Raposa Aval — human approval

Human approval for AI agents: a named person approves or rejects, silence is not consent.

AI & MLPythonv0.1.1

raposa-mcp

An MCP server that gives your agent one honest tool: ask a human.

request_human_approval(action, context, risk) -> { approved: true|false, decided_by, ... }

approved is true only when a named person pressed Approve. A timeout, an expiry or a rejection all return approved: false — silence is not consent. Every decision is sealed in Raposa's hash-chained audit log, exportable for an auditor. EU-hosted, DPA available.

Install

{
  "mcpServers": {
    "raposa": {
      "command": "uvx",
      "args": ["raposa-mcp"],
      "env": { "RAPOSA_API_KEY": "<your key>" }
    }
  }
}

Claude Code: claude mcp add raposa -e RAPOSA_API_KEY=<your key> -- uvx raposa-mcp

Get a free sandbox key (100 approvals a month) at https://raposa.group/start/ — it arrives by email in a minute.

Tools

ToolWhat it does
request_human_approval(action, context, risk, requested_by?, wait_sec=600, expires_in_sec?)creates the request and waits for a human; returns approved
create_approval(action, context, risk, requested_by?, expires_in_sec?, webhook_url?)returns the id at once; decision arrives on the HMAC-signed webhook or via get_approval
get_approval(approval_id)reads one approval

risk is low | medium | high. The API key is read from RAPOSA_API_KEY only and never appears in tool inputs or outputs. Base URL override: RAPOSA_API_BASE (default https://dcescrypt.com/api).

Who approves

The people on your team who hold the approve button get a scoped console login and, if you give us their email, every request also reaches them as a mail with signed Approve / Reject links. Their name is recorded on the decision. Docs: https://raposa.group/docs/#approvers

Develop

pip install -e ".[test]" && pytest -q

MIT · DC ESCRYPT SL · contact@raposa.group

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
uvx raposa-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "group-raposa-raposa-mcp": {
      "command": "uvx",
      "args": [
        "raposa-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

raposa-mcppypi

Compatible MCP Clients

Raposa Aval — human approval works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More