Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’° Finance & Fintech
  3. Sanction
Sanction logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 7:52:43 PM

Sanction

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository2 GitHub StarsTotal stargazers on GitHub for the source repository (2 stars).Visit Website

Spend authorization, token budgets, and an encrypted credential vault for AI agents.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "sanction": {
      "command": "npx",
      "args": [
        "-y",
        "sanction-mcp"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’° More in Finance & Fintech

Documentation Overview

Sanction

The independent authorization plane for AI agents.

Before an agent spends money, invokes a tool, touches a credential, or provisions a resource, it asks Sanction. Sanction approves, escalates to a human, or denies. Every decision is logged and auditable. Sanction belongs to no platform: one policy engine answers across model providers, payment rails, identities, and agent ecosystems.

Who runs Sanction

  • Organizations governing their own AI β€” the primary case. Teams and departments become wallets in a tree; budgets, tool rules, and approval bands are enforced β€” not dashboarded β€” with chargeback-ready reporting underneath. Alerts tell you what happened; a decision happens first.
  • Platforms and agencies embedding governance β€” agents you ship or run for clients carry a wallet wherever they execute: MCP hosts, Bedrock, your own stack via SDK or REST.
  • Individuals β€” free, no card, personal and production use.

What it does

One policy decision engine governs every kind of agent action:

Governed actionWhat Sanction enforces
Spend (/authorize)Auto-approve floor, human-escalation band, per-transaction hard cap, daily and monthly budgets β€” checked and debited atomically.
Tools (/authorize/tool)Block/allow/escalate lists for any MCP tool or external action. Escalations reach the approval inbox like spend does.
Credentials (/exec + /mandate/verify + /credentials/inject)AES-256-GCM envelope-encrypted vault (KMS-wrapped, rotating keys). Injection requires a scoped 15-minute mandate JWT and clearance β‰₯ the credential's bar. Counterparties verify the mandate with no API key. Every access audit-logged.
Provisioning (/authorize/provision)Seats, licenses, infrastructure β€” resource, line item, quantity, and dollars authorized in one call.
Capability (/authorize/capability)Skills, plugins, new APIs β€” acquiring capability is governed like spending money. One ordered rule list (block / allow / escalate, prefix-glob patterns) gates new power before it lands in an agent.

What a decision looks like in practice β€” one POST /authorize with an amount, three possible outcomes, all of them terminal or resumable:

  • Approved β†’ { "status": "approved" }; budget counters debit in the same transaction the decision persists (an advisory lock makes sibling agents queue, not race).
  • Escalated β†’ { "status": "escalated", "request_id": "…" }; a human sees it in the approval inbox, and approving mints a one-use grant the agent redeems by retrying with grant_id. Policy decides what a timeout means (approve or deny) β€” nothing hangs forever.
  • Denied β†’ { "status": "denied", "decision_code": "PER_TXN_LIMIT", "remediation": "Amount exceeds the per-transaction limit. Split into smaller charges or ask the owner to raise the limit." }. Codes are stable machine strings (DAILY_BUDGET_EXCEEDED, CATEGORY_BLOCKED, WALLET_FROZEN, …) so agents branch and replan instead of parsing prose. Replays of the same request return the same code.

Around the engine:

  • Human approvals β†’ one-use grants. Escalations land in an approval inbox (dashboard PWA, email, Slack). Approving mints a single-use, expiring grant the agent redeems on retry. Policy timeouts guarantee a terminal outcome.
  • Seats. An agent is a seat you can hand to whoever holds it: named holders, contractor auto-expiry (the key fails closed past the date), key rotation that keeps history, and batch creation from one template.
  • Budgets that cascade. Wallets nest into trees; subtree caps are enforced atomically so sibling agents can't race past a parent's limit. The console's spend view draws the month's runway β€” cumulative burn against the cap, pace, and the projected exhaust date β€” from wallet down to seat.
  • Notifications that find you. Email by default; signed JSON webhooks for machines; and Slack two ways β€” a pasted incoming-webhook URL that deep-links to the decision, or Add to Slack, which installs per workspace over OAuth and posts interactive Approve / Deny buttons that run the same resolveApproval path as the dashboard, actor recorded. Each route subscribes to its own events. Guide
  • Evidence you can replay. Every policy edit becomes an immutable revision; every decision stores the revision in force and the exact context the engine evaluated. GET /authorize/{id}/evidence re-runs the pure rules over the stored context and proves the outcome reproduces.
  • What-if over real history. POST /policy/simulate replays stored decisions under a candidate policy β€” which calls flip, what spend wouldn't clear β€” before you change anything.
  • The audit plane. GET /audit-events merges every decision, token log, and secret access into one feed (CSV export included); GET /reporting/summary spans any period with day buckets and per-seat rollups; wallet stats project burn pace and exhaustion ETAs; a weekly digest lands in Slack every Monday.
  • Tamper-evident exports. GET /audit/export hands you a signed, hash-chained snapshot of your governed decisions: altering, dropping, or reordering any row breaks the chain, and the head is HMAC-signed by Sanction. A regulator or the governed customer runs POST /audit/verify β€” self-contained, no database β€” to prove nothing changed after signing, down to the first broken link.
  • A console that opens on the roster. The dashboard home is the wallet tree as groups with agents as cards, each carrying a mandate stamp (live / paused / blocked). A wallet holds people, not just keys: team membership with roles (owner / admin / viewer), a switcher across every membership, and a viewer who can read everything and change nothing.
  • Adopt without enforcing. Observe mode runs the real engine on a live fleet and records what it would have done β€” blocking nothing, moving no counters β€” so you can watch a week of would-be denials and the dollars behind them, then flip each pool to enforce in one confirm-gated click.
  • Spend answerable to outcomes. Report outcomes (POST /outcomes) and a wallet over its cost-per-outcome ceiling throttles to human-gated spend. Wallets can be frozen outright, and budget reallocated across the tree.
  • LLM gateway. Point your model SDK's base URL at https://getsanction.com/api/gateway/<provider> with x-sanction-key β€” usage is metered and budget-capped with zero per-call instrumentation.

Every security claim above maps to enforcing code and a regression test in docs/TRACEABILITY.md β€” 1,100+ tests behind a coverage gate of 90% statements/lines, 94% functions, and 83% branches, including concurrency and Postgres row-level-security suites.

Start from a pack, not a blank policy

Eleven installable policy packs cover the common shapes β€” Startup defaults, Coding agent seat, MCP tool governance, Compliance baseline, Client-safe launch, and No-egress (Sanction Local) among them. GET /policy/packs lists them; POST /policy/packs/{id}/preview simulates one against your last 30 days of real decisions before anything changes; apply writes it as a policy revision.

Changing policy in production

Policy edits are never a leap of faith:

  1. Draft the change (or pick a pack).
  2. POST /policy/simulate replays your stored decision history under the candidate β€” see exactly which calls flip and what spend wouldn't clear.
  3. Apply. The edit becomes an immutable revision; every subsequent decision records the revision in force.
  4. If a decision is ever questioned, GET /authorize/{id}/evidence re-runs the rules over the stored context and proves the outcome reproduces.

When to use the credential vault

Use Sanction's vault when credentials should flow through the same policy, approval, and audit trail as spend and tools β€” one clearance model, no separate secrets cluster. Keep your existing Vault or Secrets Manager when you need fleet-scale secret lifecycle management independent of agent governance; Sanction consumes upstream identity and secrets rather than replacing them. Threat model: docs/SECURITY.md.


Distribution

Platform vendors govern agents inside their own walls. Sanction authorizes agents wherever they run. Pick the shortest path to your stack:

You want to…UseFirst step
Govern any MCP host (Claude Desktop, Cursor, …)MCP walletPaste https://getsanction.com/mcp or npx sanction-mcp
Intercept tools/call to an MCP serverMCP brokerRegister the upstream, point the host at /mcp/broker/<name>
Meter model spend with zero code changesLLM gatewayPoint the SDK base URL at /api/gateway/<provider>
Govern agents in a TypeScript appSDKnpm install sanction-sdk
Call the engine from anything elseREST APIPOST /v1/authorize with an x-api-key
Plug into an AuthZEN enforcement pointPDPPoint it at /api/access/v1/evaluation
Orchestrate on AWS BedrockAction Groupdocs/BEDROCK.md

The full menu:

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Finance & Fintech View all alternatives
  • Stripe AI logoStripe AI

    MCP server integrating with Stripe - tools for customers, products, payments, and more.

    πŸ’° Finance & Fintech0 views
    Compare vs Stripe AI β†’
  • Capsule logoCapsule

    Compact, source-linked context packs that reduce token waste for coding agents.

    πŸ’° Finance & Fintech0 views
    Compare vs Capsule β†’
  • Vk Ads MCP logoVk Ads MCP

    MCP server for VK Ads API: campaigns, audiences, budgets, stats. Click.ru, token or OAuth.

    πŸ’° Finance & Fintech2 views
    Compare vs Vk Ads MCP β†’
  • E
    Encrypted Langchain Token Agent

    Encrypted LangChain Token Agent

    πŸ’° Finance & Fintech0 views
    Compare vs Encrypted Langchain Token Agent β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Sanction

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "sanction": { "command": "npx", "args": ["-y", "sanction"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSanction AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sanction?style=directory)](https://allmcps.com/mcp/sanction)
HTML Embed
<a href="https://allmcps.com/mcp/sanction"><img src="https://allmcps.com/api/badge/sanction?style=directory" alt="Sanction on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’°Finance & Fintech
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 7, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars2
GitHub Star CountTotal stargazers on GitHub representing community popularity (2 stars).
37Quality signal: Fair Β· 37/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’° Finance & Fintech β†’Best MCP servers for Finance & Fintech β†’Alternatives to Sanction β†’Install in Claude DesktopInstall in CursorInstall in VS Code