VantaGate MCP Server & OpenAPI integration - Human-in-the-Loop for AI Agents
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Human-in-the-Loop authorization for AI Agents. VantaGate intercepts high-risk actions, routes them to a human approver via Slack or Email, and returns a cryptographically-signed decision - so your agent resumes or halts with a full audit trail.
AI agents are increasingly capable of executing consequential real-world actions: sending emails to thousands of users, deleting database records, moving money, deploying to production. VantaGate is the trust layer that ensures humans remain in control.
GET /checkpoint/{id} never returns the original payloadThis package ships two integration artifacts for connecting any AI agent to VantaGate:
| Artifact | File | Best for |
|---|---|---|
| OpenAPI 3.0 Spec | vanta-gate-openapi.json | No-code tools, OpenAI GPTs, Alice, n8n, Zapier |
| MCP Server | src/index.ts / dist/index.js | Claude Desktop, Cursor, Cline, any MCP-compatible agent |
The fastest path. No manual setup required.
Step 1: Get your API key from https://vanta-gate.com/dashboard/projects
Step 2: Add VantaGate to your Claude Desktop config.
Open your claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonStep 3: Restart Claude Desktop. The tools create_vantagate_checkpoint and check_vantagate_status will appear in Claude's tool list.
Step 4: Ask Claude to do something that requires approval:
"Delete all records from the staging database where created_at < 2024-01-01"
Claude will automatically pause, create a checkpoint, and tell you to check your email or Slack for the approval notification.
Import vanta-gate-openapi.json directly into your tool of choice.
API Key β Header: X-API-KEYThe GPT will now pause before high-risk tool calls and ask for human approval.
vanta-gate-openapi.jsonX-API-KEY to your VantaGate API key in the credential storecreate_vantagate_checkpoint to your agent's "before high-risk action" triggerX-API-KEY header in the credential configurationcreate_vantagate_checkpointPauses the agent workflow and routes a human approval request.
When Claude uses it: Before any high-risk action - financial operations, data deletion, production deployments, bulk communications.
| Parameter | Type | Required | Description |
|---|---|---|---|
title | string | β | Short title shown to approver. Max 200 chars. |
payload | object | β | Full JSON context for the decision. Encrypted + purged after decision. |
description | string | β | Additional context below the title. Max 1000 chars. |
options | string[] | β | Decision options. First = approve action. Default: ["Approve", "Reject"]. Min 2, max 5. |
timeout | string | β | Auto-expire duration: 30m, 4h, 2d. Default: 24h. |
notify_email | string | β | Email address for magic-link notification. |
slack_webhook_url | string | β | Slack webhook URL (Pro/Scale plans). From Dashboard β Add to Slack. |
callback_url | string | β | Your HTTPS endpoint for signed decision webhook. |
Returns: checkpoint_id and step-by-step instructions for the agent.
check_vantagate_statusPolls the decision status of a pending checkpoint.
| Parameter | Type | Required | Description |
|---|---|---|---|
checkpoint_id | string | β | The ID from create_vantagate_checkpoint. |
Returns: status (PENDING / APPROVED / REJECTED / RESOLVED / EXPIRED), selected_option, reject_reason, and the full audit trail.
Base URL: https://api.vanta-gate.com/v1
Authentication: X-API-KEY header
| Method | Endpoint | Description |
|---|---|---|
POST | /checkpoint | Create a checkpoint - pauses agent |
GET | /checkpoint/{id} | Poll for human decision |
GET | /checkpoint/secure/{token} | Decision UI (internal - magic link) |
POST | /checkpoint/secure/{token}/decide | Submit decision (internal - decision UI) |
| HTTP | Code | Description |
|---|---|---|
| 400 | Invalid_Webhook_URL | slack_webhook_url must start with https://hooks.slack.com/ |
| 400 | Invalid_Callback_URL | callback_url is malformed or points to private IP |
| 400 | Invalid_Decision | Decision value not in checkpoint's options array |
| 400 | Validation_Error | Request body field validation failure |
| 401 | Unauthorized | Missing, invalid, or rotated API key |
| 402 | Upgrade_Required | Feature requires Pro or Scale plan |
| 403 | Forbidden | API key doesn't match the checkpoint's project |
| 404 | Not_Found | Checkpoint ID or token does not exist |
| 409 | Already_Decided | Decision already recorded for this checkpoint |
| 410 | Checkpoint_Expired | Timeout window has passed |
| 429 | Rate_Limited | Too many requests - back off and retry |
All errors follow the envelope:
| Feature | Free | Pro ($49/mo) | Scale ($199/mo) |
|---|---|---|---|
| Checkpoints/month | 50 | 2,500 | 25,000 |
| Email notifications | β | β | β |
| Slack notifications | β | β | β |
| Webhook callbacks | β | β | β |
| Max timeout | 24h | 7 days | 30 days |
| Log retention | 7 days | 90 days | 365 days |
Timeout values are silently clamped to your plan's maximum. A Free plan request with
timeout: "7d"will be capped to24h.
When a human decides, VantaGate sends a signed HTTPS POST to your callback_url (up to 5 retry attempts with exponential back-off).
Request headers:
Signature verification (Node.js):
Your Webhook Signing Secret (VANTA_PROJECT_SECRET) is distinct from your API key. Find it in Dashboard β Project Settings.
X-API-KEY is hashed server-side - VantaGate never stores plaintext keys.slack_webhook_url is sent per-request and purged atomically after the decision. Zero retention.callback_url is validated against private IP ranges (SSRF prevention).MIT - see LICENSE
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/vantagate-mcp-server)<a href="https://allmcps.com/mcp/vantagate-mcp-server"><img src="https://allmcps.com/api/badge/vantagate-mcp-server?style=directory" alt="Vantagate Mcp Server on AllMCPs" /></a>