Back to Directory/Developer Tools

io.github.dingdawg/dingdawg-governance

Universal governance layer for AI agents. MCP-native, fail-closed, audit proofs and rollback.

Developer ToolsJavaScriptv2.1.6

DingDawg Governance

npm version npm downloads License: MIT

Every AI action receipted. Capability-gated. Rollback-ready.

AI Governance-as-a-Service via MCP. Every write, shell command, and state-changing operation your agent makes is validated before it runs and cryptographically receipted after it completes — giving you a tamper-evident audit trail you can query, export, or roll back at any time.

Works with Claude Code, Codex, Cursor, Windsurf, and any MCP-compatible agent.


Install

npm install dingdawg-governance

Quick Start

# Authenticate (free — no credit card)
npx dingdawg-governance auth login

# Start the governance MCP server
DINGDAWG_API_KEY=your_key npx dingdawg-governance

Add to your MCP client config:

{
  "mcpServers": {
    "dingdawg-governance": {
      "command": "npx",
      "args": ["dingdawg-governance"],
      "env": {
        "DINGDAWG_API_KEY": "your_key_here"
      }
    }
  }
}

Get your free API key at app.dingdawg.com/settings/api.


What You Get

  • Pre-execution validation — Every action checked against your policy before it runs. Blocked actions never touch your filesystem.
  • Cryptographic receipts — Tamper-evident record for every action with a unique ID, output hash, and public verification URL.
  • One-command rollback — Undo any file write by referencing its receipt ID. Prior state is captured automatically before every write.
  • Real-time trust scores — Behavioral pattern tracking across sessions surfaces anomalies before they become incidents.
  • Compliance reports in seconds — SOC 2 and ISO 27001-aligned audit reports as signed PDF or structured JSON. One API call.

MCP Tools

ToolWhat it does
validate_actionPre-execution check. Returns APPROVED, FLAGGED, or BLOCKED with reason code and risk score.
generate_receiptPost-execution cryptographic receipt with tamper-evident output hash.
capture_rollback_stateSnapshot current state before destructive or high-risk operations.
rollback_actionRestore prior state from a receipt ID.
query_receiptsSearch receipts by date, agent, action type, or status. Export-ready.
check_statusCurrent tier, daily usage, quota, and active governance alerts.
generate_audit_reportOn-demand compliance report — SOC 2, ISO 27001, or custom policy framework.

Plans

PlanGoverned actions/dayRollback windowAudit reports
Free200——
Pro — $29/mo10,00030 daysUnlimited
Business — $149/moUnlimited90 daysCompliance PDF

No credit card to start. Full pricing: dingdawg.com/governance#pricing


Documentation

Full docs at dingdawg.com/governance/docs


Contributing

Issues and pull requests welcome. See CONTRIBUTING.md.

github.com/dingdawg/governance-mcp


Built by DingDawg — Trust layer for the agentic internet.

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y dingdawg-governance

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-dingdawg-dingdawg-governance": {
      "command": "npx",
      "args": [
        "-y",
        "dingdawg-governance"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

dingdawg-governancenpm

Compatible MCP Clients

io.github.dingdawg/dingdawg-governance works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More