Authorize-before-execute for AI agents: evaluate an action, get a permit, verify it before running.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
MCP server that enforces authorize-before-execute for any MCP-compatible AI agent.
Atlasent is security and organizational authority infrastructure for consequential actions by people, software, and AI.
This MCP server brings it to AI agents (Claude, Cursor, Windsurf, any MCP host). Before an agent's tool call changes a real system (a production deploy, a data export, an access grant), the agent asks Atlasent first. With an API key (remote mode):
Try it in 60 seconds with no account: npx -y @atlasent/mcp-server (local mode, a demo that protects nothing).
Local blocking is free. To actually block on your own machine without an account, use MCP Gate or the Claude Code agent guard. Both are part of the free Community plan. Hosted decisions, shared policies and approvals for a team are on the Atlasent plans.
Atlasent performs execution-time authorization: determine whether a specific consequential Action is authorized now, issue a bounded Permit on allow, verify that Permit at the execution Gate, and only then allow the governed native effect.
A plausible request is not organizational authority.
This MCP server exposes Atlasent authorization primitives to Model Context Protocol hosts and includes a protected deployment demo that proves the ordering end to end.
This repository ships two packages, and one of them has two modes. All three block tool calls. Only one of the three is evidence, and the difference is not a feature list β it is who said yes.
| Surface | Who decided | What it is |
|---|---|---|
@atlasent/mcp-server local mode | a built-in heuristic | nothing β a credential-free demo. Its terminal rule is allow, including for action types it does not recognise. Never rely on it as protection. |
@atlasent/mcp-gate + policy.json | you, in advance, in a file you can edit | operator configuration. Starts at {"default":"deny","rules":[]} and blocks everything until you write a rule. Runs with no account and no network. |
@atlasent/mcp-gate cloud mode | your organization, at execution time | an organizational permit β single-use, bound to that call, verifiable afterwards. |
A rule you can silently edit is configuration. A permit your organization issued, that was consumed once and can be produced later, is authority. Both stop the call; only the second answers "who authorized this?" β which is the question that arrives after an incident, not before one.
The gate says which one decided, on every decision: no_matching_rule is your local
policy, cloud_permit_consumed is an organizational permit. These reason strings are
deliberately not normalised into a generic "blocked." Do not collapse them.
The two packages point in opposite directions, which is why they are separate:
mcp-server exposes Atlasent as MCP tools an agent calls to ask for authorization;
mcp-gate sits in front of someone else's MCP server and intercepts.
For an enforced protected path:
Evaluation is not execution. A positive Decision is not the Gate. Permit Verification happens before the protected side effect.
You don't need an Atlasent account or API key to try this server. With no credentials set, it runs in local mode: an in-process rules engine that works offline.
Add this to your MCP host config (Claude Desktop, Cursor, Windsurf, and others; per-host file locations are below):
Then ask your agent to "deploy billing-api to production". The built-in rules deny it because it has no approvals. Ask again with an approval and it's allowed, and the server verifies the permit before the simulated deploy runs.
Built-in local rules (src/localEngine.ts):
| Situation | Decision |
|---|---|
| Production action with no approvals | deny |
Destructive action (delete, drop, purge, ...) outside a change window | hold |
| Sign / certify / grant / revoke / suspend / resume actions | deny |
| Override / release / export / import / publish actions | hold |
| Anything that passes the rules | allow β single-use permit, 5-minute TTL |
Local permits are unsigned, so local mode is for development, CI, and trying things out. It's not a production enforcement boundary. The server refuses to fall back to local mode under NODE_ENV=production. When you're ready for signed permits, audit evidence, and your organization's own policies, switch to remote mode β get an API key.
packages/agent-hooks is a Claude Code plugin. Destructive
and shipping commands wait for a person: DROP TABLE, terraform destroy, volume
deletes, git push --force, production deploys. With nobody to ask, they are refused.
Everything else runs as normal. Local, no account.
"Someone at the keyboard said yes" is where it stops. The rest of this repository is the organizational version: an approver your organization named, and a permit you can prove afterwards.
Atlasent does not treat every ad-hoc tool string as a new governed Action Type.
Use the Protected Action Canon for stable Action identity. Two important examples are:
For a generic AI tool invocation, use agent.tool.invoke as the public Canon-backed Action Type and carry tool-specific factsβtool name, target, environment, arguments/payload digest, resource state, and other required contextβin the authorization context or binding fields supported by the selected integration path.
Use the read-only atlasent_lookup_action tool to discover Canon-backed Action Types instead of inventing a parallel taxonomy.
Keep the concepts separate:
allow | deny | hold | escalate at the platform boundary.A human Approval, favorable risk signal, policy match, deployment ticket, or workflow status does not by itself become organizational Authority.
deploy_service is intentionally small. It demonstrates a two-layer protected path:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/atlasent-mcp-server)<a href="https://allmcps.com/mcp/atlasent-mcp-server"><img src="https://allmcps.com/api/badge/atlasent-mcp-server?style=directory" alt="AtlaSent MCP Server on AllMCPs" /></a>