{"_id":"@agent-grant-protocol/mcp","_rev":"3-216bbb04046849ab37b34dd4deeafa73","name":"@agent-grant-protocol/mcp","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@agent-grant-protocol/mcp","version":"0.1.0","license":"Apache-2.0","_id":"@agent-grant-protocol/mcp@0.1.0","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/mcp#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"dist":{"shasum":"9c04970a60137ecfb2c71b07e26f2d2b34f00271","tarball":"https://registry.npmjs.org/@agent-grant-protocol/mcp/-/mcp-0.1.0.tgz","fileCount":4,"integrity":"sha512-K3kUMuMP2J/85G7F6OSj3q1T9uN4A1k5GNo7X3yQI+Cgu+nVdwvrOlDGk20i37YEe3GBiQHfHi/pb6eVNrjA5w==","signatures":[{"sig":"MEUCIBr6iglggniGZp/NFwMI5HPmkGRDCtpQUG9ovXrwHMDWAiEA1YmviDhsheqKZhFnEYRoTsLT6RnVv5U7mFGefN0qT58=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22366},"main":"src/gate.mjs","type":"module","engines":{"node":">=18"},"exports":{".":"./src/gate.mjs"},"gitHead":"dd732c26ee9c65b65c94736dd4ad2c9e0fc0e456","scripts":{"test":"node --test test/*.test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"repository":{"url":"git+https://github.com/agent-grant-protocol/agp.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.12.1","description":"Grant-gated MCP tool calls: middleware enforcing AGP grants and proofs on Streamable HTTP tools/call requests.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"@agent-grant-protocol/verifier":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1783352784434_0.1379362931763588","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-grant-protocol/mcp","version":"0.1.1","license":"Apache-2.0","_id":"@agent-grant-protocol/mcp@0.1.1","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/mcp#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"dist":{"shasum":"d098a5873882553e2a83676590fe0e79829ae2b9","tarball":"https://registry.npmjs.org/@agent-grant-protocol/mcp/-/mcp-0.1.1.tgz","fileCount":4,"integrity":"sha512-E5cDKNnYfUe2W1Fe2Jj7EVe7vY+TSFrA7qLD/E3pHcxR0/PobJ3GdEX+EznQrgCaBewVrryICJSagGBSeWhwfA==","signatures":[{"sig":"MEUCIQDpavoae6UByOQm105K37Q3o/FAEOZ4klOOnbsDxa1TAwIgfFhxIdS4hFEARqwg5w4be0tXm+/VahuY9VuduQqvbUE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22366},"main":"src/gate.mjs","type":"module","engines":{"node":">=18"},"exports":{".":"./src/gate.mjs"},"gitHead":"dd732c26ee9c65b65c94736dd4ad2c9e0fc0e456","scripts":{"test":"node --test test/*.test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"repository":{"url":"git+https://github.com/agent-grant-protocol/agp.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.12.1","description":"Grant-gated MCP tool calls: middleware enforcing AGP grants and proofs on Streamable HTTP tools/call requests.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"@agent-grant-protocol/verifier":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.1_1783352874518_0.20102903769979674","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-grant-protocol/mcp","version":"0.1.2","description":"Grant-gated MCP tool calls: middleware enforcing AGP grants and proofs on Streamable HTTP tools/call requests.","main":"src/gate.mjs","type":"module","exports":{".":"./src/gate.mjs"},"engines":{"node":">=18"},"scripts":{"test":"node --test test/*.test.mjs","prepublishOnly":"npm test"},"publishConfig":{"access":"public"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/agent-grant-protocol/agp.git","directory":"packages/mcp"},"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/mcp#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"dependencies":{"@agent-grant-protocol/verifier":"^0.1.3"},"gitHead":"c5e59c60d8915225a21ab8527fc795bfc4cd5911","_id":"@agent-grant-protocol/mcp@0.1.2","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-W2XEkaDOJYT0hRMK21G/twuIRRwqlKiJnBOau6Zt28V58iGhMzvT5RoNKvZERcgeFWNauysNzQT++z8lLcSq8g==","shasum":"750817a5aadfb86ed7b72ee7563562902571966f","tarball":"https://registry.npmjs.org/@agent-grant-protocol/mcp/-/mcp-0.1.2.tgz","fileCount":4,"unpackedSize":23261,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCNZofXPJO2F+QBevDVmgbXOMwN+MnNKWk43OTHnx840gIhAK6kFTksaBB1UKJOzWVkuLyTdSDG5JEP1sPDeq1QFKWP"}]},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"directories":{},"maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.1.2_1783461860782_0.7622964054637484"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-06T15:46:24.187Z","modified":"2026-07-07T22:04:21.085Z","0.1.0":"2026-07-06T15:46:24.566Z","0.1.1":"2026-07-06T15:47:54.654Z","0.1.2":"2026-07-07T22:04:20.919Z"},"bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"license":"Apache-2.0","homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/mcp#readme","repository":{"type":"git","url":"git+https://github.com/agent-grant-protocol/agp.git","directory":"packages/mcp"},"description":"Grant-gated MCP tool calls: middleware enforcing AGP grants and proofs on Streamable HTTP tools/call requests.","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"readme":"# @agent-grant-protocol/mcp\n\nMiddleware that puts MCP tool calls behind AGP grants. A `tools/call` request over the Streamable HTTP transport must carry an `AGP-Grant` and `AGP-Proof` header; the gate verifies them and rejects anything the grant doesn't cover. When the grant's owner revokes it, calls start failing within a minute, with no changes on the server side.\n\nEach tool call is verified as an AGP `do` operation (`act: \"mcp.tool\"`), with the tool name matched against the grant's `tools` list. If you price a tool, the same call also has to pass a `spend` check against the grant's budget.\n\nThe wire mapping is specified in [the AGP-for-MCP profile draft](https://github.com/agent-grant-protocol/agp/blob/main/spec/profiles/mcp-v0.1-draft.md); the protocol itself in [AGP v0.1](https://github.com/agent-grant-protocol/agp/blob/main/spec/agp-v0.1.md).\n\n## Use\n\n```js\nimport { createMcpGate } from '@agent-grant-protocol/mcp';\n\nconst gate = createMcpGate({\n  endpoint: 'https://tools.example.com/mcp',   // proof htu + grant audience\n  // You need statusOf in practice: tools/call is do-scoped, so without it\n  // every call fails closed with STATUS_UNAVAILABLE (spec §7.3 step 9).\n  statusOf: async (jti) => {\n    const res = await fetch(`https://g.aye.app/s/${jti}`);\n    return res.ok ? (await res.json()).status : null;\n  },\n  pricing: { 'search.web': { asset: 'USDC', amount: '0.001' } }, // optional\n});\n\n// Express (mount with express.raw so the proof's body hash sees exact bytes):\napp.use('/mcp', express.raw({ type: 'application/json' }), gate.express());\n\n// or fetch-style (Workers, Hono, Bun):\nexport default { fetch: gate.fetchHandler(mcpServerHandler) };\n\n// or any framework, via the core:\nconst d = await gate.check({ method, headers, body });\nif (!d.ok) return respond(d.status, d.body); // { error: <spec §7.3 code> }\n```\n\nIf a grant is presented on `tools/list`, you can pass the verified grant from `gate.check` to `gate.filterTools(tools, verified)` so agents only see the tools they can actually call. This is a courtesy, not the enforcement layer; `tools/call` is always verified on its own.\n\nRejections are HTTP-level, before JSON-RPC processing. The error codes are the v0.1 §7.3 normative closed set (`SCOPE_MISS`, `REVOKED`, `FROZEN`, `EXPIRED`, `BAD_PROOF`, `SPEND_EXCEEDED`, ...): 401 for `EXPIRED` and `BAD_FORMAT`, with a `WWW-Authenticate: AgentGrant` header, and 403 for everything else.\n\nOne proof covers one HTTP request. Its `bh` claim binds the exact request body (batches included), and its jti is consumed once per successful request, so agents mint a fresh proof for each request. The built-in replay cache is in-memory; swap in anything with `{ has(jti), add(jti) }`.\n\nThe profile draft leaves out stdio transport, `resources/*`, and `prompts/*` for now; see its §8 for why.\n","readmeFilename":"README.md"}