@palveron/mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@palveron/mcp-serverCheck this tool call against governance policy before I execute it."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
⚡ Early access. Palveron is launching soon and access is currently invite-gated. This server is fully functional — you just need a
pv_live_key, which comes with an Early Access invite. Join the waitlist → palveron.com/early-access
Give your MCP-capable client — Claude Code, Cursor, any other MCP host — governance tools it can call before executing an action: policy verdicts, PII-masking results, and an audit trace for every check, all from the Palveron AI Governance Gateway.
Drop-in MCP server — one binary, configure your MCP host, you're done
Advisory governance verdicts — the gateway decides allow / mask / deny / hold; the agent (or your wrapping code) acts on the verdict
Audit trail per check — trace IDs flow back to the Palveron dashboard
Built on
@palveron/sdk— retry, circuit breaker, typed errors out of the box
Advisory check vs. enforced governance — which one do you need?
This package is the advisory path. It cannot physically stop a tool call: it answers the question "is this allowed?", and the calling agent (or your code via check()/wrap()) is expected to honor the answer. That is by design — it works with any MCP host, needs no network topology change, and gives you verdicts plus audit traces immediately.
Enforced, non-bypassable governance for MCP tool calls is a different product surface: the Palveron remote MCP proxy. There you register the target MCP server in the Palveron dashboard and point your IDE at POST {gateway}/api/v1/mcp/proxy/{server_id} instead of the target — every tools/call then structurally passes through policy checks, approval holds, and drift detection before it can reach the target server. No cooperation from the agent required.
This package ( | Remote MCP proxy | |
Model | Voluntary pre-flight check | In-path enforcement |
Can a call bypass it? | Yes — enforcement depends on the caller honoring the verdict | No — the proxy sits between client and target server |
Setup |
| Register the target server in the dashboard, point the IDE at the proxy URL |
Use it when | You want verdicts + audit traces inside any MCP host, or wrap tool calls programmatically | You need governance that agents cannot skip |
See the MCP setup guide for the enforced path.
Related MCP server: thewardn-mcp
Installation
npm install -g @palveron/mcp-server
# or use directly via npx
npx @palveron/mcp-serverQuick Start
The
pv_live_…key in the examples below requires an Early Access invite — request one here. Once you have a key, everything works out of the box.
Claude Code
Add to your claude_desktop_config.json:
{
"mcpServers": {
"palveron": {
"command": "npx",
"args": ["@palveron/mcp-server"],
"env": {
"PALVERON_API_KEY": "pv_live_xxx",
"PALVERON_BASE_URL": "https://gateway.palveron.com"
}
}
}
}Other MCP hosts
Any MCP-capable host can launch the server via the palveron-mcp binary:
PALVERON_API_KEY=pv_live_xxx palveron-mcpTools exposed via MCP
Tool | Purpose |
| Check a tool call against governance policies before execution. Returns the decision ( |
| Governance status and diagnostics — gateway connectivity, circuit-breaker state, configured local lists. |
| List the project's active policies so the host can explain its decisions. |
Configuration
The server reads its configuration from environment variables. The MCP host sets them; you never put secrets in code.
Variable | Required | Description |
| yes | API key ( |
| no | Override the gateway endpoint (default: |
| no |
|
| no |
|
| no | Comma-separated tool names that are always denied locally, without a gateway call |
| no | Comma-separated tool names that always pass locally, without a gateway call |
Requirements
Node.js 18 or newer
An MCP-capable client (Claude Code 0.4+, Cursor, etc.)
Links
Early Access / Waitlist — palveron.com/early-access
Documentation — docs.palveron.com/integrations/mcp
Dashboard — palveron.com
Support — hello@palveron.com
GitHub — palveron/mcp-server
Changelog — CHANGELOG.md
License
MIT — Copyright © 2026 Palveron.
Available Tools
3 toolspalveron_checkA
Verify a tool call against PALVERON governance policies before execution. Returns whether the action is allowed, blocked, or modified (with PII redacted). Every check creates an immutable audit trace.
| Name | Required | Description | Default |
|---|---|---|---|
| tool | Yes | The tool name to check (e.g. "execute_command", "write_file", "browser_navigate") | |
| input | Yes | The tool input/arguments as a string or JSON string | |
| agent_id | No | Optional agent identifier for audit trail | |
| session_id | No | Optional session ID for conversation tracking |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description fully bears the transparency burden. It discloses the return categories (allowed, blocked, modified), PII redaction, and the creation of an immutable audit trace, giving the agent a clear picture of side effects. It does not mention rate limits or failure modes, but for a governance check this is reasonably complete.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, front-loaded with the core action, and each sentence adds value: what it does, what it returns, and the audit side effect. No redundant or vague language is present.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is moderately simple (4 params, no output schema), and the description covers purpose, usage context, outcome types, and side effects. It lacks explicit examples or detailed return structure, but these are not essential given the schema and the clear description. The description is sufficiently complete for an agent to choose and invoke the tool appropriately.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema provides 100% coverage with descriptions for all four parameters. The description itself does not add parameter-level detail beyond the schema, but it does frame the purpose of the tool/input parameters. This meets the baseline for full schema coverage, with no additional semantics provided.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description provides a specific verb+resource combination: 'Verify a tool call against PALVERON governance policies before execution.' This clearly distinguishes the tool from siblings like palveron_status and palveron_policy_list, focusing on pre-execution checking rather than status or policy listing.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'before execution' clearly establishes when to use the tool (prior to running a tool call). It also describes the outcome (allowed/blocked/modified) which implies appropriate usage as a gate. However, it does not explicitly name alternatives or provide conditions for when not to use it, so it lacks explicit exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
palveron_policy_listA
List active governance policies for the current project. Shows policy names, enforcement actions, and content type scopes.
| Name | Required | Description | Default |
|---|---|---|---|
| environment | No | Environment filter (default: "prod") |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are present, so the description carries the burden of behavioral disclosure. It adds useful context about filtering to 'active' policies and scoping to the 'current project', and lists output fields. However, it does not mention behavior around the environment parameter, default settings, pagination, or error conditions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two concise sentences with front-loaded action ('List...'), followed by output details. Every word adds value, with no redundancy or fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with one optional parameter and no output schema, the description adequately covers the core purpose and output content. It could be enhanced by noting the environment filter's effect, but this is documented in the schema. Overall, it is sufficiently complete for an agent to select and invoke the tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The single parameter 'environment' has a schema description covering its default and purpose, achieving 100% schema description coverage. The tool description adds no additional parameter semantics, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool lists active governance policies for the current project, with a specific verb ('List') and resource ('active governance policies'). It also enumerates the output details (policy names, enforcement actions, content type scopes), making its purpose distinct from sibling tools like palveron_check and palveron_status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage when you need to view governance policies, but provides no explicit guidance on when to use this tool versus siblings or when it should not be used. There are no exclusions or alternative tool references.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
palveron_statusA
Get PALVERON governance status and diagnostics. Shows connection state, circuit breaker status, configured policies, and gateway health.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It explicitly lists what the tool shows (connection state, circuit breaker status, configured policies, gateway health), giving a clear picture of its read-only, diagnostic nature. It doesn't describe potential side effects or prerequisites, but none are expected for a status tool, and the listed outputs provide solid transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is succinct and well-structured. It opens with a clear, front-loaded purpose statement, followed by a concise list of diagnostic outputs. Every word adds value with no redundancy or filler, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is complete for a status tool with no parameters and no output schema. It enumerates the key areas of diagnostic information (connection, circuit breaker, policies, gateway health), giving the agent a clear understanding of what the tool returns. It doesn't include extensive detail like exact response format, but for a status/diagnostics tool, this is adequate and not a significant gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters (0 params), so the baseline is 4. The description correctly adds no parameter details since none exist. The input schema is empty, and the description is consistent, not requiring any compensation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Get PALVERON governance status and diagnostics.' It uses a specific verb ('Get') and resource ('PALVERON governance status'), and lists the specific diagnostic areas (connection state, circuit breaker, policies, gateway health). This distinguishes it from siblings like palveron_check and palveron_policy_list, which focus on checking or listing policies.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus its siblings. It doesn't mention alternatives or exclusions. While the purpose is clear, it says nothing about scenarios where palveron_check or palveron_policy_list might be more appropriate, leaving the agent without explicit usage context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v1.0.4- First observed
palveron_check - First observed
palveron_policy_list - First observed
palveron_status
TDQS
Each tool has a distinct purpose: palveron_check verifies a single action, palveron_status provides system diagnostics, and palveron_policy_list lists policies. There is no ambiguity or overlap between them.
All tools share the consistent palveron_ prefix and snake_case format, but the second word is a mix of verb (check) and nouns (status, policy_list). Minor deviation from a strict verb_noun pattern.
Three tools is well-scoped for a governance checker: one to perform checks, one for status, and one for policy listing. No tools feel redundant or missing.
The domain is governance policy enforcement, and the set covers the core operations: enforcing a policy (check), understanding system state (status), and discovering applicable policies (list). No obvious gaps for the stated purpose.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP enforcement layer that intercepts AI agent actions and blocks rule violations before execution.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Runtime permission, approval, and audit layer for AI agent tool execution.
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Related MCP Servers
AlicenseNot gradedqualityCmaintenancePolicy enforcement gateway for MCP tool calls, evaluating every tool invocation against declarative YAML policies (allow/deny/escalate-to-human), generating cryptographic hash-chained audit receipts, and including built-in content safety scanning.2MIT- FlicenseNot gradedqualityDmaintenanceGovernance wrapper for MCP servers that intercepts and evaluates every Claude tool call against policy, with verdicts including CLEARED, HELD, or BLOCKED, enabling oversight and escrow for human review.-

Vaikora Guard MCPofficial
AlicenseNot gradedqualityDmaintenanceEnforces deterministic policies on AI agent tool calls, evaluating actions against compliance modules (SOC 2, HIPAA, GDPR, etc.) and returning ALLOW, BLOCK, or CONSTRAIN decisions with an audit trail.MIT- FlicenseNot gradedqualityCmaintenanceWraps your existing MCP servers and checks each tool call against policy and live state before it runs. Allow, block, or require a refresh, with a reason the agent can act on.5-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/palveron/mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server