Before AI acts, Decionis decides. @decionis/mcp is a stdio Model Context Protocol server that lets AI coding agents — Claude Code, Cursor, Codex, Copilot, OpenHands — read a repository's DECIONIS_POLICY.md and evaluate candidate actions before they commit, deploy, or migrate anything. Locally, with zero network, zero credentials, and nothing recorded.
It is not a re-implementation: decionis_evaluate boots the platform's own evaluator — bundled into this package — in-process, publishes your repo policy through the protocol's schema-validated bundle ingestion, and evaluates through the same path the hosted service uses. The verdict an agent sees locally is the verdict the platform would produce.
No install needed — every client below launches the server with npx. The package ships three
executables, so name the one you want with --package:
npx -y --package=@decionis/mcp decionis-mcpClaude Code — one command:
claude mcp add decionis -- npx -y --package=@decionis/mcp decionis-mcpor .mcp.json at the repo root:
{
"mcpServers": {
"decionis": {
"command": "npx",
"args": ["-y", "--package=@decionis/mcp", "decionis-mcp"]
}
}
}Codex — ~/.codex/config.toml, or a trusted project's .codex/config.toml:
[mcp_servers.decionis]
command = "npx"
args = ["-y", "--package=@decionis/mcp", "decionis-mcp"]
required = trueCursor — use the same server block as Claude Code in .cursor/mcp.json.
Prefer a global install? npm install -g @decionis/mcp puts decionis-mcp on your PATH, and
every config above simplifies to "command": "decionis-mcp".
| Tool | Purpose |
|---|---|
decionis_read_policy |
Path, sha256, and compiled rules (or compile errors) of the repo's DECIONIS_POLICY.md. |
decionis_evaluate |
Evaluate a candidate action payload against the policy through the real evaluator; returns the verdict + matched rule. |
decionis_verdict_help |
The verdict vocabulary, rules-block grammar, and how an agent should behave on each verdict. |
The policy file resolves from the tool's path argument, then $DECIONIS_POLICY_PATH, then ./DECIONIS_POLICY.md in the working directory.
DECIONIS_POLICY.md lives at your repo root. Write whatever prose your team wants around it, but
only a fenced ```decionis block is enforceable — prose outside the fence is documentation,
and a file with no block makes decionis_evaluate return no_rules_block:
# Decionis Policy
Destructive shell commands need a human; agent-authored infra changes wait for review.
```decionis
{
"version": 1,
"rules": [
{
"name": "Block destructive shell commands",
"priority": 100,
"domain": "*",
"all": [{ "field": "context.destructive", "op": "eq", "value": true }],
"action": "block"
},
{
"name": "Restrain AI-authored infra changes",
"priority": 80,
"domain": "*",
"all": [{ "field": "context.agent_generated", "op": "eq", "value": true }],
"action": "restrain"
}
]
}
```decionis_read_policy returns the compiled rules (or the compile errors) so you can check the block
before relying on it. Start from a forkable policy on the
Policy Exchange
(e.g. claude-code-destructive-shell-gate), or copy the fully annotated
examples/DECIONIS_POLICY.md
from the govern repo — the same file format governs both surfaces.
MCP tools are the discovery and explanation surface: the model can consult them. The native PreToolUse hooks are the binding surface: they intercept every supported tool call outside the model's discretion. Codex, GitHub Copilot, and Claude Code all normalize into one AgentToolCall contract and one AgentGateEvaluator interface.
npm install -g @decionis/mcp # puts decionis-agent-hook on the PATHCopy the provider template (ships inside the package) to its native repository location:
| Host | Template | Native location |
|---|---|---|
| Codex | templates/CodexHooks.json |
.codex/hooks.json |
| Claude Code | templates/ClaudeSettings.json |
.claude/settings.json |
| GitHub Copilot CLI / cloud agent / VS Code | templates/CopilotHooks.json |
.github/hooks/Decionis.json |
The templates ship inside the installed package, so copy them from there — for Claude Code:
mkdir -p .claude && cp "$(npm root -g)/@decionis/mcp/templates/ClaudeSettings.json" .claude/settings.jsonA templates/managed/ set (Codex requirements.toml pinning, a root-owned Copilot policy hook, and
an org-controlled Claude settings fragment) ships alongside them for device-management rollouts.
The hook defaults to local mode — it loads DECIONIS_POLICY.md, publishes it into the in-process evaluator, and enforces the result with no network access or credentials.
Switch to the enterprise policy graph and signed decision pipeline with:
DECIONIS_AGENT_GATE_MODE=remote
DECIONIS_AGENT_GATE_URL=https://protocol.decionis.com/v1/protocol/evaluate-decision
DECIONIS_API_KEY=<org-scoped-key>
DECIONIS_ORG_ID=<org-uuid>DECIONIS_AGENT_GATE_TIMEOUT_MS optionally changes the remote request timeout (default 4 s). Partial remote configuration is rejected; network errors, invalid hook input, missing policy, and evaluator failures all produce a native deny.
An APPROVE result adds no permission override — the host's normal sandbox and approval flow still applies. REJECT, REVIEW, and ESCALATE all stop the tool call; the latter two stay blocked until a human resolves them through the policy workflow.
- MCP surfaces:
https://decionis.com/.well-known/mcp.json - Full API contract:
https://decionis.com/.well-known/openapi.json
Source of truth for the published npm package lives in the Decionis platform monorepo; this repository is the public home for setup guides, samples, and issue reports. Bugs and feature requests are welcome here — the issue forms route them to the right package.
- Gating CI/CD pipelines instead of agents? The same gate is a GitHub Action:
decionis/govern(Marketplace). - Try a live policy check — no account needed — in the Sandbox.
- Security issues: never open a public issue — see our security policy / security@decionis.com.