Skip to content
MCPaiosMachine Authority
Explore
MCPaios/Documentation

PUBLIC TECHNICAL DOCUMENTATION

Integrate the authority boundary without surrendering the target runtime.

MCPaios exposes machine-facing contracts for proposal, exact grant issuance, current verification, completion, receipt retrieval, reconstruction, and reporting. Protected targets retain their credentials and execute locally.

DOCS / AUTHORITY-API-V1 / MCP2-CORE

SERVICE ROLES

Separate principals for separate authority jobs.

Operator

Submits proposals, issues already-ratified grants, and reads grants. It cannot manufacture human authority.

Fence

Verifies an exact request and completes an existing ALLOW receipt. It cannot grant or revoke authority.

Auditor

Reads receipts, reconstruction, reports, and bounded authority evidence. It cannot mutate the authority record.

AUTHENTICATION BOUNDARY

Every protected machine route is tenant-bound and bearer-authenticated.

Authorization: Bearer <mcpaios-service-token>
X-MCPaios-Tenant: <tenant-id>
Content-Type: application/json

The public /api/v1/protocol declaration does not require a bearer credential. The plaintext bearer is hashed in the server runtime and is not persisted by the HTTP layer. The service gateway enforces tenant, role, status, and expiry.

AUTHORITY API V1

Current Authority API routes.

ROLEMETHODROUTEPURPOSE
OperatorPOST/api/v1/proposals

Submit a bounded machine proposal.

OperatorPOST/api/v1/grants

Issue the exact already-ratified grant.

OperatorGET/api/v1/grants/{grantId}

Read a bounded grant.

FencePOST/api/v1/multi-model/attempts/claim

Claim one exact multi-model attempt before verification.

FencePOST/api/v1/verify

Atomically verify current authority and commit the decision receipt.

FencePOST/api/v1/receipts/{receiptId}/complete

Bind target-reported completion to an ALLOW receipt.

AuditorGET/api/v1/receipts/{receiptId}

Read canonical decision evidence.

AuditorGET/api/v1/reconstruct/{receiptId}

Reconstruct the authority and execution path.

AuditorGET/api/v1/report

Read tenant authority and ledger status.

FENCE VERIFICATION

Resolve current authority immediately before the side effect.

Conceptual pseudocode, not an SDK invocation. Reject transport errors and malformed responses before local execution. The real response uses decision.decision, receipted, and receipt_id. Multi-model legs must first claim their exact attempt and use the declared mcpaios.multi_model_leg.v1 extension; a retry requires a new run ID.

const decision = await mcpaios.verify({
  ...exactVerificationRequest
});

if (decision.decision?.decision !== "ALLOW" ||
    decision.receipted !== true || !decision.receipt_id) {
  return denyWithoutExecution(decision);
}

const outcome = await target.executeLocally();
await mcpaios.complete(decision.receipt_id, outcome);
// If completion cannot be confirmed, reconcile before retrying the action.

EXECUTION BOUNDARY

There is deliberately no hosted `/execute` route.

A protected target remains responsible for execution after it receives a receipted ALLOW. MCPaios governs authority and evidence; it does not take possession of target credentials or become a generic remote execution service.

Connection ≠ authority ≠ execution

Keep the tool connection, current authority decision, and protected side effect as inspectable, independently governed steps.

01

CONCEPTUAL START

Read how the authority lifecycle works.

Authority lifecycle →
02

IMPLEMENTATION START

Map the roles and target fence.

Developer integration →

OPERATE THE BOUNDARY

The documentation is public. Authority operations remain protected.

Sign in to provision machine identities, submit governed work, inspect grants, and review evidence.

Open the Control Plane