Authorizes MCP tool calls against a session policy, not one call at a time.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Incorporating business-process-logic constraints into AI systems.
Your agent has a $1,000 refund ceiling. It issues eleven refunds of $900. Every call is inside the per-refund limit, so every per-call check passes, and $9,900 goes out the door. Nothing that looks at one call at a time can see this.
Clay Seal sits in front of your tools and judges each call against the whole session: the grant, the running totals, where the arguments came from, and what the agent has already done.
| Start here | install and watch it stop two attacks |
| Use it in two lines | wrap tools you already have |
| In front of an MCP server | no code change |
| Write the policy | the grant an operator seals |
| How it works | the six layers, in the order they run |
| What it measures | the numbers, and what they are not |
| Where the boundary is | what this does not do |
| Documentation | docs/START.md first, then docs/ |
| Build from source | and run the tests |
Working on the code? docs/INTEGRATION.md names which
modules the shipped gateway actually executes, which is the fastest way to tell
the live path from the parts that are not wired in. The decision itself is
SessionBroker._authorize_locked in
clayseal/capabilities/broker.py; most refusals
come from _floor in the same file.
If you are a coding agent, skip to the deploy runbook.
clayseal try takes about a minute. It runs two attacks in front of you and
shows the gateway stopping them. There is nothing to configure, no key to get
and nothing leaves your machine.
Every verdict there is decided live by the same gateway you would deploy. The
picture is generated from a real run by python scripts/render_try_svg.py, and
a test fails if it drifts from what the command prints, so it cannot become a
screenshot of something that used to work.
Python 3.10 to 3.14. Two dependencies, cryptography and pyyaml.
On names. The directory is
agentauth-capabilities, the package isclayseal, and the import isclayseal.capabilities. The project was renamed at 0.6;agentauthstill imports as a deprecation shim. See Naming at the end for the detail.
Do this in the project you are editing, in order:
Python functions: Guardrail.from_policy_file("policy.yaml").wrap_all({...})
and bind the wrappers. Keys must match tools.allow. Construct one
Guardrail per session (a new one resets ceilings). Catch Refused
(budget / not granted) and StepUpRequired (held — typical for off-list
email). Non-file tools go in paths.pathless.
Already an MCP server (Claude Desktop / Cursor): clayseal proxy, not
clayseal serve. Do not point proxy at a plain .py file. clayseal howto
is the runbook.
Wrap the tools you already have. Nothing else about your agent changes.
The first refund goes through. The second is refused, because the $1,000 session ceiling is already spent. Neither call reached your function.
The policy is inline here so you can paste the whole thing into a file and run
it. In a real deployment it lives in its own YAML, where a security team can
review it and a pull request can gate it. clayseal policy new > policy.yaml
writes a commented one to start from, and Guardrail.from_policy_file loads it.
The wrappers keep the name, docstring and signature of your originals, so any framework that introspects them sees the tool it saw before. That covers LangGraph, the OpenAI Agents SDK, CrewAI and hand-written loops. Call the wrappers the same way you called the originals, positionally or by name.
No code change at all. The gateway speaks MCP, so it sits between your agent and the server:
Or paste this into Claude Desktop's MCP config, Cursor's MCP settings, or
.cursor/mcp.json. The agent talks to Clay Seal; Clay Seal talks to the server:
Tools the policy does not grant are removed from the catalogue, so the agent is never told they exist.
This is a whole policy. It lints clean.
Run clayseal policy lint policy.yaml before you ship. It catches the mistake
that matters most: a tool that can spend money but debits no budget. On the file
above it reports no errors and one warning (the ceiling is per session unless
you bind a principal), which names a real decision you have not made yet.
Full reference: docs/POLICY.md.
From a checkout. examples/ has seven, each runnable with no key and no network:
Read the last block. A JSON-RPC error proves the agent was told no; the server's own ledger proves the refund did not happen, and those are different claims. The same run on the command line, which is the deployment shape a deployment actually uses:
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/clay-seal)<a href="https://allmcps.com/mcp/clay-seal"><img src="https://allmcps.com/api/badge/clay-seal?style=directory" alt="Clay Seal on AllMCPs" /></a>