Skip to content
MCPaiosMachine Authority
Explore

FREE CORE MACHINE AUTHORITY

Authority for machines that act.

MCPaios governs authority as the operational implementation of the MCP2 Machine Authority & Evidence Profile. It separates what a machine can technically reach from what it is authorized to do—and produces the evidence needed to prove the difference later.

Core MCPaios access is free. External infrastructure and other products may have their own costs.

AUTHORITY FENCE / ILLUSTRATIONEXAMPLE
Machine requestactor × action × target × purpose × time
MCP2 DECISIONALLOWreceipt committed first
Protected targetLocal execution after current ALLOW
Decision receiptCompletion evidenceReconstruction
Bounded before execution.Revocable before the next action.Decision receipted before execution.Reconstructible later.

THE OPERATING QUESTION

Does this machine possess valid, bounded, unrevoked authority to perform this exact action against this exact target now?

And can that decision later be proven?

SYSTEM INDEX

One authority system. Distinct technical layers.

Explore the protocol, operating plane, trust boundaries, and proof model as separate parts of one governed execution path.

AUTHORITY IS NOT CAPABILITY

A credential may make execution possible. It does not make execution authorized.

MCPaios keeps the execution credential at the target boundary and evaluates authority independently. A machine proposal cannot ratify itself. A stale grant cannot become current by being replayed. A receipt cannot be substituted for the decision it was meant to record.

Examine the trust boundaries →
CAPABILITYAUTHORITYRESULT
presentabsentDENY
presentexpiredDENY
presentrevokedDENY
presentcurrent + exactALLOW

REQUEST → RECORD

A complete machine-authority lifecycle.

Machine proposal, human decision, bounded grant, fence verification, local execution, receipt, reconstruction, and revocation each perform a separate job. No stage silently authorizes the next.

01Proposal
02Human decision
03Bounded grant
04Fence verification
05Execution
06Receipt
07Reconstruction
08Revocation
Read the full lifecycle →

HISTORICAL PROOF · SEPTEMBER 3, 2026

ALLOW before local execution. DENY after human revocation.

A preserved September 3 production proof exercised machine proposal, human ratification, exact grant issuance, receipted ALLOW, local completion, reconstruction, revocation, later GRANT_NOT_ACTIVE DENY, and retirement of the temporary service credentials.

Inspect the sanitized evidence →
2human memberships
2decision receipts
1bound completion
0active proof credentials

BUILT FOR CONSEQUENTIAL SYSTEMS

For machines that can do more than generate text.

Organizations deploying agents, workflow operators, infrastructure teams, regulated systems, and developers can add a provable authority decision without surrendering their target runtime.

AGENTSAUTOMATED WORKFLOWSINFRASTRUCTUREREGULATED SYSTEMSDEVELOPERS
Explore the operating cases →

OPEN PROTOCOL · OPERATIONAL PRODUCT

MCP2 defines machine authority. MCPaios puts it to work.

MCP2 — Machine Authority & Evidence Profile defines how bounded, current, revocable machine authority is evaluated and reconstructed. It is not “MCP version 2,” and it does not replace the Model Context Protocol.

MCPaios supplies the human and machine operating surfaces around that protocol: proposals, identities, ratification, grants, execution fences, receipts, revocation, reports, and reconstruction.

Read the protocol overview →

HUMAN AUTHORITY PLANE

Operate machine authority from one controlled record.

Review what machines request, see what they hold, revoke what must stop, and reconstruct what happened.

Sign in to the Control Plane