Submit and inspect governed AI business actions through a self-hosted BailingHub control plane.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
็ฎไฝไธญๆ | English
Let an MCP-compatible AI agent use natural-language requests to query and operate your store, SaaS, CRM, ERP, or other business system through BailingHub.
Depending on the capabilities explicitly exposed by the business system and the routes allowed for this connection, an agent can, for example:
The agent does not receive administrator or business-system credentials. BailingHub keeps the route boundary, approval state, execution record, and audit trail, while the downstream business system still makes the final authorization decision.
0.3.0: adds host-controlled multi-connection lifecycle APIs and CurrentUser DPAPI storage for Windows Agent Sessions. The existing Agent Client and
0.1.xClient Token behavior remains compatible and is not replaced.
This package is a thin integration adapter. It does not embed BailingHub, grant business permissions, or replace the downstream business system's final authorization. It supports both the existing operator-provisioned Client Token mode and an Agent Session mode in which a human approves one local Agent through the system browser.
| Tool | Purpose |
|---|---|
submit_governed_job | Submit untrusted task text to one operator-configured BailingHub route |
get_governed_job | Read the current public state of a credential-owned job |
wait_for_governed_job | Poll one job for at most 60 seconds without resubmitting it |
The Agent Client 0.3 path starts with five small meta-tools for turn bootstrap, capability search, governed invocation/recovery, and visible run completion. BailingHub then returns at most 12 active business tools for the current turn; each replacement removes the previous active set instead of growing the model context indefinitely.
Host implementers should use the host-neutral Agent Client SDK guide.
The route, BailingHub URL, and credential are local process configuration. They are never MCP tool arguments and therefore cannot be selected or replaced by model output.
bailinghub-mcp-server login once. The CLI uses a random loopback
callback plus PKCE, opens the system browser, and stores the approved session in the
platform-specific secure credential store. The MCP tools then use /agent-api/v1/* and
refresh rotated tokens locally.BAILINGHUB_CLIENT_TOKEN is present, the adapter keeps
using POST /run and GET /jobs/{job_id} exactly as before.Neither mode lets the model supply a credential, route, acting subject, or approval result. The Agent Session records the identity approved by the Hub/business authorization boundary; the downstream business system still makes the final authorization decision.
The MCP Registry server.json describes only the compatible standalone stdio/Client Token
installation, so that entry still marks BAILINGHUB_CLIENT_TOKEN as required. The native DSH
plugin does not consume that Registry configuration: it imports this package's /sdk subpath as
an ordinary library dependency and establishes an Agent Session through the browser. Do not add a
Client Token field to a DSH plugin based on the Registry form.
The adapter intentionally does not accept:
In compatible Client Token mode, use a dedicated token restricted to the one route configured for this server process. Run separate server instances when different MCP clients need different route boundaries.
Prerequisites:
For the legacy static-job mode, configure an MCP host to spawn:
Authorize one registered public Agent client and one fixed route before starting the MCP host without a Client Token:
The login callback binds only to a random 127.0.0.1 port and uses state plus PKCE S256.
Access and refresh tokens never appear in CLI output. macOS uses Keychain. Linux and other
POSIX platforms require an explicit BAILINGHUB_ALLOW_FILE_CREDENTIAL_STORE=true opt-in;
that fallback rejects files that are not owned by the current user with mode 0600.
Windows uses a CurrentUser DPAPI-protected file under the user's LocalAppData directory. If
Windows PowerShell or DPAPI is unavailable, Agent Session fails closed and never falls back to
plaintext. Compatible Client Token mode remains available on every supported platform.
For a local BailingHub process, loopback HTTP is accepted:
Non-loopback HTTP is rejected by default. BAILINGHUB_ALLOW_INSECURE_HTTP=true exists only
for an operator-controlled private network where TLS terminates elsewhere. Do not use it
across an untrusted network.
request_id for one business request.submit_governed_job with that ID and the task text.job_id.wait_for_governed_job for a short bounded wait, or call get_governed_job later.request_id and task meaning.queued, running, and dispatched are non-terminal. done, error, and rejected are
terminal. A wait timeout is not a failed task and must not cause a replacement submission.
Use the MCP integration path as the
canonical start page. The first integration is successful when an MCP host submits through
the operator-fixed route, the same job_id reaches a terminal state, BailingHub retains
its approval and audit state, and the MCP host never receives administrator or
business-system credentials.
Report a PASS, partial result, or failure through the BailingHub independent validation form and select the MCP track. Never include tokens, model keys, personal information, or production business data.
The dependency direction is one-way:
See:
Client Token mode uses the stable bailing.client-api.v1 surface:
POST /runGET /jobs/{job_id}Agent Session mode uses the additive Agent Auth v1 and Agent API v1 surfaces:
POST /agent-auth/v1/authorizationsPOST /agent-auth/v1/tokenGET /agent-auth/v1/sessionPOST /agent-auth/v1/revokeGET /agent-api/v1/workspacesGET /agent-api/v1/workspaces/{route}/bootstrapPOST /agent-api/v1/workspaces/{route}/turnsPOST /agent-api/v1/workspaces/{route}/capabilities/searchPOST /agent-api/v1/tool-invocationsPOST /agent-api/v1/tool-invocations/{invocation_id}/resumePOST /agent-api/v1/runs/{run_id}/completeThe bailinghub-mcp-server/sdk subpath additionally exposes a host-neutral Agent Client factory.
It owns browser login, named local selectors, isolated credentials, token refresh, and Core DTO
mapping. On the same Hub/client/workspace binding it replaces an older local connection only when
Core reports the same trusted on_behalf_of; different business identities remain independently
selectable. Core resolves the business authorization entry, so host adapters such as DSH never ask
for a business URL and do not own credentials or BailingHub HTTP endpoint details.
No administrator, executor, approval-decision, tool-proxy, configuration, or direct business API is called by this adapter.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/bailinghub-governance)<a href="https://allmcps.com/mcp/bailinghub-governance"><img src="https://allmcps.com/api/badge/bailinghub-governance?style=directory" alt="BailingHub Governance on AllMCPs" /></a>