rotascale-mcp
Govern any agent that speaks the Model Context Protocol — including agents whose code you cannot touch.
pip install rotascale-mcp
Two surfaces, and the difference is the whole point
rotascale-mcp |
rotascale-mcp-proxy |
|
|---|---|---|
| How it is reached | the agent decides to call a governance tool | every tool call passes through it |
| Can the agent avoid it | yes | no |
| Enforcement | advisory | in the tool path |
Only the proxy is a control. The server surface is genuinely useful — real
evidence, and a real gate for an agent that cooperates — but an agent that never
calls authorize_action is not governed by it. We would rather say that plainly
than let you find out during an incident.
Rotascale as an MCP server
Adds governance tools to any MCP host. The agent chooses when to call them.
{
"mcpServers": {
"rotascale": {
"command": "rotascale-mcp",
"env": {
"ROTASCALE_URL": "https://rotascale.acme.internal",
"ROTASCALE_API_KEY": "rota_live_…"
}
}
}
}
| Tool | When the agent calls it |
|---|---|
open_trajectory |
once, at the start of a task |
authorize_action |
before any consequential action — moving money, changing a record, contacting a person |
witness_step |
as it reads and acts; kind="retrieval" is what carries taint |
check_authority |
to see what it may do and what budget remains |
close_trajectory |
when the task ends, success or failure |
authorize_action returns an outcome, not a boolean
Six outcomes, each with a different remedy, and a guidance string written for
a model to act on:
| Outcome | What it means |
|---|---|
allow |
proceed |
deny |
outside the granted authority — do not retry, do not route around |
exhausted |
budget or call allowance spent — retrying cannot help |
gated |
the context is tainted and this authority needs a clean one |
review_sync |
a human must decide first |
review_async |
proceed, but it is queued for review |
A boolean would collapse these, and an agent that cannot tell exhausted from
gated will do the wrong thing about both — usually retrying, which is useless
for the first and a security problem for the second.
Transport
stdio by default, because that is how MCP hosts launch a local server. Logging goes to stderr, since stdout is the protocol channel.
ROTASCALE_MCP_TRANSPORT=streamable-http rotascale-mcp
Why a separate package
pip install rotascale must never carry an MCP dependency, and the MCP spec
revises on its own schedule. Pinning them together would force pointless
releases of one to keep up with the other.
Tracking MCP servers you already use
Separate from this package: the rotascale SDK's watch_mcp wraps an MCP
client session and reports each server's tool manifest, so a tool whose
description changes is caught — including between sessions. A description is
an instruction the model reads, so rewriting one changes what your agent does
without changing a line of your code.
from rotascale.middleware import watch_mcp
session = watch_mcp(session, server="filesystem", transport="stdio")
Metadata
Release files for rotascale-mcp 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rotascale_mcp-0.1.1.tar.gz | 96.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rotascale_mcp-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 120.4 kB
Release files / rotascale_mcp-0.1.1.tar.gz
| Download URL | rotascale_mcp-0.1.1.tar.gz |
|---|---|
| Size | 96.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a1505806d2bc423e72640de654b4d444fd6c3f41a4565f31943001a35496bb08
|
|
BLAKE2b-256 checksum How to use checksums |
3dbed01ed81a30ad40eee385ac73142148fb2d171d91e32f76638a82040289c8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 7, 2026.
Transparency logRelease files / rotascale_mcp-0.1.1-py3-none-any.whl
| Download URL | rotascale_mcp-0.1.1-py3-none-any.whl |
|---|---|
| Size | 23.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
84d738f14fff74cd49803cf8a95ed7ce2bde12467ad2e808b3432bd87a1b0314
|
|
BLAKE2b-256 checksum How to use checksums |
e3cc4754c28442597a72ee337f5504c62c98e9269311a07d50affcd53fc78bc9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 7, 2026.
Transparency log