The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Palveron Governance Gateway listing page.
Official Palveron MCP server — advisory AI-governance checks for MCP hosts and coding agents
⚡ Early access. Palveron is launching soon and access is currently invite-gated. This server is fully functional — you just need a
pv_live_key, which comes with an Early Access invite. Join the waitlist → palveron.com/early-access
Give your MCP-capable client — Claude Code, Cursor, any other MCP host — governance tools it can call before executing an action: policy verdicts, PII-masking results, and an audit trace for every check, all from the Palveron AI Governance Gateway.
@palveron/sdk — retry, circuit breaker, typed errors out of the boxThis package is the advisory path. It cannot physically stop a tool call: it answers the question "is this allowed?", and the calling agent (or your code via check()/wrap()) is expected to honor the answer. That is by design — it works with any MCP host, needs no network topology change, and gives you verdicts plus audit traces immediately.
Enforced, non-bypassable governance for MCP tool calls is a different product surface: the Palveron remote MCP proxy. There you register the target MCP server in the Palveron dashboard and point your IDE at POST {gateway}/api/v1/mcp/proxy/{server_id} instead of the target — every tools/call then structurally passes through policy checks, approval holds, and drift detection before it can reach the target server. No cooperation from the agent required.
This package (@palveron/mcp-server) | Remote MCP proxy | |
|---|---|---|
| Model | Voluntary pre-flight check | In-path enforcement |
| Can a call bypass it? | Yes — enforcement depends on the caller honoring the verdict | No — the proxy sits between client and target server |
| Setup | npx, one env var | Register the target server in the dashboard, point the IDE at the proxy URL |
| Use it when | You want verdicts + audit traces inside any MCP host, or wrap tool calls programmatically | You need governance that agents cannot skip |
See the MCP setup guide for the enforced path.
The
pv_live_…key in the examples below requires an Early Access invite — request one here. Once you have a key, everything works out of the box.
Add to your claude_desktop_config.json:
Any MCP-capable host can launch the server via the palveron-mcp binary:
| Tool | Purpose |
|---|---|
palveron_check | Check a tool call against governance policies before execution. Returns the decision (PASSED, BLOCKED, MODIFIED/REDACTED/ANONYMIZED with the sanitized input, PENDING_APPROVAL, …), whether the call may proceed, findings, and the audit trace ID. |
palveron_status | Governance status and diagnostics — gateway connectivity, circuit-breaker state, configured local lists. |
palveron_policy_list | List the project's active policies so the host can explain its decisions. |
The server reads its configuration from environment variables. The MCP host sets them; you never put secrets in code.
| Variable | Required | Description |
|---|---|---|
PALVERON_API_KEY | yes | API key (pv_live_…) — comes with an Early Access invite |
PALVERON_BASE_URL | no | Override the gateway endpoint (default: https://gateway.palveron.com) |
PALVERON_FAIL_OPEN | no | true = allow tool calls when the gateway is unreachable (default: false, fail-closed) |
PALVERON_LOG_LEVEL | no | debug / info / warn / error / silent (default: info) |
PALVERON_ALWAYS_BLOCK | no | Comma-separated tool names that are always denied locally, without a gateway call |
PALVERON_ALWAYS_ALLOW | no | Comma-separated tool names that always pass locally, without a gateway call |
MIT — Copyright © 2026 Palveron.