cQnce MCP

io.github.cqnce-appv0.1.3更新於 Sep 28, 2026

Add human approval to AI agent workflows through cQnce authorization tools.

已驗證Streamable HTTP可網頁執行AI & MLSecurity & Monitoring

概覽

AI 產生的概覽

讓 AI 助理在執行高風險或不可逆操作前,請求並等待人工核准。

功能
將 MCP 用戶端連線到 cQnce,讓助理可以提交授權請求並阻塞等待人工核准或拒絕。核心工具包括 wait_for_approval、submit_authorization_request、poll_request_status、cancel_request、list_requests 與 get_request。使用管理員權杖後,另提供專案、路由規則、代理、團隊與 webhook 管理工具。請求可攜帶操作細節,以及日誌、diff、截圖等附件供審核者參考。
適用情境
當代理在刪除資料、部署到正式環境、轉移資金或變更憑證與權限之前,必須取得人工決定時使用。它適合需要核准環節的監督式工作流程,也適合在正式環境中由宿主應用程式強制執行核准閘門、而非依賴代理主動呼叫工具的情境。若代理的操作不涉及核准要求,則無需使用。
執行需求
需要 cQnce 帳號與專案 API 金鑰:本機 npm 套件透過環境變數 CQNCE_API_KEY 提供,遠端端點 mcp.cqnce.app 則透過 Authorization Bearer 標頭提供。執行本機套件需要 Node.js 18 以上版本。選用的環境變數 CQNCE_ADMIN_TOKEN(租用戶管理員 JWT)可啟用專案、代理、團隊與回呼管理工具。需要能連線 cQnce API 的網路,也可透過選用的 CQNCE_BASE_URL 指向私有部署。
安裝前請注意
CQNCE_API_KEY 與 Authorization 標頭屬於機密資訊,而選用的 CQNCE_ADMIN_TOKEN 具備租用戶層級的專案、代理與團隊管理權限。核准內容(包括日誌、diff、截圖等附件)會傳送到 cQnce 服務供人工審核者查看。阻塞式的 wait_for_approval 工具會讓代理暫停,直到取得決定或逾時;若僅依賴代理自行呼叫工具,遭入侵或設定錯誤的代理可能略過核准,因此正式環境應由宿主強制執行閘門。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 cQnce MCP,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "cqnce-mcp": {
      "type": "http",
      "url": "https://mcp.cqnce.app/mcp"
    }
  }
}

README

@cqnce/mcp-server

Official MCP server for cQnce — add human-in-the-loop authorization to any AI agent or workflow.

Connect Claude, Cursor, GitHub Copilot, or any MCP-compatible client to cQnce so the AI can request human approval before performing risky or irreversible actions.

Quick start

bash
npx @cqnce/mcp-server

Set the CQNCE_API_KEY environment variable to your project API key before running.

Approval modes

Mode 1 — Agent-requested approval

The agent calls wait_for_approval or submit_authorization_request itself, as instructed in the system prompt or via tool discovery. This is the easiest integration path and works well for supervised workflows.

Risk: a compromised or misconfigured agent may simply not call the tool.

Mode 2 — Enforced approval gate (recommended for production)

The host application or executor intercepts every sensitive tool call before it runs and requires a prior cQnce approval, regardless of what the agent requested. The gate lives outside the model context — the agent cannot skip it.

This is a real security boundary. Build enterprise and compliance-sensitive integrations on this mode.

python
# Example: host-side interception (framework-agnostic)HIGH_RISK_TOOLS = {"send_payment", "deploy_production", "delete_customer"}
def execute_tool_call(tool_call):    if tool_call.name not in HIGH_RISK_TOOLS:        return run_tool(tool_call)    decision = cqnce.submit_and_wait(        payload={"action": tool_call.name, "parameters": tool_call.arguments},        timeout_seconds=300,    )    if decision["status"] != "APPROVED":        return {"error": "not_authorized", "status": decision["status"]}    return run_tool(tool_call)

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

json
{  "mcpServers": {    "cqnce": {      "command": "npx",      "args": ["-y", "@cqnce/mcp-server"],      "env": {        "CQNCE_API_KEY": "your-project-api-key"      }    }  }}

Cursor

Add to .cursor/mcp.json in your project (or the global ~/.cursor/mcp.json):

json
{  "mcpServers": {    "cqnce": {      "command": "npx",      "args": ["-y", "@cqnce/mcp-server"],      "env": {        "CQNCE_API_KEY": "your-project-api-key"      }    }  }}

Any MCP client (stdio transport)

bash
CQNCE_API_KEY=your-project-api-key npx @cqnce/mcp-server

Cloud agents (Streamable HTTP / remote MCP)

For cloud-hosted agents that cannot run local processes, use the cQnce MCP Worker deployed on Cloudflare Workers. It speaks the MCP Streamable HTTP transport and is stateless — every request authenticates with your API key.

Configure your cloud agent framework to connect to:

https://mcp.cqnce.app/mcpAuthorization: Bearer <your-project-api-key>

Example (Claude API with MCP):

python
import anthropic
client = anthropic.Anthropic()
response = client.beta.messages.create(    model="claude-opus-4-5",    max_tokens=1024,    mcp_servers=[        {            "type": "url",            "url": "https://mcp.cqnce.app/mcp",            "name": "cqnce",            "authorization_token": "your-project-api-key",        }    ],    messages=[{"role": "user", "content": "..."}],    betas=["mcp-client-2025-04-04"],)
Self-hosting

The Worker source is in this repository. Deploy your own instance to Cloudflare Workers:

bash
npm installnpx wrangler deploy

Set CQNCE_BASE_URL in the Cloudflare dashboard if you use a private cQnce deployment (defaults to https://api.cqnce.app).

Configuration

VariableRequiredDescription
CQNCE_API_KEYYesProject API key from cqnce.app
CQNCE_BASE_URLNoAPI base URL (default: https://api.cqnce.app)
CQNCE_ADMIN_TOKENNoTenant admin JWT — enables project/agent/team management tools

Tools

Core (requires CQNCE_API_KEY)

ToolDescription
wait_for_approvalSubmit a request and block until a human approves or rejects it. This is the primary tool for human-in-the-loop workflows.
submit_authorization_requestSubmit a request and return the requestId immediately (non-blocking).
poll_request_statusCheck the current status of a request by ID.
cancel_requestCancel a pending request.
list_requestsList requests for this project (filterable by status, date, tags).
get_requestGet full details of a single request including agent responses.

Admin (requires CQNCE_ADMIN_TOKEN)

Project management, routing rule configuration, agent/team management, and webhook callbacks.

Recommended system prompt

When integrating Claude via the Anthropic API, add this system prompt to enforce the authorization policy automatically — without relying on the user to request it each time:

You have access to the cQnce tool for human-in-the-loop authorization.
ALWAYS call wait_for_approval BEFORE performing any action that is:- Destructive or irreversible (deleting data, dropping tables, removing files)- Affecting production systems (deployments, database migrations, config changes)- Financial (payments, transfers, subscription changes)- Involving credentials or access control (creating/revoking API keys, changing permissions)
In the approval payload, include:- "action": what you are about to do- "target": what resource is affected- "reason": why this action is needed- "risk": what happens if approved or rejected- "attachments": (optional) list of supporting files as { name, contentType, data (base64) }  — include logs, diffs, screenshots, or any evidence that helps the reviewer decide
When the response status is "REJECTED":- Read the rejection reason carefully.- If the reason identifies missing information or context, gather that information,  enrich the payload (or attachments), and resubmit via wait_for_approval.- Only give up if the rejection reason makes clear the action itself is not permitted.
Proceed ONLY if the returned status is "APPROVED".If "EXPIRED" or the rejection reason leaves no actionable path forward, stop and explain.

Example

Once configured, you can tell Claude:

"Before deleting the production database, ask for human approval via cQnce."

Claude will call wait_for_approval with the action details, pause until a human approves or rejects from the cQnce mobile app, and only proceed if the status is APPROVED. If rejected with a reason (e.g. "missing rollback plan"), Claude will gather that information and resubmit automatically.

Requirements

  • Node.js 18+
  • A cQnce account and project API key — sign up free

來源:README.md,提交 ae05e67

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.3最新Sep 28, 2026