PalveronPalveronDocs

MCP Gateway

Monitor and enforce policies for MCP tool calls between AI agents and external services.

The MCP Gateway sits as a transparent proxy between AI agents and MCP servers. Every tool call passes through the Palveron Verify flow: Agent-stop check → Server-active check → Admission check → Rule check → Log entry → optional Flare Anchor.

Two Operating Modes

ModeHow it worksUse case
Enforcement GatewayPalveron forwards Streamable-HTTP (JSON) traffic — tool calls are intercepted, inspected, and forwardedCoding-agent target servers (GitHub, filesystem, database MCP servers), in-house MCP servers
Governance Control PlaneNative SaaS agents that cannot be proxied are meant to be registered from templates. The templates are listed but locked at the moment: they sign in with methods Palveron does not support yetSalesforce Einstein, Microsoft Copilot, ServiceNow

Clients vs. servers

Cursor, Windsurf and Claude Code are MCP clients, not servers you connect to Palveron. You register the target MCP server (a GitHub, database or filesystem MCP server) and paste its Palveron proxy URL into your client. See the Setup Guide.

How It Works

  1. Register a target MCP server — from the searchable catalog or by custom address (Editor role)
  2. Scan the server to discover its tools; Palveron proposes a rule per tool, nothing takes effect yet
  3. An Admin approves the server after a successful scan and admits every tool with its rule: only admitted tools of an ACTIVE server serve calls
  4. Route traffic through the Palveron proxy endpoint (your client points at it)
  5. Every tool call produces a tamper-evident trace with optional Flare blockchain attestation

Proxy Endpoint

Agents connect to the Palveron-generated proxy endpoint instead of directly to the MCP server:

POST /api/v1/mcp/proxy/{server_id}
Content-Type: application/json
Authorization: Bearer {project_api_key}

{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": { "name": "query_records", "arguments": { "query": "SELECT Id FROM Account" } },
  "id": 1
}

Palveron forwards the JSON-RPC request to the actual MCP server after all checks have passed.

Policy Actions

Four enforcement actions available per tool:

ActionBehavior
ALLOWTool call is allowed
LOG_ONLYTool call is allowed but produces a detailed audit trace
REQUIRE_APPROVALTool call is queued for manual approval (pending approvals expire)
DENYTool call is blocked — the agent receives a JSON-RPC error

Only admitted tools serve calls; admitting a tool confirms its rule. When no rule applies to an admitted tool, the call is held for approval, never passed (NO_TOOL_RULE_REQUIRE_APPROVAL).

Security Features

  • Admission + change detection: when an Admin admits a tool (with the server's approval, or one by one on the tools page), Palveron records a fingerprint over the tool's name, description and input parameters (approvedHash). If a tool later differs from that admitted state, its calls are blocked (APPROVED_FINGERPRINT_MISMATCH) and logged (McpToolDrift → OCSF/SIEM) until an Admin admits the current state again. A tool that is not admitted is blocked (TOOL_NOT_RELEASED).
  • Risk classification: automatic CRITICAL/HIGH/MEDIUM/LOW based on tool capabilities, shown per tool; the proposed rule comes from what the tool does, not from its risk
  • Project emergency stop and targeted stop: Admin-gated and audited. The project emergency stop refuses every request that uses the project key on every path; a targeted stop blocks one specific server or ends one agent's open approvals
  • Blockchain audit trail — BLOCKED decisions and HIGH/CRITICAL-risk calls are attested on Flare

Connecting a Server

There are two ways to connect, both packageless — you always end up with a governed proxy URL:

  • From the catalog — browse the official MCP registry mirror (GET /api/v1/mcp/registry), searchable, with trust signals (last updated, source-repository link), and connect in one click.
  • Custom address — register any reachable MCP server by its URL.

Either way Palveron returns a server id; the governed endpoint your client uses is POST /api/v1/mcp/proxy/{id}. See Server Management.

On this page