Deterministic authorization and security guard for AI agent actions with signed receipts.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Check an AI agent's proposed action against a policy before it calls a tool that can change the world.
Vizier is for developers running agents that can call tools, send messages, change data, or spend money. Put its SDK or MCP proxy between the agent and the tool: it asks a deterministic policy service to ALLOW, BLOCK, or route for human REVIEW, and records a receipt. A response is not proof of user consent unless the authority behind it is verified; see signed delegation grants.
One-minute tour: open the live playground, choose an allowed action, then try BLOCK_AMOUNT and BLOCK_TARGET. The playground uses example policies and data; it does not connect to your bank or modify a real account. The point is to see where the stop occurs before wiring an agent to an external tool.
Try it in code: wrap an MCP server or use the Python SDK. Field reference · Threat model · OpenAPI.
What it does not do: Vizier does not execute the protected action for you. An unverified caller-supplied authority field is an assertion, not a signed grant. Integrate a guard at the tool boundary and check fail-closed behavior before relying on it. This is experimental v0.5.5, not an independent security certification. The @vizier npm scope is not currently published; install the release archives. The MCP proxy is a separate package, not a hosted MCP wrapper of every agent.
How it fits together: agent -> Python/TypeScript guard or MCP proxy -> deterministic policy service on Cloudflare Workers -> decision and receipt -> protected tool only on an authorized allow path. The architecture diagram and technical reference below retain the integration details.
License: MIT. Questions and integration feedback: GitHub issues.
The decision path is strictly deterministic — no non-deterministic LLMs in the critical decision loop. It checks delegated actions, principal identity, amount limits, targets, sensitive operations, and authenticated integration boundaries. Every response includes policy results and a tamper-proof SHA-256 canonical receipt hash.
Status: experimental v0.5.5, deployed on Cloudflare Workers edge. Since v0.3.0, authority can be proved rather than asserted: a principal signs a delegation grant, Vizier verifies it against a registered public key, and the receipt records authority provenance. Read the threat model before placing this service in an execution path.
io.github.vassiliylakhonin/viziervizier-guard)Zero external dependencies (Python standard library only):
Equip Claude Desktop or Cursor with deterministic guardrails (vizier_screen_action, vizier_verify_receipt, vizier_check_policy):
Wrap any local or remote MCP server with deterministic authorization:
@vizier/sdk)No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/vizier-guard)<a href="https://allmcps.com/mcp/vizier-guard"><img src="https://allmcps.com/api/badge/vizier-guard?style=directory" alt="Vizier Guard on AllMCPs" /></a>