_describe 和 capabilities_invoke。模型提出呼叫請求,Veto 檢查政策、對破壞性呼叫要求審批、解析憑證,之後才讓 API 執行。宣告的關聯可連接不同操作(例如訂單的 customerId 指向 customers.get),並記錄一筆追蹤。回應整形傳回指定欄位與有界清單,並標記分頁或截斷。
適用情境
當助理需要呼叫由 OpenAPI 描述的現有 HTTP API,而不是為每個端點手寫工具時適用;也適用於需要政策執行、破壞性操作的人工審批,以及在模型之外解析憑證的情境。適合希望 MCP、CLI 與產生的 Go 用戶端共用同一執行環境的團隊。
執行需求
以本機程序透過 stdio 執行,可透過 Homebrew、go install(需 Go 1.27.1)、GitHub Releases 二進位檔或 ghcr.io/aiveto/veto 映像檔安裝。需要一份 veto.yaml 指定 OpenAPI 檔案或 URL,以及一個仍在監聽的 API。憑證來自環境變數、OAuth、呼叫端提供的權杖、權杖交換、傳回請求標頭的命令或 Go provider。此 MCP 伺服器本身未宣告驗證。
安裝前請注意
它可以執行刪除等破壞性呼叫;預設需要審批,但 veto.yaml 中的 confirmation: false 會在整個部署中關閉此關卡。憑證在發出 HTTP 之前解析並保留在追蹤之外,但伺服器與 veto approve 共用審批儲存與簽章設定。處於 1.0 之前,公開 API 可能變動。追蹤使用 OpenTelemetry,OTLP 匯出為選用。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 veto,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

[veto makes it possible for an AI agent to call your API with context and semantics. A hundred endpoints stay 3 tools.]

Turn existing OpenAPI services into tools AI agents can discover and call under your rules.

The model may request a call. Veto checks policy, requires approval for a destructive call, and resolves credentials before your API runs. Declared relations name a linked operation. A trace records the decision.

The model proposes. Veto decides. Your API executes.

Connect an MCP client, or embed the Go runtime. MCP, the CLI, eval, and a generated Go client share that runtime. The client calls the catalog through search, describe, and invoke. A hundred endpoints do not become a hundred tools. Your services stay where they already run.

bash
brew install aiveto/veto/veto
bash
go install github.com/aiveto/veto/cmd/veto@latest

brew does not need Go. go install needs Go 1.27.1. Binaries are on GitHub Releases. A release also pushes ghcr.io/aiveto/veto.

See veto in action

veto-demo is the full walk. Harbor sells home goods. Orders, customers, and billing are the APIs. The walk follows a customer from an order, holds a delete until a person approves it, and keeps the secret out of the trace. make demo runs the story. make mcp leaves Harbor listening and prints the config for Claude, Cursor, or ChatGPT.

This repo runs the relation, the held delete, and the redacted trace, then exits. No model key.

bash
git clone https://github.com/aiveto/veto.git
cd veto
go run ./examples/two-apis
text
Someone asked who placed order 123.
orders.get returned customerId 7.
customers.get was called for 7 because the note said Order.customerId identifies customers.get.
orders.delete sent no HTTP until approved.
The trace left the secret out.

A delete waits

text
Agent requests the call                          -> pending ID; no upstream HTTP
Person accepts the form in the chat              -> one matching invocation
Host without that form: veto approve <id>        -> approved ID, then the agent submits it once

The approval is bound to the caller, the operation, and the parameters. Permission and confirmation run before credentials are fetched and before HTTP. An OPA allow does not skip those checks. A webhook or a command can notify your approval system. The server and veto approve share approval storage and signing configuration. confirmation: false in veto.yaml turns that gate off for the deployment. Unset leaves it on.

A per-caller limit stops a call before policy. Timeouts and retries apply to the call that is sent.

The next call is declared

yaml
relations:
  - schema: Order
    field: customerId
    to: customers.get

Search returns the related operation. Describe returns the note, such as Order.customerId identifies customers.get. The Go Follow API walks that link. MCP invoke runs one operation. Relations.

What the agent receives

The tool names are capabilities_search, capabilities_describe, and capabilities_invoke. Direct pins add a few operations beside those three. Grouped mode adds one tool per resource. Search matches the summary, tags, the path noun, and synonyms such as retire for delete. An overlay can add a word of your own.

Response shaping returns named fields and a bounded list, and marks pagination and truncation. A Go context pack holds rules, operation summaries, the conversation, relations, and a pending confirmation, inside a byte budget. The raw OpenAPI document stays out of the pack.

Connect your services

veto init writes veto.yaml for the OpenAPI files or URLs you name, and a relations.yaml stub if you do not have one. If veto.yaml is already there, init stops.

bash
veto init orders.yaml customers.yaml

veto serve --stdio speaks MCP on stdin. Authenticated Streamable HTTP serves the same runtime to a remote client.

Credentials come from the environment, OAuth, a caller-supplied token, token exchange, a command that returns headers, or a Go provider that signs the request. The agent does not perform that login. Authentication.

Check it

TaskHow
The catalog loads, and its operation count and joins are printedvalidate
Missing auth, a colliding operation id, or a parameter that cannot be sentdoctor
The request and the policy decision, before a token is fetched and before HTTPpreview
Run a caseeval
Fail when a joined operation disappears, confirmation or a permission is dropped, a new destructive operation appears, or a case expectation changes. confirmation: false is the record of a deployment-wide dropcheck --against
Print a saved tracereplay --from
Run a messagereplay
Share contracts, relations, and cases apart from deployment credentialscapability bundle
Call the same runtime from your own Go modulegenerate a client, a CLI, and an MCP dispatch package

Traces are OpenTelemetry. OTLP export is optional. The Go model and memory interfaces, and sequential flows, run in-process. They are not a durable workflow service.

bash
veto validate --config testdata/veto.yaml
veto eval --config testdata/veto.yaml --case testdata/delete.yaml
veto serve --config testdata/veto.yaml --stdio

testdata/veto.yaml is already written, so these commands start at validate. eval runs the delete case in this repo. serve --stdio is the MCP process. A call needs an API that is still listening, which is what veto-demo keeps up.

Scope

Pre-1.0. Public APIs may change.

Setup guide | Current limits

來源:README.md,提交 5e5b0cb

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.4最新Oct 3, 2026