Repository navigation
Expand file tree
/
Copy pathmkdocs.yml
More file actions
236 lines (228 loc) · 8.17 KB
/
Copy pathmkdocs.yml
File metadata and controls
236 lines (228 loc) · 8.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
site_name: cMCP
site_description: "Check routed MCP tool calls against Cedar policy and sign TRACE session records. Start in software mode; evaluate hardware provenance separately."
site_url: https://cmcp.agentrust-io.com
repo_url: https://github.com/agentrust-io/cmcp
repo_name: agentrust-io/cmcp
edit_uri: edit/main/docs/
docs_dir: docs
exclude_docs: |
.github/
node_modules/
benchmarks/
src/
tests/
Dockerfile
docker-compose.yml
LICENSE
NOTICE
ANTITRUST.md
ADOPTERS.md
MAINTAINERS.md
SECURITY.md
CHARTER.md
CODE_OF_CONDUCT.md
pyproject.toml
.gitignore
theme:
name: material
custom_dir: overrides
font: false
logo: assets/icon.svg
favicon: assets/icon.svg
palette:
- scheme: default
primary: custom
accent: custom
toggle:
icon: material/brightness-4
name: Switch to dark mode
- scheme: slate
primary: custom
accent: custom
toggle:
icon: material/brightness-7
name: Switch to light mode
features:
- navigation.instant
- navigation.tracking
- navigation.tabs
- navigation.tabs.sticky
- navigation.sections
- navigation.top
- navigation.path
- search.suggest
- search.highlight
- content.code.copy
- content.tabs.link
- toc.follow
icon:
repo: fontawesome/brands/github
hooks:
# Per-page meta descriptions; see the module docstring.
- hooks/seo.py
plugins:
- search
- llmstxt:
full_output: llms-full.txt
markdown_description: >-
cMCP is an open-source gateway for MCP tool-call policy enforcement.
It evaluates routed calls against Cedar policy and signs session records.
Software mode demonstrates policy and signature checks without hardware
provenance. Hardware deployments require provider-specific attestation
verification, trusted inputs, and a deployment that prevents gateway bypass.
The agent, model, and upstream tool server remain separate components.
Part of AgenTrust, open specifications for verifiable AI: https://agentrust-io.com.
sections:
Get started:
- index.md
- quickstart.md
- concepts.md
- configuration.md
- spec-index.md
Specification:
- SPEC.md
- spec/cedar-policy.md
- spec/session-policy.md
- spec/tool-identity.md
- spec/transport.md
- spec/proxy-security.md
- spec/attestation.md
- spec/verification-library.md
- spec/embodied-action-evidence.md
- spec/error-codes.md
- spec/threat-model.md
Guides:
- tutorials/existing-mcp-clients.md
- tutorials/connecting-agent-frameworks.md
- tutorials/cedar-policy-walkthrough.md
- tutorials/verifying-a-trace-claim.md
- tutorials/tee-attestation.md
- tutorials/deploy-azure.md
- tutorials/deploy-gcp.md
- testing/hardware-validation.md
Project:
- limitations.md
- sponsors.md
- minify:
minify_html: true
- mkdocstrings:
default_handler: python
handlers:
python:
paths: [src]
options:
docstring_style: google
show_source: false
show_root_heading: true
show_root_full_path: false
show_symbol_type_heading: true
show_symbol_type_toc: true
members_order: source
separate_signature: true
show_signature_annotations: true
unwrap_annotated: true
markdown_extensions:
- admonition
- pymdownx.details
- pymdownx.superfences:
custom_fences:
- name: mermaid
class: mermaid
format: !!python/name:pymdownx.superfences.fence_code_format
- pymdownx.tabbed:
alternate_style: true
- pymdownx.highlight:
anchor_linenums: true
- pymdownx.inlinehilite
- pymdownx.snippets:
base_path: ["."]
check_paths: true
- pymdownx.emoji:
emoji_index: !!python/name:material.extensions.emoji.twemoji
emoji_generator: !!python/name:material.extensions.emoji.to_svg
- attr_list
- md_in_html
- tables
- toc:
permalink: true
extra:
social:
- icon: fontawesome/brands/linkedin
link: https://www.linkedin.com/company/agentrust-io/
name: AgenTrust on LinkedIn
- icon: fontawesome/brands/github
link: https://github.com/agentrust-io/cmcp
generator: false
extra_css:
# Shared AgenTrust editorial design system. Deliberately the only stylesheet:
# a local override here is how this site drifted to the Material default
# violet last time. Change the shared file instead.
# The ?v= matches CSS_VERSION in agentrust-io.github.io tools/site_header.py. Browsers keep these files for hours, so bump it there and here together.
- https://agentrust-io.com/design-system.css?v=22
nav:
- Home: index.md
- Get started:
- Quick start: quickstart.md
- How it works: concepts.md
- Configuration: configuration.md
- Specification index: spec-index.md
- Specification:
- Overview: SPEC.md
- Policy and identity:
- Component model: spec/component-model.md
- Cedar policy: spec/cedar-policy.md
- Session policy: spec/session-policy.md
- Sink sensitivity ceilings: spec/sink-policy.md
- Disclosure authorization: spec/disclosure-authorization.md
- Policy hot-reload: spec/policy-hot-reload.md
- Tool identity: spec/tool-identity.md
- Catalog lifecycle: spec/catalog-lifecycle.md
- Catalog approval provenance: spec/catalog-approval-provenance.md
- Transport and proxy:
- Transport: spec/transport.md
- stdio transport: spec/stdio-transport.md
- Proxy security: spec/proxy-security.md
- Response inspection: spec/response-inspection.md
- Call graph: spec/call-graph.md
- Phase 2 server: spec/phase2-server.md
- Attestation and evidence:
- Attestation: spec/attestation.md
- SNP platform policy: spec/platform-policy.md
- TPM security model: spec/tpm-security-model.md
- Verification library: spec/verification-library.md
- Embodied action evidence: spec/embodied-action-evidence.md
- Errors and threats:
- Error codes: spec/error-codes.md
- Failure modes: spec/failure-modes.md
- Threat model: spec/threat-model.md
- Guides:
- Tutorials:
- Try it from an existing MCP client: tutorials/existing-mcp-clients.md
- Connecting agent frameworks: tutorials/connecting-agent-frameworks.md
- Tool catalog authoring: tutorials/tool-catalog-authoring.md
- Cedar policy walkthrough: tutorials/cedar-policy-walkthrough.md
- Advisory mode debugging: tutorials/advisory-mode-debugging.md
- TLS pinning: tutorials/tls-pinning.md
- Verify a TRACE claim: tutorials/verifying-a-trace-claim.md
- TEE attestation: tutorials/tee-attestation.md
- Response inspection tutorial: tutorials/response-inspection.md
- Kill switch: tutorials/kill-switch.md
- Deployment:
- Deploy on Azure: tutorials/deploy-azure.md
- Deploy on GCP: tutorials/deploy-gcp.md
- Multi-tenant deployment: tutorials/multi-tenant-config.md
- Testing:
- Benchmarks: testing/benchmarks.md
- Soak test: testing/soak-test.md
- Hardware validation: testing/hardware-validation.md
- Project:
- Limitations: limitations.md
- Roadmap: https://github.com/agentrust-io/cmcp/blob/main/ROADMAP.md
- Governance: https://github.com/agentrust-io/cmcp/blob/main/GOVERNANCE.md
- Sponsors: sponsors.md
- Contributing: https://github.com/agentrust-io/cmcp/blob/main/CONTRIBUTING.md
- Changelog: https://github.com/agentrust-io/cmcp/blob/main/CHANGELOG.md
extra_javascript:
# Shared cross-project top navigation (TRACE / Manifest / cMCP / cA2A / ...)
# The ?v= matches CSS_VERSION in agentrust-io.github.io tools/site_header.py. Browsers keep these files for hours, so bump it there and here together.
- https://agentrust-io.com/supernav.js?v=22