Back to News
RSS feedgithub.com

Stepgate Uses Gated Stepfiles to Keep AI Agents on Procedure

Summary

Stepgate is an MCP server that turns an agent procedure into a YAML stepfile whose ordered steps cannot be skipped. Each step declares its inputs, permitted remote APIs or MCP servers, expected output, and gates; the server reveals only the current step, performs the required API calls, and advances only after the output passes JSON Schema, JSONLogic, or an HTTP verifier. For example, its package-notes workflow retrieves npm versions itself, lets the model write notes, and rejects notes whose versions differ from the registry response. Mechanical steps can build outputs without a model, while derived fields can calculate values after submission, leaving the model to handle judgment. Human approval can be required through MCP elicitation before a later step writes to a service. Stepgate attaches credentials on the server, restricts calls to hosts declared by the stepfile, and keeps model keys out of the client workflow. Failed gates return diagnoses for a bounded number of retries. Each run produces a hash-chained ledger covering steps, tool calls, gate verdicts, and retries; the `--verify` command detects later edits. Stepfiles can be used from clients such as Claude Code, Cursor, and VS Code through stdio or HTTP, with commands for testing gates offline, recording cases, watching files, and authenticating to MCP servers. The project also includes a catalog of reviewed stepfiles and tools that help agents draft and validate new ones.