Trustless governance for MCP services
A service (an MCP server) shouldn't take a caller's word for it. agentsafe-mcp-guard lets the service re-verify an agent's signed authorization against the agent's own signed policy bundle — with no trust in the caller and no round-trip to us.
How it works
The agent presents a signed authorize request. Your service verifies the signature against the key in the agent's DID, re-evaluates the request with the same deterministic policy-core the gate runs, and proceeds only on allow — so a rogue agent that skips the check can't get your service to act. A spend cap is only as good as the amount it's checked against: the amount-unknown atom blocks by default when a tool call's value isn't determinable, rather than letting it slip past an untested cap the way a signed-bytes or nested-payload payment previously could.
What the MCP guard gives you
- verifyRequest() — trustless re-evaluation
- guardIncomingTool() — wrap a service tool
- handshakeChallenge / handshakeVerify — mutual DID proof
- requirePayment / settle — x402 payment binding
- amount-unknown — deny-by-default when a tool call's value can't be determined
Cooperative or trustless
Cooperative mode: the agent's own tool layer calls the gate and refuses on block/escalate. Trustless mode: the counterparty calls the public authorize endpoint (or re-evaluates the bundle) and only acts on allow. Either way, every decision is signed, deterministic, and anchored.
See it in code
import { createMcpGuard } from "@metamynd/agentsafe-mcp-guard";
const guard = createMcpGuard({
serviceDid, serviceKey,
issuerApi: "https://metamynd.ai/api/v1",
// GET /magp/policy/pubkey, fetched once and baked in: a rewritten bundle is refused.
policyPublicKey: process.env.METAMYND_POLICY_PUBLIC_KEY,
// Required: the agents this Service acts for, and the principal that owns its credentials (MAGP 16.3).
// Any other agent is refused AGENT_NOT_ADMITTED; a listed agent another principal owns, GATEWAY_OWNER_MISMATCH.
allowedAgents: ["did:hedera:mainnet:z6Mk…_0.0.1234"],
gatewayOwnerPrincipal: "did:hedera:mainnet:zYourPrincipal…_0.0.5678",
});
// Before your MCP tool runs, re-verify the agent's SIGNED request
// against its policy bundle — trustlessly.
const verdict = await guard.verifyRequest(signedRequest);
if (verdict.decision !== "allow") return refuse(verdict.reasonCode);