policy-gate
Deterministic allow/require_approval/deny verdicts for agent actions, before they happen.
Should I use this
Quality & Safety
Findings (1)
- LOWin policy_rules
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"policy-gate": {
"url": "https://policy-gate.3labsio.workers.dev/mcp"
}
}
}Remote endpoints
https://policy-gate.3labsio.workers.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (4)
⚪policy_example
Free. Worked allow/require_approval/deny verdicts from the live policy engine, so you can judge the service before paying for it.
Input Schema
{
"type": "object",
"properties": {}
}⚪policy_rules
Free. The full built-in policy: every tier, rule, condition and rationale. Nothing about how a verdict is reached is hidden.
Input Schema
{
"type": "object",
"properties": {}
}🟢policy_check(request, policy_id, policy, ledger)
Evaluate a proposed agent action against a policy and return allow / require_approval / deny with the matched rule and rationale. Paid per call via x402 ($0.005 USDC on Base); returns signing instructions when unpaid.
Input Schema
{
"type": "object",
"properties": {
"request": {
"type": "object",
"required": [
"action"
],
"properties": {
"action": {
"type": "string",
"description": "Dotted action id, e.g. payments.send"
},
"actor": {
"type": "string"
},
"params": {
"type": "object"
}
}
},
"policy_id": {
"type": "string",
"description": "Built-in policy id; see policy_rules. \"default-action-tiers-capped\" adds a cumulative spend bound."
},
"policy": {
"type": "object",
"description": "Your own policy document, evaluated instead of ours"
},
"ledger": {
"type": "object",
"description": "Optional cumulative exposure for the window. A per-action gate cannot see repetition: 49 payments of $40 each pass a $50 rule individually. Omit it and any policy declaring a cumulative bound returns deny with ledger_required — a cap you can skip by omitting state is decorative. Explicit zeros are an answer; an absent object is not.",
"properties": {
"committed_usd": {
"type": "number",
"description": "Spend already known to have happened in the window"
},
"intended_usd": {
"type": "number",
"description": "Dispatched and not yet confirmed. Counts toward the bound, so a burst in flight is not invisible to it."
},
"unknown_usd": {
"type": "number",
"description": "Dispatched and never resolved. Any value above zero denies with unresolved_intent, regardless of headroom: the system has lost track of this quantity. It closes by observing the target, never by a clock."
}
}
}
},
"required": [
"request"
]
}🟡first_42_sponsor
Pay Fieldproof $42. Returns every live rail: Stripe card_uri, EIP-681 usdc_uri, BIP-21 btc_uri, x402 POST /v1/sponsor, Zelle, and GET /v1/invoice. One settlement meets the first-$42 bar.
Input Schema
{
"type": "object",
"properties": {}
}Community
Evidence