Metadata-Version: 2.5
Name: aigp-mcp
Version: 1.0.0
Summary: AIGP governance adapter for MCP tool invocations — policy, scope, consent, evidence
Requires-Python: >=3.10
Provides-Extra: all
Requires-Dist: boto3; extra == 'all'
Provides-Extra: aws
Requires-Dist: boto3; extra == 'aws'
Provides-Extra: dynamodb
Requires-Dist: boto3; extra == 'dynamodb'
Provides-Extra: s3
Requires-Dist: boto3; extra == 's3'
Description-Content-Type: text/markdown

# aigp-mcp

AIGP governance for MCP (Model Context Protocol) tool invocations.

Part of **MAIGP** — the Mediated AI Governance Protocol: a runtime consent / scope / evidence layer for AI systems. Every governed call is **CHECK**ed before it runs (policy, scope, jurisdiction, circuit-breaker) and **RECORD**ed + **TRACE**d as tamper-evident evidence after.

## What it governs

Governs MCP tool calls — policy, scope, consent, classification, and evidence.

## Governance model

This adapter maps the framework's lifecycle onto the AIGP agent-governance loop provided by [`maigp-agent-core`](https://pypi.org/project/maigp-agent-core/):

| Framework event | AIGP action |
|---|---|
| run / invocation start | **CHECK** (`pre_invoke`) — allowed? under what authority? |
| each model reply | token accounting (`on_model_call`) |
| each tool / function call | tool governance (`on_tool_call`) |
| run complete | **RECORD** + **TRACE** (`post_invoke`) |
| failure | `on_error` (recorded, then re-raised) |


## Install

```bash
pip install aigp-mcp
```

Pulls in [`maigp-agent-core`](https://pypi.org/project/maigp-agent-core/) (shared lifecycle) and, transitively, [`maigp-client`](https://pypi.org/project/maigp-client/).

## Quick start

```python
from aigp_mcp import GovernedMCPClient, MCPGovernanceConfig

config = MCPGovernanceConfig(
    mode="ENFORCE",
    gov_url="https://gov.example.com",
    app_id="mcp-gateway",
    hmac_secret="...",
)
governed = GovernedMCPClient(mcp_client, config)

# Pre-check → execute only if allowed → post-record evidence
result = await governed.call_tool("wiz", "listVulnerabilities",
                                  {"severity": "HIGH"})
```

## Modes & exports

`mode="ENFORCE"` blocks disallowed calls (raising `GovernanceDenied`); monitor-only modes record without blocking. Exports include `AccessDecision`, `GovernanceDenied`, and `ToolEvidence`.

## Links

- Protocol, specs & full adapter catalog: https://github.com/owner-spec/aigp-protocol
- Issues: https://github.com/owner-spec/aigp-protocol/issues

---

License: Proprietary. © Kanjani AI Research & Causum.
