{"_id":"@cubiczan/governed-mcp-gateway","name":"@cubiczan/governed-mcp-gateway","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@cubiczan/governed-mcp-gateway","version":"0.1.0","description":"HTTP MCP gateway: principal on tools/call + SSE, allowlists, vault rotate, CHP gates","mcpName":"io.github.icohangar-ops/governed-mcp-gateway","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"bin":{"governed-mcp-gateway":"bin/governed-mcp-gateway.js"},"scripts":{"build":"tsc -p tsconfig.json","start":"node dist/server.js","dev":"node --import tsx src/server.ts","test":"npm run build && node --import tsx --test test/*.test.ts","prepublishOnly":"npm run build"},"keywords":["mcp","gateway","governance","chp","principal","sse","allowlist","vault"],"author":{"name":"Shyam Desigan","email":"sam@cubiczan.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/icohangar-ops/governed-mcp-gateway.git"},"homepage":"https://github.com/icohangar-ops/governed-mcp-gateway#readme","bugs":{"url":"https://github.com/icohangar-ops/governed-mcp-gateway/issues"},"engines":{"node":">=18"},"devDependencies":{"@types/node":"^22.15.0","tsx":"^4.19.3","typescript":"^5.8.0"},"publishConfig":{"access":"public"},"gitHead":"e46321fd41910452001825476fa52857cf2db5e1","_id":"@cubiczan/governed-mcp-gateway@0.1.0","_nodeVersion":"26.0.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-kazMqKeMhaKxnCdLgVNY044JpLlhCENVbXLGZRThG/tzTL8jTFqCngjpdF8aZ9yrOWT/IgdbQdM8Xqd5TYjyjQ==","shasum":"090058ec59cff2a7682ac757eda5fa34f831cd61","tarball":"https://registry.npmjs.org/@cubiczan/governed-mcp-gateway/-/governed-mcp-gateway-0.1.0.tgz","fileCount":21,"unpackedSize":35464,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCs8rcqygI+SlN9V/AJHARjXJJl3JTd2r5dPPaWemRecAIhAMxzJ1JGm5PmSmB27/1VoS9UNcbJhJriGPAvL9sdQdz9"}]},"_npmUser":{"name":"cubiczan","email":"icohangar@gmail.com"},"directories":{},"maintainers":[{"name":"cubiczan","email":"icohangar@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/governed-mcp-gateway_0.1.0_1787368347288_0.5118360941026503"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-22T03:12:27.082Z","0.1.0":"2026-08-22T03:12:27.426Z","modified":"2026-08-22T03:12:27.631Z"},"maintainers":[{"name":"cubiczan","email":"icohangar@gmail.com"}],"description":"HTTP MCP gateway: principal on tools/call + SSE, allowlists, vault rotate, CHP gates","homepage":"https://github.com/icohangar-ops/governed-mcp-gateway#readme","keywords":["mcp","gateway","governance","chp","principal","sse","allowlist","vault"],"repository":{"type":"git","url":"git+https://github.com/icohangar-ops/governed-mcp-gateway.git"},"author":{"name":"Shyam Desigan","email":"sam@cubiczan.com"},"bugs":{"url":"https://github.com/icohangar-ops/governed-mcp-gateway/issues"},"license":"MIT","readme":"# @cubiczan/governed-mcp-gateway\n\nHTTP MCP **control plane** (default port **7474**). Principal on every `tools/call` and every SSE frame — not a tool catalog.\n\nProduction MCP auth often dies when work hops threads or workers. This gateway resolves a Bearer credential to a **Principal**, injects it into `params._meta.cubiczan.principal`, repeats it on SSE, enforces allowlists, rotates vaulted secrets in place, and runs a lightweight CHP spend gate before priced tools.\n\n## Install / run\n\n```bash\nnpm i -g @cubiczan/governed-mcp-gateway   # or use npx\nnpx -y @cubiczan/governed-mcp-gateway\n# → http://127.0.0.1:7474\n```\n\nFrom source:\n\n```bash\nnpm install\nnpm run build\nnpm start\nnpm test\n```\n\n## Cursor / Claude config\n\nStart the gateway in a terminal (or a process manager), then point the client at the HTTP MCP endpoints:\n\n```json\n{\n  \"mcpServers\": {\n    \"governed-gateway\": {\n      \"url\": \"http://127.0.0.1:7474/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer mcp_agt_payops_demo\"\n      }\n    },\n    \"chp\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@cubiczan/chp-mcp\"]\n    },\n    \"conductor\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@cubiczan/agent-conductor\"]\n    }\n  }\n}\n```\n\nDemo keys: `mcp_agt_payops_demo`, `mcp_agt_research_demo`, `mcp_human_controller_demo`.\n\n## Stack\n\n```text\n┌─────────────────┐     ┌──────────────────────────┐     ┌────────────────────┐\n│ Cursor / Claude │────▶│ governed-mcp-gateway     │────▶│ spend-mandate-plane│\n│ (MCP client)    │ SSE │ :7474  principal+vault   │ opt │ :7475              │\n└────────┬────────┘     └────────────┬─────────────┘     └────────────────────┘\n         │                           │\n         │ stdio                     │ CHP gate (embedded)\n         ▼                           ▼\n┌─────────────────┐     ┌──────────────────────────┐\n│ @cubiczan/      │     │ @cubiczan/chp-mcp        │\n│ agent-conductor │     │ Profile B spend / HITL   │\n└─────────────────┘     └──────────────────────────┘\n```\n\nSister packages: [@cubiczan/chp-mcp](https://github.com/icohangar-ops/cubiczan-chp-mcp), [@cubiczan/agent-conductor](https://github.com/icohangar-ops/agent-conductor), [consensus-hardening-protocol](https://github.com/icohangar-ops/consensus-hardening-protocol).\n\n## API\n\n| Method | Path | Auth | What |\n|--------|------|------|------|\n| `GET` | `/health` | — | `{ ok, service }` |\n| `POST` | `/mcp` | Bearer | JSON-RPC `initialize`, `tools/list`, `tools/call` |\n| `GET` | `/mcp/sse` | Bearer | SSE with principal on `_meta` |\n| `POST` | `/v1/credentials` | Human | Put a named secret |\n| `POST` | `/v1/credentials/:name/rotate` | Human | New hash, same name |\n| `POST` | `/v1/credentials/verify` | — | `{ ok }` |\n| `POST` | `/v1/locks` | Human | CHP approve / reject |\n\n```bash\ncurl -sS -H \"Authorization: Bearer mcp_agt_payops_demo\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/call\",\"params\":{\"name\":\"echo.ping\",\"arguments\":{\"hello\":\"world\"}}}' \\\n  http://127.0.0.1:7474/mcp\n```\n\n## Notes\n\n- This is an **HTTP** MCP gateway (JSON-RPC + SSE), not a stdio MCP process. The `governed-mcp-gateway` bin starts the HTTP server.\n- Shared CHP / HTTP / ledger helpers are **vendored** under `src/shared/` (no `@cubiczan/shared` workspace dep).\n- Optional: set `SPEND_PLANE_URL` to hook the spend-mandate plane before priced tools.\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-2c22f9833a658495f9d3b4e8336c5a6d"}