mcp-oracle-h
The ORACLE-H MCP server provides a human-in-the-loop validation gateway, requiring human approval via Telegram before AI agents execute critical, destructive, or irreversible actions.
Core Tools:
oracle_validate— Submit an action for human approval, providing:A precise technical description, rationale, and projected impact
An optional financial amount at stake (USD)
A configurable TTL/timeout (default: 5 minutes)
Returns a
request_idfor tracking
oracle_poll_status— Check the status of a submitted request (poll every 10–15s), receiving one of:approved→ proceedrejected→ abortexpired→ no response in time; abort or retry
Key Use Cases:
Destructive operations (deleting files, dropping databases, force-pushing to git)
External writes (sending emails, posting to APIs)
Financial transactions (payments, billing changes)
Infrastructure changes (deployments, DNS, environment variables)
Additional Highlights:
Increases AI workflow reliability from ~81.5% to ~99.6% by adding human checkpoints
Secured via bearer token authentication and HMAC-SHA256 signed webhooks
Compatible with Claude Desktop, Cursor, VS Code extensions (Cline, Roo Code, GitHub Copilot), n8n, Zed, Continue.dev, and LangGraph
Enables human-on-the-loop validation by sending notifications to Telegram, allowing users to approve or reject critical, destructive, or irreversible actions before an AI agent executes them.
ORACLE-H MCP Server
Human-on-the-Loop validation for autonomous AI agents — via Model Context Protocol
What is ORACLE-H?
ORACLE-H is a safety infrastructure that acts as a mandatory checkpoint for autonomous AI agents. Before executing any critical, destructive, or irreversible action, the agent submits it for human approval via Telegram. The human decides with a single tap.
Agent → oracle_validate → Human gets Telegram alert → Approve/Reject → Agent proceedsWithout ORACLE-H: 4-step workflow succeeds ~81.5% of the time. With ORACLE-H: Same workflow succeeds ~99.6% of the time.
MCP Tools
Tool | Description |
| Submit a risky action for human approval. Returns a |
| Poll the decision until approved, rejected, or expired. |
Quick Start (Demo — no signup required)
# Test immediately with the public demo key
ORACLE_SIGNATURE_KEY=demo-signature-key-change-in-production
ORACLE_BASE_URL=https://oracle-h.onlineInstallation
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "<your-signature-key>",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}
}Cursor / Windsurf
Add to your MCP settings:
{
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "<your-signature-key>",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}Cline (VS Code)
// File: cline_mcp_settings.json
{
"mcpServers": {
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "demo-signature-key-change-in-production",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}
}Roo Code (VS Code)
// File: .roo/mcp.json (project-level)
{
"mcpServers": {
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "demo-signature-key-change-in-production",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}
}GitHub Copilot (VS Code)
Add to VS Code settings.json:
{
"github.copilot.chat.mcp.servers": {
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "demo-signature-key-change-in-production",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}
}n8n
Use the MCP Client Tool node in n8n, running via supergateway:
npx -y supergateway --stdio "npx -y oracle-h-mcp" --port 8811Then connect n8n's MCP Client Tool to http://localhost:8811/sse
Zed Editor
Add to settings.json:
{
"context_servers": {
"oracle-h": {
"command": {
"path": "npx",
"args": ["-y", "oracle-h-mcp"]
},
"env": {
"ORACLE_SIGNATURE_KEY": "<your-signature-key>",
"ORACLE_BASE_URL": "https://oracle-h.online"
}
}
}
}Continue.dev
Create .continue/mcpServers/oracle-h.yaml:
name: oracle-h
version: 1.0.0
schema: v1
mcpServers:
- name: oracle-h
command: npx
args:
- -y
- oracle-h-mcp
env:
ORACLE_SIGNATURE_KEY: <your-signature-key>
ORACLE_BASE_URL: https://oracle-h.onlineLangGraph (Python)
from langchain_mcp_adapters.client import MultiServerMCPClient
async with MultiServerMCPClient({
"oracle-h": {
"command": "npx",
"args": ["-y", "oracle-h-mcp"],
"env": {
"ORACLE_SIGNATURE_KEY": "your-key",
"ORACLE_BASE_URL": "https://oracle-h.online"
},
"transport": "stdio"
}
}) as client:
tools = client.get_tools()How it works
Agent calls
oracle_validatewith action, rationale, projected impact, and TTLHuman receives a Telegram notification with full context and risk analysis
Human taps Approve or Reject directly in Telegram
Agent polls
oracle_poll_statusuntil decision arrivesAgent proceeds or aborts based on the human decision
The system includes:
🛡️ Anti-hallucination Watchdog — detects context truncation before submitting
📊 Reliability Calculator — shows the statistical improvement (81.5% → 99.6%)
⏳ TTL / Expiry — requests auto-expire if no human response within the configured timeout
🔐 Bearer Token Auth — each agent has a unique signature key
🔒 HMAC-SHA256 signed webhooks — tamper-proof decisions
System Prompt Snippet
Add this to your agent's system prompt to ensure ORACLE-H is always used correctly:
## Human Approval Gate — ORACLE-H (MANDATORY)
Call oracle_validate BEFORE executing any action in these categories:
DESTRUCTIVE: Deleting files, dropping databases, removing users, git force-push
EXTERNAL WRITES: Sending emails, posting to APIs, submitting forms
FINANCIAL: Payments, billing changes, subscription modifications
INFRASTRUCTURE: Deployments, server config, DNS, environment variables
POLLING PROTOCOL:
After oracle_validate, poll oracle_poll_status every 10-15 seconds until:
- "approved" → proceed
- "rejected" → STOP, inform user, propose alternatives
- "expired" → STOP, ask user if they want to retry
HARD RULES:
- NEVER execute before "approved"
- If oracle_validate is unreachable: BLOCK the action, inform user
- Read-only operations do NOT require oracle_validateAPI
Full API documentation: oracle-h.online/llms.txt OpenAPI spec: oracle-h.online/openapi.json
License
MIT
Available Tools
2 toolsoracle_poll_statusA
Check the current status of a validation request previously submitted via oracle_validate. Poll every 10-15 seconds until status is "approved" or "rejected". If "expired", the human did not respond in time — abort the action.
| Name | Required | Description | Default |
|---|---|---|---|
| request_id | Yes | The request_id returned by oracle_validate |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes the polling behavior, timing recommendations, and status-based outcomes ('approved', 'rejected', 'expired'). However, it doesn't mention error handling, rate limits, or authentication requirements, leaving some behavioral aspects unspecified.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely efficient with three sentences that each serve distinct purposes: stating the core function, providing polling guidance, and specifying expiration handling. There is zero wasted text, and the most critical information appears first.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-parameter polling tool with no output schema, the description provides excellent context about the polling behavior, timing, and status outcomes. However, it doesn't describe the return format or what data the status check actually provides beyond the three mentioned states, which leaves some uncertainty about the tool's complete behavior.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents the request_id parameter. The description adds context by mentioning this is 'returned by oracle_validate', which provides useful semantic linkage but doesn't add significant technical details beyond what the schema provides. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action ('Check the current status') and resource ('a validation request previously submitted via oracle_validate'), distinguishing it from its sibling oracle_validate. It explicitly identifies what the tool does and what it operates on.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage instructions: 'Poll every 10-15 seconds until status is "approved" or "rejected"' and 'If "expired", the human did not respond in time — abort the action.' It gives clear timing guidance and specific conditions for when to stop polling or abort, which is comprehensive guidance for when and how to use this tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
oracle_validateA
Submit a critical or irreversible action to ORACLE-H for human approval. The human operator will receive a Telegram notification with full context and can approve or reject. ALWAYS use this tool before executing any destructive, financial, or irreversible operation. Returns a request_id to use with oracle_poll_status to retrieve the decision.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | Precise technical description of the action you are about to execute | |
| rationale | Yes | Why this action is necessary and why it is the optimal path | |
| projected_impact | Yes | Risk and impact if this action fails or is wrong. Must describe potential damage. | |
| financial_amount | No | Financial amount at stake in USD (0 if none) | |
| expires_in_seconds | No | How long to wait for the human response before timing out (default: 5 minutes) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key behavioral traits: the tool triggers human approval via Telegram notification, the action is critical/irreversible, and it returns a request_id for polling. However, it doesn't mention rate limits, authentication requirements, or error handling scenarios.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is perfectly structured and concise with zero waste. Three sentences each serve distinct purposes: stating the tool's purpose, providing usage guidelines, and explaining the return value. Every sentence earns its place and the information is front-loaded appropriately.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (human-in-the-loop approval system) and lack of annotations/output schema, the description provides good contextual completeness. It explains the approval workflow, Telegram notification mechanism, and relationship with oracle_poll_status. However, it doesn't describe what happens after timeout or error scenarios, leaving some gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all 5 parameters thoroughly. The description doesn't add any additional parameter semantics beyond what's in the schema. The baseline score of 3 is appropriate when the schema does the heavy lifting for parameter documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('submit a critical or irreversible action to ORACLE-H for human approval') and distinguishes it from its sibling oracle_poll_status by explaining the relationship. It precisely defines what the tool does: submitting actions for human approval via Telegram notification.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage guidelines: 'ALWAYS use this tool before executing any destructive, financial, or irreversible operation.' It clearly defines when to use it (for critical/irreversible actions) and references the alternative tool oracle_poll_status for retrieving decisions, creating a complete workflow.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v1.0.0- First observed
oracle_poll_status - First observed
oracle_validate
TDQS
The two tools have completely distinct and non-overlapping purposes: oracle_validate is for submitting actions for human approval, while oracle_poll_status is for checking the status of those submissions. Their descriptions clearly differentiate them, with no ambiguity in functionality.
Both tools follow a consistent 'oracle_verb_noun' pattern (oracle_poll_status and oracle_validate), using snake_case and starting with the server prefix. This makes them predictable and easy to identify within the server's namespace.
With only two tools, the server feels thin for its apparent purpose of handling human approval workflows. While the tools cover the core submit-and-poll cycle, there are likely missing operations like listing pending requests or managing notifications, making the scope underdeveloped.
The server provides basic coverage for the human approval domain with submit and poll operations, but there are notable gaps. Missing tools for operations like canceling requests, viewing request history, or configuring approval settings limit its completeness, though agents can still work with the core workflow.
Related MCP Connectors
Preventive human-approval write-gate for AI agents: writes commit only after a human approves.
- mcpOAuthcom.decionis
Authorize consequential AI agent actions before execution
Human-in-the-loop approval for agent actions, with verifiable action-bound receipts.
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/tponscr-debug/mcp-oracle-h'
If you have feedback or need assistance with the MCP directory API, please join our Discord server