Skip to content
MCPaiosMachine Authority
Explore
MCPaios/Developers

IMPLEMENTATION MODEL

Put the authority check where the side effect begins.

Integrating MCPaios means separating proposal submission from target-side execution. The operator asks. A human ratifies. MCP2 evaluates current authority. The fence records ALLOW or DENY. The target executes locally only after a durable ALLOW.

DEVELOPER / FENCE-FIRST / API-V1

Conceptual illustrations below are abbreviated, not copy-and-send API payloads. Use the authenticated integration guide for the exact request contract.

Illustrative proposal fieldsmachine → authority plane
{
  "actor": "machine:operator:billing-07",
  "action": "issue_refund",
  "target": "order:18492",
  "purpose": "customer_remediation",
  "requested_until": "2026-09-05T02:15:00Z",
  "policy_digest": "sha256:4d2a…9c11",
  "nonce": "req_01K4…7FD"
}
Illustrative decision fieldsauthority plane → fence
{
  "decision": "ALLOW",
  "grant_id": "grt_01K4…D93",
  "authority_state": "CURRENT",
  "scope_match": true,
  "receipt_id": "rcp_01K4…AE8",
  "receipt_durable": true
}

INTEGRATION SEQUENCE

Five steps from machine request to completed evidence.

1

Provision separate identities

Create least-privilege operator, fence, and auditor principals instead of sharing one universal service token.

2

Submit an exact proposal

Bind actor, action, target, purpose, policy context, requested duration, and a replay-resistant nonce.

3

Wait for human ratification

Treat the request as non-authoritative until an authenticated human has reviewed the exact scope.

4

Verify at the target fence

Resolve current authority immediately before using the target’s locally held execution credential.

5

Complete the receipt chain

Attach target-reported completion evidence to the earlier durable decision without rewriting it.

FENCE CONTRACT

What the target must never infer.

A proposal response is not a grant. A successful submission only proves the authority plane received the request.

A grant identifier is not a current decision. The fence must resolve present state rather than trusting an identifier supplied by the caller.

An ALLOW without a durable receipt is not executable. Evidence commitment is part of the pre-execution contract.

A decision receipt is not completion evidence. The target must report the outcome against the existing decision receipt.

A retry needs explicit handling. Do not replay a consumed nonce. Multi-model retries require a new run ID; completion retries remain bound to their original receipt.

Tool descriptor drift requires re-evaluation. New MCP tool integrations should bind the approved descriptor/schema fingerprint and fail closed if the live descriptor changes before execution.

Task, Skill, audit, and transport context are evidence—not authority. They may be versioned or fingerprinted into the protected request so reconstruction can explain the surrounding MCP context without allowing that context to manufacture an ALLOW.

MCP TOOL EVIDENCE V2

Bind the exact upstream tool surface that was approved.

For new MCP tool integrations, mcpaios.mcp_tool.v2 binds MCP revision, server identity, tool descriptor digest, arguments digest, negotiated-extension digest, and optional Task/Skill/audit context before the target executes.

Read the MCP2 boundary →

NO HOSTED /EXECUTE SHORTCUT

Bring your own agent stack and execution runtime.

MCPaios governs the authority boundary without requiring the agent, model, workflow engine, tool protocol, or protected target to collapse into one vendor runtime. The target uses its own credential only after a receipted ALLOW.

Read the API contracts →
AgentsWorkflowsMCP toolsAPIsDatabasesInfrastructure

OPERATE THE BOUNDARY

Provision identities and inspect the live integration surface.

The authenticated Control Plane guides service identity creation, one-time credential custody, proposal submission, and fence configuration.

Open the Control Plane