{"_id":"@agentauthoritychain/mcp-guard","_rev":"3-bfb5728166033dc8cae4d6b04188a3ea","name":"@agentauthoritychain/mcp-guard","dist-tags":{"latest":"0.5.2"},"versions":{"0.5.0":{"name":"@agentauthoritychain/mcp-guard","version":"0.5.0","keywords":["mcp","ai-agents","authority","delegation","authorization","fail-closed"],"license":"Apache-2.0","_id":"@agentauthoritychain/mcp-guard@0.5.0","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"homepage":"https://agentauthoritychain.com/integrations/","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"7b7b2747871abef47b8f8006954403461ef2f9ac","tarball":"https://registry.npmjs.org/@agentauthoritychain/mcp-guard/-/mcp-guard-0.5.0.tgz","fileCount":5,"integrity":"sha512-GNcjBLPbd6uiKGM8s4YEvf/emBAaj8VjR56qfPZlCco4Cod+0LbSA59qnPOWocEaq4JnLWh7ekl2+mrs9aKOKA==","signatures":[{"sig":"MEUCIHdJEKY8ZTsL7tBOYJrN86ah/v5ne0Wux++CivY7cCpsAiEA4BiQujHbnO56wTPqdTS1Q9Lxn9PDPjcicIgKPjUmXH0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12834},"type":"module","engines":{"node":">=20"},"exports":{".":"./aac-mcp-guard.mjs","./aacp":"./aacp-mcp-binding.mjs"},"gitHead":"d0529caa30a618caa665eff0d4813b991c7f9cc8","_npmUser":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"},"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/mcp"},"_npmVersion":"11.17.0","description":"Fail-closed delegated authority guard for consequential MCP tool execution","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@agentauthoritychain/client":"0.5.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-guard_0.5.0_1787694247889_0.6559733766884854","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@agentauthoritychain/mcp-guard","version":"0.5.1","keywords":["mcp","mcp-authorization","ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","fail-closed"],"license":"Apache-2.0","_id":"@agentauthoritychain/mcp-guard@0.5.1","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"homepage":"https://agentauthoritychain.com/wiki/","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"d496ca2682b6c587f63e6c76064299875508f0a3","tarball":"https://registry.npmjs.org/@agentauthoritychain/mcp-guard/-/mcp-guard-0.5.1.tgz","fileCount":5,"integrity":"sha512-5MIC/IPupxwXndp7gMbkO7/yaMf6znDG8dcGk7ZhxXZSWclWdL3RsS25xyJtRPeTUzyPQQVcP86vCxe6jetC1Q==","signatures":[{"sig":"MEUCIFkt7zetoifEjTh2ENAHuZqmW8nQwqUCirQf0a1McWooAiEAskBrDv+DNwUvW5XypNrn03R713rYYpjIw54RwzW9IxY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14133},"type":"module","engines":{"node":">=20"},"exports":{".":"./aac-mcp-guard.mjs","./aacp":"./aacp-mcp-binding.mjs"},"gitHead":"877d3574053e2d57c499f221fe8c0464c32035e9","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","approver":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"},"trustedPublisher":{"id":"github","oidcConfigId":"oidc:be379c61-480c-4cf3-9e1a-2fc150159c7e"}},"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/mcp"},"_npmVersion":"11.19.0","description":"Fail-closed delegated authority guard for consequential MCP tool execution","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@agentauthoritychain/client":"0.5.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-guard_0.5.1_1787710178550_0.5082242625592537","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"_id":"@agentauthoritychain/mcp-guard@0.5.2","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"e249f34231ba5598387a08a2328c5200215bffcb","tarball":"https://registry.npmjs.org/@agentauthoritychain/mcp-guard/-/mcp-guard-0.5.2.tgz","integrity":"sha512-jnVVKLeGBuklQLvxxjomnmRR0zEYyQZvoq9u5GXYk4TnYXRor3A1vFYD9nBSAh/P4I23h0v+5VKAY+/OEmfhXQ==","fileCount":5,"unpackedSize":14688,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDPjptZvCpoOj66b0jd+Fkx4fdVuNYFlkiTRx60oWIZSAIhAN0twBDTZoBuGMEHJWQ395U5t6ZNlYSawLbD60SyJgr2"}]},"name":"@agentauthoritychain/mcp-guard","type":"module","engines":{"node":">=20"},"exports":{".":"./aac-mcp-guard.mjs","./aacp":"./aacp-mcp-binding.mjs"},"gitHead":"a157a73e61e4a5bc47b4b0500ad882cf4e9e74a1","license":"Apache-2.0","version":"0.5.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:be379c61-480c-4cf3-9e1a-2fc150159c7e"},"approver":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}},"homepage":"https://agentauthoritychain.com/wiki/","keywords":["mcp","mcp-authorization","ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","fail-closed"],"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/mcp"},"_npmVersion":"11.19.0","description":"Fail-closed delegated authority guard for consequential MCP tool execution","directories":{},"maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"_nodeVersion":"24.19.0","dependencies":{"@agentauthoritychain/client":"0.5.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-guard_0.5.2_1787749617430_0.058102290217938446"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-25T21:44:07.697Z","modified":"2026-08-26T13:06:57.702Z","0.5.0":"2026-08-25T21:44:08.040Z","0.5.1":"2026-08-26T02:09:38.657Z","0.5.2":"2026-08-26T13:06:57.536Z"},"bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"license":"Apache-2.0","homepage":"https://agentauthoritychain.com/wiki/","keywords":["mcp","mcp-authorization","ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","fail-closed"],"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/mcp"},"description":"Fail-closed delegated authority guard for consequential MCP tool execution","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"readme":"# Agent Authority Chain MCP guard\n\nFail-closed delegated-authority enforcement for consequential MCP tool calls. Wrap a tool handler when the operation must execute only after an exact, cryptographically verified permit that remains inside the principal's delegated capability and constraints.\n\nThis package is not an MCP transport authentication replacement. It adds pre-action authority verification: widened, expired, revoked, denied, malformed or unavailable authority keeps the tool handler closed.\n\n```bash\nnpm install @agentauthoritychain/mcp-guard@0.5.2 @agentauthoritychain/client@0.5.2\n```\n\n```javascript\nimport { AACClient } from \"@agentauthoritychain/client\";\nimport { guardMcpTool } from \"@agentauthoritychain/mcp-guard\";\n\nconst client = new AACClient({ credential: process.env.AAC_API_CREDENTIAL });\nconst protectedTool = guardMcpTool(toolHandler, {\n  client,\n  buildSignedScenario: buildNarrowSignedAuthorityForToolCall,\n});\n```\n\nThe guard builds authority through your callback, asks the canonical client to verify it, and invokes the handler only after an exact permit. It reuses `@agentauthoritychain/client` and does not duplicate verifier, receipt, revocation or policy semantics. Private issuer keys remain in your environment.\n\nFor an MCP server dispatch map, `guardMcpDispatch(handlers, options)` applies the same fail-closed guard to every named handler and returns a new protected map.\n\nUse this package for MCP tool execution. Use `@agentauthoritychain/client` directly for general Node.js APIs/workflows, `agentauthoritychain` for Python, or the direct HTTP contract for other stacks.\n\nBefore configuration, run the canonical client's credential-free public-test export and require every exact expected result.\n\n- Integration Wiki: https://agentauthoritychain.com/wiki/\n- OpenAPI contract: https://agentauthoritychain.com/openapi.json\n- Machine-readable discovery: https://agentauthoritychain.com/agents.json\n- Canonical source: https://github.com/AgentAuthorityChain/aac\n- Security reporting: https://agentauthoritychain.com/.well-known/security.txt\n\nRequires Node.js 20+. AAC supplies technical verification evidence; it is not legal authority, payment authorization, regulatory certification or independent proof of issuer legitimacy.\n","readmeFilename":"README.md"}