Expand description
Per-tool audit for external MCP servers served over the HTTP gateway.
A client-mediated tools/call to an external provider has no backend
process to record it, so the gateway taps the forwarded request/response,
writes one mcp_tool_executions row under the calling user, and hands the
result to the artifact ingest. The execution id is minted before the
response leaves, and stamped into its _meta, so the client’s own later
report of the same result carries the exact server key. record composes
the tap over the upstream body; the tap owns an McpAudit and finalizes
it (once) on stream EOF or drop.
Copyright (c) systemprompt.io — Business Source License 1.1. See https://systemprompt.io for licensing details.
Modules§
- jsonrpc
- Minimal JSON-RPC / MCP frame parsing for the tool-call audit tap.
- tap
- Observe-while-forwarding tap that captures an external MCP tool-call result and stamps the execution id into it.