Provision separate identities
Create least-privilege operator, fence, and auditor principals instead of sharing one universal service token.
IMPLEMENTATION MODEL
Integrating MCPaios means separating proposal submission from target-side execution. The operator asks. A human ratifies. MCP2 evaluates current authority. The fence records ALLOW or DENY. The target executes locally only after a durable ALLOW.
DEVELOPER / FENCE-FIRST / API-V1Conceptual illustrations below are abbreviated, not copy-and-send API payloads. Use the authenticated integration guide for the exact request contract.
{
"actor": "machine:operator:billing-07",
"action": "issue_refund",
"target": "order:18492",
"purpose": "customer_remediation",
"requested_until": "2026-09-05T02:15:00Z",
"policy_digest": "sha256:4d2a…9c11",
"nonce": "req_01K4…7FD"
}{
"decision": "ALLOW",
"grant_id": "grt_01K4…D93",
"authority_state": "CURRENT",
"scope_match": true,
"receipt_id": "rcp_01K4…AE8",
"receipt_durable": true
}INTEGRATION SEQUENCE
Create least-privilege operator, fence, and auditor principals instead of sharing one universal service token.
Bind actor, action, target, purpose, policy context, requested duration, and a replay-resistant nonce.
Treat the request as non-authoritative until an authenticated human has reviewed the exact scope.
Resolve current authority immediately before using the target’s locally held execution credential.
Attach target-reported completion evidence to the earlier durable decision without rewriting it.
FENCE CONTRACT
A proposal response is not a grant. A successful submission only proves the authority plane received the request.
A grant identifier is not a current decision. The fence must resolve present state rather than trusting an identifier supplied by the caller.
An ALLOW without a durable receipt is not executable. Evidence commitment is part of the pre-execution contract.
A decision receipt is not completion evidence. The target must report the outcome against the existing decision receipt.
A retry needs explicit handling. Do not replay a consumed nonce. Multi-model retries require a new run ID; completion retries remain bound to their original receipt.
Tool descriptor drift requires re-evaluation. New MCP tool integrations should bind the approved descriptor/schema fingerprint and fail closed if the live descriptor changes before execution.
Task, Skill, audit, and transport context are evidence—not authority. They may be versioned or fingerprinted into the protected request so reconstruction can explain the surrounding MCP context without allowing that context to manufacture an ALLOW.
MCP TOOL EVIDENCE V2
For new MCP tool integrations, mcpaios.mcp_tool.v2 binds MCP revision, server identity, tool descriptor digest, arguments digest, negotiated-extension digest, and optional Task/Skill/audit context before the target executes.
NO HOSTED /EXECUTE SHORTCUT
MCPaios governs the authority boundary without requiring the agent, model, workflow engine, tool protocol, or protected target to collapse into one vendor runtime. The target uses its own credential only after a receipted ALLOW.
Read the API contracts →OPERATE THE BOUNDARY
The authenticated Control Plane guides service identity creation, one-time credential custody, proposal submission, and fence configuration.