Skip to main content
ClaudeWave

Turn existing OpenAPI services into tools AI agents can discover and call under your rules.

MCP ServersRegistry oficial1 estrellas0 forks● GoApache-2.0Actualizado today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (Apache-2.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 10/4/2026
Install in Claude Code / Claude Desktop
Method: Manual · veto
Claude Code CLI
git clone https://github.com/aiveto/veto
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "veto": {
      "command": "veto"
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Install the binary first: go install github.com/aiveto/veto@latest (make sure it ends up on your PATH).
Casos de uso

Resumen de MCP Servers

<img src="docs/veto-social.png" width="1280" alt="veto makes it possible for an AI agent to call your API with context and semantics. A hundred endpoints stay 3 tools.">

**Turn existing OpenAPI services into tools AI agents can discover and call under your rules.**

The model may request a call. Veto checks policy, requires approval for a destructive call, and resolves credentials before your API runs. Declared relations name a linked operation. A trace records the decision.

**The model proposes. Veto decides. Your API executes.**

Connect an MCP client, or embed the Go runtime. MCP, the CLI, eval, and a generated Go client share that runtime. The client calls the catalog through search, describe, and invoke. A hundred endpoints do not become a hundred tools. Your services stay where they already run.

```bash
brew install aiveto/veto/veto
```

```bash
go install github.com/aiveto/veto/cmd/veto@latest
```

`brew` does not need Go. `go install` needs Go 1.27.1. Binaries are on [GitHub Releases](https://github.com/aiveto/veto/releases). A release also pushes `ghcr.io/aiveto/veto`.

## See veto in action

[veto-demo](https://github.com/aiveto/veto-demo) is the full walk. Harbor sells home goods. Orders, customers, and billing are the APIs. The walk follows a customer from an order, holds a delete until a person approves it, and keeps the secret out of the trace. `make demo` runs the story. `make mcp` leaves Harbor listening and prints the config for Claude, Cursor, or ChatGPT.

This repo runs the relation, the held delete, and the redacted trace, then exits. No model key.

```bash
git clone https://github.com/aiveto/veto.git
cd veto
go run ./examples/two-apis
```

```text
Someone asked who placed order 123.
orders.get returned customerId 7.
customers.get was called for 7 because the note said Order.customerId identifies customers.get.
orders.delete sent no HTTP until approved.
The trace left the secret out.
```

## A delete waits

```text
Agent requests the call                          -> pending ID; no upstream HTTP
Person accepts the form in the chat              -> one matching invocation
Host without that form: veto approve <id>        -> approved ID, then the agent submits it once
```

The approval is bound to the caller, the operation, and the parameters. Permission and confirmation run before credentials are fetched and before HTTP. An [OPA](docs/guide.md#policy) allow does not skip those checks. A webhook or a command can notify your approval system. The server and `veto approve` share approval storage and signing configuration. `confirmation: false` in [`veto.yaml`](docs/guide.md#one-vetoyaml) turns that gate off for the deployment. Unset leaves it on.

A per-caller limit stops a call before policy. Timeouts and retries apply to the call that is sent.

## The next call is declared

```yaml
relations:
  - schema: Order
    field: customerId
    to: customers.get
```

Search returns the related operation. Describe returns the note, such as `Order.customerId identifies customers.get`. The Go Follow API walks that link. MCP invoke runs one operation. [Relations](docs/guide.md#relations).

## What the agent receives

The tool names are `capabilities_search`, `capabilities_describe`, and `capabilities_invoke`. Direct pins add a few operations beside those three. Grouped mode adds one tool per resource. Search matches the summary, tags, the path noun, and synonyms such as retire for delete. An overlay can add a word of your own.

[Response shaping](docs/guide.md#mcp) returns named fields and a bounded list, and marks pagination and truncation. A Go [context pack](docs/guide.md#pack) holds rules, operation summaries, the conversation, relations, and a pending confirmation, inside a byte budget. The raw OpenAPI document stays out of the pack.

## Connect your services

[`veto init`](docs/guide.md#one-vetoyaml) writes `veto.yaml` for the OpenAPI files or URLs you name, and a `relations.yaml` stub if you do not have one. If `veto.yaml` is already there, `init` stops.

```bash
veto init orders.yaml customers.yaml
```

`veto serve --stdio` speaks MCP on stdin. [Authenticated Streamable HTTP](docs/guide.md#remote-mcp) serves the same runtime to a remote client.

Credentials come from the environment, OAuth, a caller-supplied token, token exchange, a command that returns headers, or a Go provider that signs the request. The agent does not perform that login. [Authentication](docs/guide.md#auth).

## Check it

| Task | How |
| --- | --- |
| The catalog loads, and its operation count and joins are printed | [`validate`](docs/guide.md#one-vetoyaml) |
| Missing auth, a colliding operation id, or a parameter that cannot be sent | [`doctor`](docs/guide.md#doctor) |
| The request and the policy decision, before a token is fetched and before HTTP | [`preview`](docs/guide.md#preview) |
| Run a case | [`eval`](docs/guide.md#check-in-ci) |
| Fail when a joined operation disappears, confirmation or a permission is dropped, a new destructive operation appears, or a case expectation changes. `confirmation: false` is the record of a deployment-wide drop | [`check --against`](docs/guide.md#check-in-ci) |
| Print a saved trace | [`replay --from`](docs/guide.md#replay) |
| Run a message | [`replay`](docs/guide.md#replay) |
| Share contracts, relations, and cases apart from deployment credentials | [capability bundle](docs/guide.md#capability-bundle) |
| Call the same runtime from your own Go module | [generate](docs/guide.md#generate) a client, a CLI, and an MCP dispatch package |

Traces are OpenTelemetry. OTLP export is optional. The Go model and memory interfaces, and sequential flows, run in-process. They are not a durable workflow service.

```bash
veto validate --config testdata/veto.yaml
veto eval --config testdata/veto.yaml --case testdata/delete.yaml
veto serve --config testdata/veto.yaml --stdio
```

`testdata/veto.yaml` is already written, so these commands start at `validate`. `eval` runs the delete case in this repo. `serve --stdio` is the MCP process. A call needs an API that is still listening, which is what veto-demo keeps up.

## Scope

**Pre-1.0.** Public APIs may change.

[Setup guide](docs/guide.md) | [Current limits](docs/guide.md#limits)
ai-agentscligogolangllmmcpmodel-context-protocolopenapi3opentelemetry

Lo que la gente pregunta sobre veto

¿Qué es aiveto/veto?

+

aiveto/veto es mcp servers para el ecosistema de Claude AI. Turn existing OpenAPI services into tools AI agents can discover and call under your rules. Tiene 1 estrellas en GitHub y su última actualización registrada es del 2026-10-04.

¿Cómo se instala veto?

+

Puedes instalar veto clonando el repositorio (https://github.com/aiveto/veto) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar aiveto/veto?

+

Nuestro agente de seguridad ha analizado aiveto/veto y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene aiveto/veto?

+

aiveto/veto es mantenido por aiveto. La última actividad registrada en GitHub es del 2026-10-04, con 0 issues abiertos.

¿Hay alternativas a veto?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega veto en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: aiveto/veto
[![Featured on ClaudeWave](https://claudewave.com/api/badge/aiveto-veto)](https://claudewave.com/repo/aiveto-veto)
<a href="https://claudewave.com/repo/aiveto-veto"><img src="https://claudewave.com/api/badge/aiveto-veto" alt="Featured on ClaudeWave: aiveto/veto" width="320" height="64" /></a>

Más MCP Servers

Alternativas a veto