policy-gate

Deterministic allow/require_approval/deny verdicts for agent actions, before they happen.

Should I use this

Quality & Safety

B
Description quality
88%
Schema completeness
46%
Naming quality
85%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'policy_rules' description lacks action verbin policy_rules

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~548Tokens (tool definitions)
~1.1 KBTypical response size
Minimal attention impact (0.43% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "policy-gate": {
      "url": "https://policy-gate.3labsio.workers.dev/mcp"
    }
  }
}

Remote endpoints

https://policy-gate.3labsio.workers.dev/mcpstreamable-http

What it can do

Tool inventory

Tools (4)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪policy_example

Free. Worked allow/require_approval/deny verdicts from the live policy engine, so you can judge the service before paying for it.

Input Schema

{
  "type": "object",
  "properties": {}
}
⚪policy_rules

Free. The full built-in policy: every tier, rule, condition and rationale. Nothing about how a verdict is reached is hidden.

Input Schema

{
  "type": "object",
  "properties": {}
}
🟢policy_check(request, policy_id, policy, ledger)

Evaluate a proposed agent action against a policy and return allow / require_approval / deny with the matched rule and rationale. Paid per call via x402 ($0.005 USDC on Base); returns signing instructions when unpaid.

Input Schema

{
  "type": "object",
  "properties": {
    "request": {
      "type": "object",
      "required": [
        "action"
      ],
      "properties": {
        "action": {
          "type": "string",
          "description": "Dotted action id, e.g. payments.send"
        },
        "actor": {
          "type": "string"
        },
        "params": {
          "type": "object"
        }
      }
    },
    "policy_id": {
      "type": "string",
      "description": "Built-in policy id; see policy_rules. \"default-action-tiers-capped\" adds a cumulative spend bound."
    },
    "policy": {
      "type": "object",
      "description": "Your own policy document, evaluated instead of ours"
    },
    "ledger": {
      "type": "object",
      "description": "Optional cumulative exposure for the window. A per-action gate cannot see repetition: 49 payments of $40 each pass a $50 rule individually. Omit it and any policy declaring a cumulative bound returns deny with ledger_required — a cap you can skip by omitting state is decorative. Explicit zeros are an answer; an absent object is not.",
      "properties": {
        "committed_usd": {
          "type": "number",
          "description": "Spend already known to have happened in the window"
        },
        "intended_usd": {
          "type": "number",
          "description": "Dispatched and not yet confirmed. Counts toward the bound, so a burst in flight is not invisible to it."
        },
        "unknown_usd": {
          "type": "number",
          "description": "Dispatched and never resolved. Any value above zero denies with unresolved_intent, regardless of headroom: the system has lost track of this quantity. It closes by observing the target, never by a clock."
        }
      }
    }
  },
  "required": [
    "request"
  ]
}
🟡first_42_sponsor

Pay Fieldproof $42. Returns every live rail: Stripe card_uri, EIP-681 usdc_uri, BIP-21 btc_uri, x402 POST /v1/sponsor, Zelle, and GET /v1/invoice. One settlement meets the first-$42 bar.

Input Schema

{
  "type": "object",
  "properties": {}
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded4 tools
verifiedversion not recorded4 tools