MCP Gateway
Monitor and enforce policies for MCP tool calls between AI agents and external services.
The MCP Gateway sits as a transparent proxy between AI agents and MCP servers. Every tool call passes through the Palveron Verify flow: Agent-stop check → Server-active check → Admission check → Rule check → Log entry → optional Flare Anchor.
Two Operating Modes
| Mode | How it works | Use case |
|---|---|---|
| Enforcement Gateway | Palveron forwards Streamable-HTTP (JSON) traffic — tool calls are intercepted, inspected, and forwarded | Coding-agent target servers (GitHub, filesystem, database MCP servers), in-house MCP servers |
| Governance Control Plane | Native SaaS agents that cannot be proxied are meant to be registered from templates. The templates are listed but locked at the moment: they sign in with methods Palveron does not support yet | Salesforce Einstein, Microsoft Copilot, ServiceNow |
Clients vs. servers
Cursor, Windsurf and Claude Code are MCP clients, not servers you connect to Palveron. You register the target MCP server (a GitHub, database or filesystem MCP server) and paste its Palveron proxy URL into your client. See the Setup Guide.
How It Works
- Register a target MCP server — from the searchable catalog or by custom address (Editor role)
- Scan the server to discover its tools; Palveron proposes a rule per tool, nothing takes effect yet
- An Admin approves the server after a successful scan and admits every tool with its rule: only admitted tools of an
ACTIVEserver serve calls - Route traffic through the Palveron proxy endpoint (your client points at it)
- Every tool call produces a tamper-evident trace with optional Flare blockchain attestation
Proxy Endpoint
Agents connect to the Palveron-generated proxy endpoint instead of directly to the MCP server:
POST /api/v1/mcp/proxy/{server_id}
Content-Type: application/json
Authorization: Bearer {project_api_key}
{
"jsonrpc": "2.0",
"method": "tools/call",
"params": { "name": "query_records", "arguments": { "query": "SELECT Id FROM Account" } },
"id": 1
}Palveron forwards the JSON-RPC request to the actual MCP server after all checks have passed.
Policy Actions
Four enforcement actions available per tool:
| Action | Behavior |
|---|---|
ALLOW | Tool call is allowed |
LOG_ONLY | Tool call is allowed but produces a detailed audit trace |
REQUIRE_APPROVAL | Tool call is queued for manual approval (pending approvals expire) |
DENY | Tool call is blocked — the agent receives a JSON-RPC error |
Only admitted tools serve calls; admitting a tool confirms its rule. When no rule applies to an admitted tool, the call is held for approval, never passed (NO_TOOL_RULE_REQUIRE_APPROVAL).
Security Features
- Admission + change detection: when an Admin admits a tool (with the server's approval, or one by one on the tools page), Palveron records a fingerprint over the tool's name, description and input parameters (
approvedHash). If a tool later differs from that admitted state, its calls are blocked (APPROVED_FINGERPRINT_MISMATCH) and logged (McpToolDrift→ OCSF/SIEM) until an Admin admits the current state again. A tool that is not admitted is blocked (TOOL_NOT_RELEASED). - Risk classification: automatic CRITICAL/HIGH/MEDIUM/LOW based on tool capabilities, shown per tool; the proposed rule comes from what the tool does, not from its risk
- Project emergency stop and targeted stop: Admin-gated and audited. The project emergency stop refuses every request that uses the project key on every path; a targeted stop blocks one specific server or ends one agent's open approvals
- Blockchain audit trail — BLOCKED decisions and HIGH/CRITICAL-risk calls are attested on Flare
Connecting a Server
There are two ways to connect, both packageless — you always end up with a governed proxy URL:
- From the catalog — browse the official MCP registry mirror (
GET /api/v1/mcp/registry), searchable, with trust signals (last updated, source-repository link), and connect in one click. - Custom address — register any reachable MCP server by its URL.
Either way Palveron returns a server id; the governed endpoint your client uses is POST /api/v1/mcp/proxy/{id}. See Server Management.