{"_id":"@agentvalet/mcp-broker","_rev":"2-d4e9257b89eeda7d5a7b1852f38c6760","name":"@agentvalet/mcp-broker","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@agentvalet/mcp-broker","version":"0.1.0","keywords":["mcp","modelcontextprotocol","credential-broker","policy","authorization","authzen","agentvalet"],"license":"MIT","_id":"@agentvalet/mcp-broker@0.1.0","maintainers":[{"name":"edwinashdown","email":"edwin@aifirstpartner.com"}],"homepage":"https://github.com/agentvalet/agentvalet#readme","bugs":{"url":"https://github.com/agentvalet/agentvalet/issues"},"dist":{"shasum":"1136fdb44147c9112685451e80f028ca3a760594","tarball":"https://registry.npmjs.org/@agentvalet/mcp-broker/-/mcp-broker-0.1.0.tgz","fileCount":90,"integrity":"sha512-iHBzpFGY1UAJ28msCfb3I7KMJezpf8IBj5F7HxZSKkwl60AEDSaQkpBaRbyoGOGTMCvu+twtSJOG1MbMRwYX5A==","signatures":[{"sig":"MEYCIQDse5o68dk9yiPJ0LVQl7RAFrI8pdtw2TCtpwlRTVUPTAIhAJr4eCjEAFPRxyQpLDhj1Qr4QVhS1k47lXRhd+O8U7cG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":148748},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"exports":{".":"./dist/index.js"},"gitHead":"50558330aa7b5e8c676630cf9062ebcd2cf54345","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"pnpm run build"},"_npmUser":{"name":"edwinashdown","email":"edwin@aifirstpartner.com"},"repository":{"url":"git+https://github.com/agentvalet/agentvalet.git","type":"git","directory":"packages/mcp-broker"},"_npmVersion":"10.9.7","description":"Embeddable credential broker and policy enforcement for third-party MCP servers. Wrap once; every tool is policy-checked, credential-injected, and audited.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"zod":"^3.25.0","vitest":"^1.5.0","typescript":"^5.4.0","@types/node":"^20.0.0","@modelcontextprotocol/sdk":"^1.29.0"},"peerDependencies":{"@modelcontextprotocol/sdk":"^1.29.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-broker_0.1.0_1783227140953_0.27669556568538","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentvalet/mcp-broker","version":"0.1.1","description":"Embeddable credential broker and policy enforcement for third-party MCP servers. Wrap once; every tool is policy-checked, credential-injected, and audited.","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":"./dist/index.js"},"scripts":{"build":"tsc","dev":"tsc --watch","typecheck":"tsc --noEmit","test":"vitest run","prepublishOnly":"pnpm run build"},"peerDependencies":{"@modelcontextprotocol/sdk":"^1.29.0"},"devDependencies":{"@modelcontextprotocol/sdk":"^1.29.0","@types/node":"^20.0.0","typescript":"^5.4.0","vitest":"^1.5.0","zod":"^3.25.0"},"engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/AgentValet/AgentValet.git","directory":"packages/mcp-broker"},"keywords":["mcp","modelcontextprotocol","credential-broker","policy","authorization","authzen","agentvalet"],"license":"MIT","_id":"@agentvalet/mcp-broker@0.1.1","gitHead":"6c087508199244c6620f87454324ebe4115300df","bugs":{"url":"https://github.com/AgentValet/AgentValet/issues"},"homepage":"https://github.com/AgentValet/AgentValet#readme","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-haKH97iQw5unf/YPMVEtqLQGke+StlNVTRpEL0qBmPbg6gb3OQ6gXU46HTVdgZyPOZcrp7nRPNrL5Thqx9HDmw==","shasum":"cd9b57116c6d947b25f1135da8a3d8ad9f4138ef","tarball":"https://registry.npmjs.org/@agentvalet/mcp-broker/-/mcp-broker-0.1.1.tgz","fileCount":90,"unpackedSize":148748,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentvalet%2fmcp-broker@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIH+H4wRzpLsl/w1HHUpPuZdStAxBl+Oedc8cpW+t/52lAiBXPxw5tJ2euHtEpvJJe05Mb+IZCS2Ko2gjj5r8KerWTw=="}]},"_npmUser":{"name":"edwinashdown","email":"edwin@aifirstpartner.com"},"directories":{},"maintainers":[{"name":"edwinashdown","email":"edwin@aifirstpartner.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-broker_0.1.1_1783230811395_0.26988861529937513"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-05T04:52:20.772Z","modified":"2026-07-05T05:53:31.834Z","0.1.0":"2026-07-05T04:52:21.107Z","0.1.1":"2026-07-05T05:53:31.543Z"},"bugs":{"url":"https://github.com/AgentValet/AgentValet/issues"},"license":"MIT","homepage":"https://github.com/AgentValet/AgentValet#readme","keywords":["mcp","modelcontextprotocol","credential-broker","policy","authorization","authzen","agentvalet"],"repository":{"type":"git","url":"git+https://github.com/AgentValet/AgentValet.git","directory":"packages/mcp-broker"},"description":"Embeddable credential broker and policy enforcement for third-party MCP servers. Wrap once; every tool is policy-checked, credential-injected, and audited.","maintainers":[{"name":"edwinashdown","email":"edwin@aifirstpartner.com"}],"readme":"# @agentvalet/mcp-broker\n\nAn embeddable credential broker and policy enforcement wrapper for MCP servers.\nWrap your server once. Every tool you register after that is policy-checked,\ngets a resolved narrow credential injected at call time, and emits an audit\nrecord. The agent never holds the downstream secret.\n\nIt's free and open source. The paid layer is the hosted AgentValet control\nplane (managed policy, push approvals, SSO, central audit, the vault), and it\nplugs in through the same four interfaces this package defines.\n\nThis is the mirror image of `@agentvalet/mcp-server`: that package lets an agent\ncall platforms through the AgentValet proxy, whereas this package lets you embed\nAgentValet enforcement inside your own MCP server.\n\n## Install\n\n```bash\nnpm install @agentvalet/mcp-broker\n```\n\n`@modelcontextprotocol/sdk` is a peer dependency you already have. The broker\nitself has zero runtime dependencies.\n\n## Three lines to adopt\n\n```typescript\nimport { McpServer } from \"@modelcontextprotocol/sdk/server/mcp.js\";\nimport { broker } from \"@agentvalet/mcp-broker\";\n\nconst server = new McpServer({ name: \"github-tools\", version: \"1.0.0\" });\n\n// Wrap once. Every tool registered after this is policy-checked,\n// credential-injected, and audited.\nbroker(server, {\n  policy: \"file:./policy.yaml\",          // or \"authzen:https://pdp.example.com\"\n                                          // or \"agentvalet:\" (hosted)\n  secrets: \"env:\",                        // or \"file:./secrets.enc\"\n  audit: \"jsonl:./audit.log\",             // or \"agentvalet:\" (hosted)\n});\n\nserver.tool(\"create_issue\", schema, async (args, ctx) => {\n  // ctx.credential is the resolved, narrow secret for this call only.\n  return await githubClient(ctx.credential.token).issues.create(args);\n});\n```\n\nYou don't restructure your handlers. `broker()` intercepts tool registration, so\nregister your tools after the wrap and each one runs inside the enforcement\npipeline:\n\n```\nresolve identity -> evaluate policy -> (approval if required) ->\nresolve credential -> invoke handler -> redact -> audit\n```\n\n## Fail closed by default\n\n`failMode` defaults to `\"closed\"`. If the policy source is unreachable, the call\nis denied. `\"open\"` exists for a dev loop only, and it logs loudly on every\nrequest. A security tool that fails open is not a security tool.\n\n## The same policy semantics as the hosted plane, provably\n\nThe `file:` policy source evaluates your local YAML with a byte-identical copy of\nthe exact policy kernel the hosted AgentValet plane runs. The copy is generated\nby a sync script and a contract test fails the build if it ever drifts. So a\nrule you write locally decides allow, deny, or require_approval with the same\nsemantics you'd get in the cloud. There's no second implementation to disagree\nwith.\n\n## Local policy is small on purpose\n\n```yaml\nversion: 1\ndefaults:\n  effect: deny\nrules:\n  - tool: create_issue\n    effect: allow\n    credential: github_issues_rw\n  - tool: delete_repo\n    effect: require_approval\n    credential: github_admin\n```\n\nOne file, one rule per tool, deny by default. There are no environments, no\ninheritance, no templating, and no record of who changed a rule. That's a\ndeliberate limit, not a missing feature. The moment you need any of those, you've\noutgrown a single file, and that's what the hosted plane is for. This format\nwill never grow them.\n\n## The four interfaces\n\nEvery escape hatch is an interface, and the hosted implementations are just the\nbest implementation of each:\n\n- `PolicySource` decides allow, deny, or require_approval for a call.\n- `SecretSource` resolves a narrow credential and honours scope narrowing from\n  the decision's obligations.\n- `ApprovalProvider` gates a call on a human decision. The reference\n  implementation is a CLI y/n prompt with a timeout; the hosted one is push\n  approval to the owner's devices.\n- `AuditSink` receives a stable, versioned event carrying an args fingerprint,\n  never the raw arguments.\n\nPass a scheme string (`\"file:\"`, `\"env:\"`, `\"jsonl:\"`, `\"authzen:\"`,\n`\"agentvalet:\"`) or your own implementation object. Both work everywhere.\n\n## What the audit records\n\nEach tool call emits one event: caller identity, server and tool, an args\nfingerprint (never the raw args), the decision and policy version, the credential\nscope, latency, and the outcome. Every outcome is covered, including denials,\napproval timeouts, and handler errors.\n\n## License\n\nMIT.\n","readmeFilename":"README.md"}