{"_id":"@allowly/mcp","_rev":"5-e1d751316684f086017044b69663a66f","name":"@allowly/mcp","dist-tags":{"bootstrap":"0.2.0-bootstrap.0","latest":"0.3.2"},"versions":{"0.2.0-bootstrap.0":{"name":"@allowly/mcp","version":"0.2.0-bootstrap.0","license":"MIT","_id":"@allowly/mcp@0.2.0-bootstrap.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"dist":{"shasum":"d69f05055cce86b79db1be46143b7e01436c5881","tarball":"https://registry.npmjs.org/@allowly/mcp/-/mcp-0.2.0-bootstrap.0.tgz","fileCount":6,"integrity":"sha512-/3lLm1GEyTW4PNuyYUmpt7qTnSaTrJjB2a1Q2r+xloh/RIcRbWM8HNyCsRLd4ZmIQCdNIkMXeTWRGjxKwRE0Qg==","signatures":[{"sig":"MEUCIQC7p36qEoOEoRruMukUVAHqPgS0pcPIjkO88UsScX8xvQIgI28RaaY3+/HxRiHcchcPJgzvg2yaegXPDwg/k+3XSHo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9913},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"59887721fc18fdefd9fda064d24c63c964193f9b","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean --external @allowly/sdk --external @modelcontextprotocol/sdk && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const pkg = await import('@allowly/mcp'); if (typeof pkg.AllowlyMCPMiddleware !== 'function') process.exit(1)\"","typecheck":"tsc --noEmit"},"_npmUser":{"name":"yevgeny.alianov","email":"support@allowly.ai"},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Allowly guardrail middleware for MCP tool calls","directories":{},"_nodeVersion":"24.18.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40","@allowly/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.30.0"},"peerDependencies":{"@allowly/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0-bootstrap.0_1785387063608_0.10081432031113469","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@allowly/mcp","version":"0.2.0","license":"MIT","_id":"@allowly/mcp@0.2.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"dist":{"shasum":"425e5fb8c2a6ccbc468339a48ac9c49657472c92","tarball":"https://registry.npmjs.org/@allowly/mcp/-/mcp-0.2.0.tgz","fileCount":6,"integrity":"sha512-RECtDyP+fCumT65h6HlCugri6eqhQ81p0DHpX1f9HMkIXlRs/MRRQAyyHsyOWBqKrJrF9XkpayM0eFppyE0S+g==","signatures":[{"sig":"MEYCIQDgbNsb/M5YIBIcXnLY4AJYIj2uSSUpE4YQ1qmvoD/sMwIhAIiRX7JreeTzpxeSIQOA35wXjcT2FeTp5PAjpmRnLMfm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fmcp@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9901},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"59887721fc18fdefd9fda064d24c63c964193f9b","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean --external @allowly/sdk --external @modelcontextprotocol/sdk && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const pkg = await import('@allowly/mcp'); if (typeof pkg.AllowlyMCPMiddleware !== 'function') process.exit(1)\"","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7fad18f6-218d-4981-9bb2-568940f21b4d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Allowly guardrail middleware for MCP tool calls","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40","@allowly/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.30.0"},"peerDependencies":{"@allowly/sdk":"^0.2.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0_1785387477465_0.9737303382357179","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@allowly/mcp","version":"0.3.0","license":"MIT","_id":"@allowly/mcp@0.3.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"dist":{"shasum":"7ad563f4f0d33cf8d69b930b81d18d1995554bcc","tarball":"https://registry.npmjs.org/@allowly/mcp/-/mcp-0.3.0.tgz","fileCount":6,"integrity":"sha512-Ln7my3CR9DADcdBeu+RXxGtYSy8bZz31YVnlcz7pyhkSM0F7ehnyoXxIZUxyUECeY/BAXXCuEPxPe/7CD3quHA==","signatures":[{"sig":"MEUCIQDf0YF0FwjoOOawiTX4p9BhrBM1ocI/vDCesHGT9nJxVwIgNHYe8xuJI/40pgOrxG+6fl/G+VFj5HHy0p460l/UFzg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fmcp@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9901},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b4789b751d233a9393ac9394d87d3ad9019bcf2e","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean --external @allowly/sdk --external @modelcontextprotocol/sdk && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const pkg = await import('@allowly/mcp'); if (typeof pkg.AllowlyMCPMiddleware !== 'function') process.exit(1)\"","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7fad18f6-218d-4981-9bb2-568940f21b4d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Allowly guardrail middleware for MCP tool calls","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40","@allowly/sdk":"^0.3.0","@modelcontextprotocol/sdk":"^1.30.0"},"peerDependencies":{"@allowly/sdk":"^0.3.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.0_1785656700777_0.4551738904178879","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@allowly/mcp","version":"0.3.1","license":"MIT","_id":"@allowly/mcp@0.3.1","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"dist":{"shasum":"c8cd5f3bf947011f847faceb442c3221e838e314","tarball":"https://registry.npmjs.org/@allowly/mcp/-/mcp-0.3.1.tgz","fileCount":6,"integrity":"sha512-s4N5lyvRHhrAE81riZdk0qxU7Vwx7dQVMaN4IzGdNKr85TXR/6mxWseutnhxEW1qTa2RAupksRA0Whg4BORtVg==","signatures":[{"sig":"MEUCIBtFJwfDVIEmg7IVTYM11lx4bNLFsZRNwJU1xUnTz9tNAiEAukll1H8VO9+XqX5dBZntoW/8hecUgXdOxvrXGDEIsEo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fmcp@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9901},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"07fd83e13e7269dcadf24217e871ea3103d0a02e","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean --external @allowly/sdk --external @modelcontextprotocol/sdk && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const pkg = await import('@allowly/mcp'); if (typeof pkg.AllowlyMCPMiddleware !== 'function') process.exit(1)\"","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7fad18f6-218d-4981-9bb2-568940f21b4d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Allowly guardrail middleware for MCP tool calls","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40","@allowly/sdk":"^0.3.1","@modelcontextprotocol/sdk":"^1.30.0"},"peerDependencies":{"@allowly/sdk":"^0.3.1","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.1_1785895731930_0.40664342074970183","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"_id":"@allowly/mcp@0.3.2","bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"dist":{"shasum":"56105c9f4c505f4f742283f781fa001d34c11601","tarball":"https://registry.npmjs.org/@allowly/mcp/-/mcp-0.3.2.tgz","fileCount":6,"integrity":"sha512-SwNn9R81C/Npp4tYHym3sCwGpUB2uKCyYo3rL3Zd8i4QsQ/St+UXJXYR8Qp1mP9s/RFH+JR6OM7faSUfEZJFIw==","signatures":[{"sig":"MEYCIQCJmDuwj0sfT1WOKVtqbz4a19Lyk+ePMBM4L3+5BATlLwIhANJcvarcsVthiCuJLZUu0u7Fzgcis2lBdGcXsbz+ojSe","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHSSwE8QeFhcuVQBkyD+5cXRw8O8XjNOLyzx5aaVLs/aAiEAlrdfQEybeaXlf0lk95WEWCTFVLC3Q+UzoOyjInguD7I="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fmcp@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":10419},"main":"./dist/index.js","name":"@allowly/mcp","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"8a6cb08039e5f3245cf821f5eb9083287df5d2f1","license":"MIT","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean --external @allowly/sdk --external @modelcontextprotocol/sdk && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const pkg = await import('@allowly/mcp'); if (typeof pkg.AllowlyMCPMiddleware !== 'function') process.exit(1)\"","typecheck":"tsc --noEmit"},"version":"0.3.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7fad18f6-218d-4981-9bb2-568940f21b4d"}},"homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"_npmVersion":"11.19.0","description":"Allowly guardrail middleware for MCP tool calls","directories":{},"maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40","@allowly/sdk":"^0.5.0","@modelcontextprotocol/sdk":"^1.30.0"},"peerDependencies":{"@allowly/sdk":"^0.3.1 || ^0.4.0 || ^0.5.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.3.2_1789594228663_0.5432155556072225"}}},"time":{"created":"2026-07-30T04:51:03.393Z","modified":"2026-09-16T21:30:29.123Z","0.2.0-bootstrap.0":"2026-07-30T04:51:03.732Z","0.2.0":"2026-07-30T04:57:57.598Z","0.3.0":"2026-08-02T07:45:00.914Z","0.3.1":"2026-08-05T02:08:52.085Z","0.3.2":"2026-09-16T21:30:28.757Z"},"bugs":{"url":"https://github.com/Allowly-AI/allowly-mcp/issues"},"license":"MIT","homepage":"https://github.com/Allowly-AI/allowly-mcp#readme","repository":{"url":"git+https://github.com/Allowly-AI/allowly-mcp.git","type":"git"},"description":"Allowly guardrail middleware for MCP tool calls","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"readme":"# @allowly/mcp\n\nAllowly guardrail middleware for MCP tool calls.\n\nUse this package when you already have an MCP server and want each tool call to pass through Allowly before the tool runs. The MCP tool name is sent to Allowly as the action name.\n\nThis is the TypeScript MCP middleware, separate from `@allowly/sdk` because npm has no extras. The Python equivalent ships inside the Python SDK as `allowly[fastmcp]`.\n\n## Install\n\n```bash\nnpm install @allowly/mcp @allowly/sdk @modelcontextprotocol/sdk\n```\n\n`@allowly/mcp` is ESM-only and requires Node.js 20 or newer.\n\n## Usage\n\n```ts\nimport { McpServer } from \"@modelcontextprotocol/sdk/server/mcp.js\";\nimport { AllowlyMCPMiddleware } from \"@allowly/mcp\";\n\nconst mcp = new McpServer({ name: \"my-agent\", version: \"1.0.0\" });\nregisterAgentTools(mcp);\n\nconst allowly = new AllowlyMCPMiddleware({\n  apiKey: process.env.ALLOWLY_API_KEY!,\n  userIdFn: ({ extra }) => {\n    const userId = extra.authInfo?.extra?.userId;\n    return typeof userId === \"string\" ? userId : null;\n  },\n  authorizationIdFn: async (userId) => {\n    return getAuthorizationIdForUser(userId);\n  },\n});\n\nallowly.attach(mcp.server);\n```\n\nRegister tools before calling `attach()`; the middleware fails fast when there is no tool handler to wrap.\n\n## Behavior\n\n- `allow`: the original MCP tool handler runs.\n- `deny`: the middleware returns an MCP error response with the Allowly reason.\n- `confirm`: the middleware returns a confirmation payload with `confirm_nonce`,\n  `confirm_expires_at`, and `confirm_prompt_hint`; do not present an expired prompt.\n- `escalate`: the middleware returns an escalation payload with `escalation_id`.\n\nThe middleware calls:\n\n```ts\nallowly.check({\n  authorizationId,\n  actions: [toolName],\n});\n```\n\nAuthorization creation stays outside this package. Store the user's Allowly authorization ID in your app, then resolve it in `authorizationIdFn`.\n\n## SEAL evidence is explicit\n\nThis middleware does not send MCP tool arguments or results to SEAL. If your\nworkflow needs signed evidence for a JSON record, post that chosen record to a\nprivate managed SEAL webhook after the tool completes. Keep the original JSON\nin your workflow and keep the webhook URL out of MCP arguments, logs, tickets,\nand source control. The webhook path and retry rules are documented at\n[allowly.ai/docs/api-reference/seal](https://allowly.ai/docs/api-reference/seal/).\n\n## User IDs\n\nBy default, the middleware does not trust tool arguments for identity. Provide `userIdFn` and read identity from the MCP handler's trusted `extra` context, such as `extra.authInfo` or `extra.sessionId`.\n","readmeFilename":"README.md"}