Skip to main content
Glama
palveron

@palveron/mcp-server

by palveron

⚡ Early access. Palveron is launching soon and access is currently invite-gated. This server is fully functional — you just need a pv_live_ key, which comes with an Early Access invite. Join the waitlist → palveron.com/early-access

Give your MCP-capable client — Claude Code, Cursor, any other MCP host — governance tools it can call before executing an action: policy verdicts, PII-masking results, and an audit trace for every check, all from the Palveron AI Governance Gateway.

  • Drop-in MCP server — one binary, configure your MCP host, you're done

  • Advisory governance verdicts — the gateway decides allow / mask / deny / hold; the agent (or your wrapping code) acts on the verdict

  • Audit trail per check — trace IDs flow back to the Palveron dashboard

  • Built on @palveron/sdk — retry, circuit breaker, typed errors out of the box

Advisory check vs. enforced governance — which one do you need?

This package is the advisory path. It cannot physically stop a tool call: it answers the question "is this allowed?", and the calling agent (or your code via check()/wrap()) is expected to honor the answer. That is by design — it works with any MCP host, needs no network topology change, and gives you verdicts plus audit traces immediately.

Enforced, non-bypassable governance for MCP tool calls is a different product surface: the Palveron remote MCP proxy. There you register the target MCP server in the Palveron dashboard and point your IDE at POST {gateway}/api/v1/mcp/proxy/{server_id} instead of the target — every tools/call then structurally passes through policy checks, approval holds, and drift detection before it can reach the target server. No cooperation from the agent required.

This package (@palveron/mcp-server)

Remote MCP proxy

Model

Voluntary pre-flight check

In-path enforcement

Can a call bypass it?

Yes — enforcement depends on the caller honoring the verdict

No — the proxy sits between client and target server

Setup

npx, one env var

Register the target server in the dashboard, point the IDE at the proxy URL

Use it when

You want verdicts + audit traces inside any MCP host, or wrap tool calls programmatically

You need governance that agents cannot skip

See the MCP setup guide for the enforced path.

Related MCP server: thewardn-mcp

Installation

npm install -g @palveron/mcp-server
# or use directly via npx
npx @palveron/mcp-server

Quick Start

The pv_live_… key in the examples below requires an Early Access invite — request one here. Once you have a key, everything works out of the box.

Claude Code

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "palveron": {
      "command": "npx",
      "args": ["@palveron/mcp-server"],
      "env": {
        "PALVERON_API_KEY": "pv_live_xxx",
        "PALVERON_BASE_URL": "https://gateway.palveron.com"
      }
    }
  }
}

Other MCP hosts

Any MCP-capable host can launch the server via the palveron-mcp binary:

PALVERON_API_KEY=pv_live_xxx palveron-mcp

Tools exposed via MCP

Tool

Purpose

palveron_check

Check a tool call against governance policies before execution. Returns the decision (PASSED, BLOCKED, MODIFIED/REDACTED/ANONYMIZED with the sanitized input, PENDING_APPROVAL, …), whether the call may proceed, findings, and the audit trace ID.

palveron_status

Governance status and diagnostics — gateway connectivity, circuit-breaker state, configured local lists.

palveron_policy_list

List the project's active policies so the host can explain its decisions.

Configuration

The server reads its configuration from environment variables. The MCP host sets them; you never put secrets in code.

Variable

Required

Description

PALVERON_API_KEY

yes

API key (pv_live_…) — comes with an Early Access invite

PALVERON_BASE_URL

no

Override the gateway endpoint (default: https://gateway.palveron.com)

PALVERON_FAIL_OPEN

no

true = allow tool calls when the gateway is unreachable (default: false, fail-closed)

PALVERON_LOG_LEVEL

no

debug / info / warn / error / silent (default: info)

PALVERON_ALWAYS_BLOCK

no

Comma-separated tool names that are always denied locally, without a gateway call

PALVERON_ALWAYS_ALLOW

no

Comma-separated tool names that always pass locally, without a gateway call

Requirements

  • Node.js 18 or newer

  • An MCP-capable client (Claude Code 0.4+, Cursor, etc.)

License

MIT — Copyright © 2026 Palveron.

Available Tools

3 tools
palveron_checkA

Verify a tool call against PALVERON governance policies before execution. Returns whether the action is allowed, blocked, or modified (with PII redacted). Every check creates an immutable audit trace.

ParametersJSON Schema
NameRequiredDescriptionDefault
toolYesThe tool name to check (e.g. "execute_command", "write_file", "browser_navigate")
inputYesThe tool input/arguments as a string or JSON string
agent_idNoOptional agent identifier for audit trail
session_idNoOptional session ID for conversation tracking

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description fully bears the transparency burden. It discloses the return categories (allowed, blocked, modified), PII redaction, and the creation of an immutable audit trace, giving the agent a clear picture of side effects. It does not mention rate limits or failure modes, but for a governance check this is reasonably complete.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three sentences, front-loaded with the core action, and each sentence adds value: what it does, what it returns, and the audit side effect. No redundant or vague language is present.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is moderately simple (4 params, no output schema), and the description covers purpose, usage context, outcome types, and side effects. It lacks explicit examples or detailed return structure, but these are not essential given the schema and the clear description. The description is sufficiently complete for an agent to choose and invoke the tool appropriately.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema provides 100% coverage with descriptions for all four parameters. The description itself does not add parameter-level detail beyond the schema, but it does frame the purpose of the tool/input parameters. This meets the baseline for full schema coverage, with no additional semantics provided.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description provides a specific verb+resource combination: 'Verify a tool call against PALVERON governance policies before execution.' This clearly distinguishes the tool from siblings like palveron_status and palveron_policy_list, focusing on pre-execution checking rather than status or policy listing.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'before execution' clearly establishes when to use the tool (prior to running a tool call). It also describes the outcome (allowed/blocked/modified) which implies appropriate usage as a gate. However, it does not explicitly name alternatives or provide conditions for when not to use it, so it lacks explicit exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

palveron_policy_listA

List active governance policies for the current project. Shows policy names, enforcement actions, and content type scopes.

ParametersJSON Schema
NameRequiredDescriptionDefault
environmentNoEnvironment filter (default: "prod")

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries the burden of behavioral disclosure. It adds useful context about filtering to 'active' policies and scoping to the 'current project', and lists output fields. However, it does not mention behavior around the environment parameter, default settings, pagination, or error conditions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two concise sentences with front-loaded action ('List...'), followed by output details. Every word adds value, with no redundancy or fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple tool with one optional parameter and no output schema, the description adequately covers the core purpose and output content. It could be enhanced by noting the environment filter's effect, but this is documented in the schema. Overall, it is sufficiently complete for an agent to select and invoke the tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The single parameter 'environment' has a schema description covering its default and purpose, achieving 100% schema description coverage. The tool description adds no additional parameter semantics, so the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool lists active governance policies for the current project, with a specific verb ('List') and resource ('active governance policies'). It also enumerates the output details (policy names, enforcement actions, content type scopes), making its purpose distinct from sibling tools like palveron_check and palveron_status.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage when you need to view governance policies, but provides no explicit guidance on when to use this tool versus siblings or when it should not be used. There are no exclusions or alternative tool references.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

palveron_statusA

Get PALVERON governance status and diagnostics. Shows connection state, circuit breaker status, configured policies, and gateway health.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It explicitly lists what the tool shows (connection state, circuit breaker status, configured policies, gateway health), giving a clear picture of its read-only, diagnostic nature. It doesn't describe potential side effects or prerequisites, but none are expected for a status tool, and the listed outputs provide solid transparency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is succinct and well-structured. It opens with a clear, front-loaded purpose statement, followed by a concise list of diagnostic outputs. Every word adds value with no redundancy or filler, making it highly efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description is complete for a status tool with no parameters and no output schema. It enumerates the key areas of diagnostic information (connection, circuit breaker, policies, gateway health), giving the agent a clear understanding of what the tool returns. It doesn't include extensive detail like exact response format, but for a status/diagnostics tool, this is adequate and not a significant gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters (0 params), so the baseline is 4. The description correctly adds no parameter details since none exist. The input schema is empty, and the description is consistent, not requiring any compensation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Get PALVERON governance status and diagnostics.' It uses a specific verb ('Get') and resource ('PALVERON governance status'), and lists the specific diagnostic areas (connection state, circuit breaker, policies, gateway health). This distinguishes it from siblings like palveron_check and palveron_policy_list, which focus on checking or listing policies.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus its siblings. It doesn't mention alternatives or exclusions. While the purpose is clear, it says nothing about scenarios where palveron_check or palveron_policy_list might be more appropriate, leaving the agent without explicit usage context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 3 tool updatesv1.0.4
    • First observedpalveron_check
    • First observedpalveron_policy_list
    • First observedpalveron_status

TDQS

A4.2/5.0
Disambiguation5/5

Each tool has a distinct purpose: palveron_check verifies a single action, palveron_status provides system diagnostics, and palveron_policy_list lists policies. There is no ambiguity or overlap between them.

Naming Consistency4/5

All tools share the consistent palveron_ prefix and snake_case format, but the second word is a mix of verb (check) and nouns (status, policy_list). Minor deviation from a strict verb_noun pattern.

Tool Count5/5

Three tools is well-scoped for a governance checker: one to perform checks, one for status, and one for policy listing. No tools feel redundant or missing.

Completeness5/5

The domain is governance policy enforcement, and the set covers the core operations: enforcing a policy (check), understanding system state (status), and discovering applicable policies (list). No obvious gaps for the stated purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Policy enforcement gateway for MCP tool calls, evaluating every tool invocation against declarative YAML policies (allow/deny/escalate-to-human), generating cryptographic hash-chained audit receipts, and including built-in content safety scanning.
    2
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Governance wrapper for MCP servers that intercepts and evaluates every Claude tool call against policy, with verdicts including CLEARED, HELD, or BLOCKED, enabling oversight and escrow for human review.
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enforces deterministic policies on AI agent tool calls, evaluating actions against compliance modules (SOC 2, HIPAA, GDPR, etc.) and returning ALLOW, BLOCK, or CONSTRAIN decisions with an audit trail.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Wraps your existing MCP servers and checks each tool call against policy and live state before it runs. Allow, block, or require a refresh, with a reason the agent can act on.
    5
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/palveron/mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server