Featured

Deploy OpenClaw in 60 seconds β€” 20% off logoDeploy OpenClaw in 60 seconds β€” 20% off

Launch OpenClaw on Hostinger in about 60 seconds and keep your agent live 24/7. Our referral link gives you 20% off, no coupon code needed.

Launch on Hostinger β†’
Run your Hermes agent on Hostinger, fully managed logoRun your Hermes agent on Hostinger, fully managed

Launch Hermes on Hostinger in one click, fully managed, no VPS knowledge needed. Use code ZACAARON10 for 10% off.

Launch on Hostinger β†’
Crawl and scrape any site into clean data, 10% off logoCrawl and scrape any site into clean data, 10% off

Firecrawl crawls and scrapes any site into clean markdown for your agent. Get 1,000 free credits, and new users get 10% off their first purchase.

Try Firecrawl free β†’
6,000+ web scrapers for your AI agent, start free logo6,000+ web scrapers for your AI agent, start free

Apify gives your agent live web data: 6,000+ prebuilt scrapers and actors, MCP-ready. Sign up free with $5 in usage credits.

Try Apify free β†’
One API to scrape, enrich, and extract the internet. logoOne API to scrape, enrich, and extract the internet.

Context.dev gives your agents a single API to scrape, enrich, and extract live web data β€” no proxies, no parsers, no maintenance.

Start building free β†’
SetupClaw: done-for-you OpenClaw for founders & exec teams logoSetupClaw: done-for-you OpenClaw for founders & exec teams

White-glove OpenClaw for founders and exec teams (4–50+ employees): we install, harden, integrate your tools, and maintain it β€” secured from day one.

Get it set up for you β†’
SEO data APIs for your agent, $1 free credit logoSEO data APIs for your agent, $1 free credit

DataForSEO gives your agent live access to SERP results, keyword data, backlinks, and on-page SEO data through one API. New accounts get a $1 credit, good for up to 20,000 keyword or backlink lookups.

Try DataForSEO free β†’
Reach 48,000+ AI builders

A flat monthly placement in front of developers actively installing AI tools. No lock-in, cancel anytime.

Advertise here β†’

Works with

Claude CodeClaude DesktopCursorVS CodeClineCodex CLIOpenClaw+ any MCP client

Install to Claude Code

This server doesn't publish a one-line install command. Follow the setup in the source repository.

Summary

sint-ai/sint-protocol MCP server](https://glama.ai/mcp/servers/sint-ai/sint-protocol/badges/score.svg)](https://glama.ai/mcp/servers/sint-ai/sint-protocol) πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Security-first MCP governance proxy (sint-mcp) with capability tokens, T0-T3...

README.md

SINT Protocol

![CI](https://github.com/sint-ai/sint-protocol/actions/workflows/ci.yml) !Node.js !TypeScript !License

![Glama](https://glama.ai/mcp/servers/sint-ai/sint-protocol)

Open-source runtime security and governance for AI agents, MCP tools, robotics, industrial automation, and physical AI.

Mission Authority: SINT also provides a hardware-agnostic authority and evidence protocol for autonomous air, ground, maritime, and robotic systems. It binds platform identity, mission scope, operator authorization, abort behavior, and signed after-action evidence without selecting targets or generating effects. See docs/mission-authority.md.

SINT Protocol is an open protocol and TypeScript reference stack that sits between AI agent intent and real-world execution. Before a governed tool call, robot command, industrial write, payment-like action, or actuator movement can run, the request passes through PolicyGateway.intercept() for capability-token authorization, T0-T3 approval tiering, physical constraint enforcement, revocation checks, and tamper-evident evidence logging.

What is SINT Protocol?

SINT is an AI agent security control plane for actions with real-world consequence. It helps teams answer four questions before an autonomous system acts:

  • Who is allowed to act? Ed25519 capability tokens bind issuer, subject,

resource, action, expiry, constraints, and delegation chain.

  • What constraints apply? Velocity, force, geofence, budget, rate-limit, and

consent constraints travel with the token instead of living in ad hoc config.

  • When is human review required? T0-T3 approval tiers route low-risk actions

automatically and escalate physical or irreversible actions to operators.

  • How do you prove what happened? Every decision can be written to a

SHA-256 hash-chained EvidenceLedger with portable proof receipts.

Where SINT Fits

SINT is not a replacement for MCP, A2A, ROS 2, MAVLink, MQTT, OPC UA, Open-RMF, or industrial robot tooling. It is the enforcement layer in front of those systems:

  • MCP security: authorize tool calls before an MCP server executes them.
  • Agent runtime governance: add pre-tool authorization, typed deny/escalate

outcomes, and evidence references to agent frameworks.

  • Robotics and drones: enforce ROS 2, MAVLink, PX4, and fleet actions with

physical constraints and e-stop semantics.

  • Industrial automation: govern OPC UA, MQTT/Sparkplug, SRCI, simulator, and

offline robot-program paths before PLC or robot actions touch equipment.

  • Consumer and regulated data: apply consent, caregiver delegation,

differential privacy, and audit exports for smart-home and health workflows.

Latest Implementation Highlights

  • Installable MCP proxy: npx -y sint-mcp --stdio runs the security-first

multi-MCP proxy.

  • Industrial humanoid shipyard safety: executable conformance fixtures now

cover Persona-style shipyard humanoid welding, hot-work permits, fire watch, fume extraction, confined-space gas safety, bystander escalation, simulation-to-execution drift, material load envelopes, and unconditional e-stop rollback.

  • Shipyard bridge and evidence scaffolding: ROS 2 weld-start profile

helpers, OPC UA safety-signal mappings, Isaac Sim receipt stubs, and sintctl shipyard evidence export generate hash-chained JSONL evidence for supervisor review, remote survey support, and incident reconstruction.

  • Agent commerce governance: the Economic Layer now includes a conformance

profile for agent-to-agent task markets: task creation, bids, worker selection, benchmark-proof submission, settlement release, and x402-style payment permits.

  • Five-minute interceptor demo: pnpm run demo:interceptor-quickstart

shows request -> decision -> receipt and the fail-closed path.

  • Production gateway posture: production mode requires durable stores,

explicit authentication, readiness checks, and signature enforcement.

  • Industrial action pack: pnpm run demo:factory-action and

pnpm run demo:industrial-pack verify deny, escalate, approve, simulate, and receipt-chain flows before vendor adapter execution.

  • Autonomy supervisor: @pshkv/autonomy-supervisor adds an authority lane

for managed autonomy: stable -> metacognitive_recovery -> assisted_recovery -> regulated_control.

  • External evidence packets: OWASP Agentic AI landscape, MITRE ATLAS

candidate mappings, AAIF RFC-001 packet, NIST bundle, dependency review, and production-slice validation artifacts are published under docs/.

Academic and compliance grounding: SINT is designed with reference to IEC 62443 FR1-FR7, EU AI Act Article 13, and NIST AI RMF. The evaluation framework references the ROSClaw empirical safety study (arXiv:2603.26997) and MCP security analysis (arXiv:2601.17549).

Agent ──► SINT Bridge ──► Policy Gateway ──► Allow / Deny / Escalate
                               β”‚
                       Evidence Ledger (SHA-256 hash-chained)
                               β”‚
                    ProofReceipt (pluggable attestation)

Install the MCP server

The installable server entrypoint is sint-mcp.

npx -y sint-mcp --stdio
npx -y sint-mcp --config ./sint-mcp.config.example.json --stdio

If you prefer containers, build and run the repo root Dockerfile:

docker build -t sint-mcp .
docker run --rm -i sint-mcp

Try the interceptor flagship in 5 minutes

If you want the fastest builder-facing path into the SEP-1763 interceptor work:

pnpm install
pnpm run build
pnpm run demo:interceptor-quickstart

That walkthrough shows the full flagship loop in one terminal transcript:

  • MCP-style request enters the interceptor
  • SINT returns allow or escalate
  • an audit receipt is generated for the allowed path
  • execution fail-closes when a gate prerequisite is missing

Start here:

Production-Ready Core

For production deployments, SINT now fails closed unless the gateway is started with durable stores and explicit authentication:

SINT_ENV=production
SINT_STORE=postgres
SINT_CACHE=redis
DATABASE_URL=postgresql://...
REDIS_URL=redis://...
SINT_API_KEY=...
SINT_REQUIRE_SIGNATURES=true
SINT_WS_ALLOW_QUERY_API_KEY=false

Use /v1/ready as the orchestration health gate; it verifies the configured store and cache, while /v1/health only proves the process is alive.

Production references:

Why SINT?

AI agents now execute code, call tools, move money, operate robots, control smart-home devices, and interact with industrial systems. The risk is no longer only prompt quality; it is whether the runtime has a verifiable control point between "the model decided" and "the world changed."

SINT makes that control point explicit. It turns agent execution into a governed workflow with scoped authority, pre-action policy evaluation, operator review, physical limits, revocation, and audit evidence.

Capability Coverage

| Capability | SINT Protocol | Microsoft AGT | MCP Baseline | SROS2 | |---|---|---|---|---| | Physical constraint enforcement (velocity, force, geofence) | βœ… In token | ❌ | ❌ | ❌ | | Tier-based human oversight (T0–T3) | βœ… 4-tier | ⚠️ Execution rings | ❌ | ❌ | | Append-only hash-chained audit | βœ… SHA-256 | ⚠️ Logging | ❌ | ❌ | | ROS 2 / MAVLink / industrial bridges | βœ… 12 bridges | ❌ Digital only | ❌ | ⚠️ ROS only | | Consumer smart home governance | βœ… Home Assistant + Matter | ❌ | ❌ | ❌ | | HIPAA + GDPR health data access | βœ… FHIR + HealthKit | ❌ | ❌ | ❌ | | OWASP ASI01–ASI10 coverage | βœ… 10/10 Full | βœ… 10/10 | ❌ | ❌ | | Economic routing + budgets | βœ… bridge-economy | ❌ | ❌ | ❌ | | Swarm collective constraints | βœ… SwarmCoordinator | ❌ | ❌ | ❌ | | E-stop / CircuitBreaker | βœ… EU AI Act Art. 14 | βœ… Kill switch | ❌ | ❌ | | Caregiver delegation + consent | βœ… FHIR Consent tokens | ❌ | ❌ | ❌ | | Differential privacy ledger | βœ… Per-query epsilon budget | ❌ | ❌ | ❌ |

SINT is designed for physical AI and regulated data workflows where actions can be irreversible: robots, drones, smart homes, health fabric, industrial control, and critical infrastructure. Microsoft AGT focuses on digital/software governance patterns; SINT focuses on pre-action enforcement across tool, robotics, and industrial execution boundaries.

The empirical case for SINT:

  • ROSClaw (IROS 2026): Up to 4.8Γ— spread in out-of-policy LLM action proposals across frontier models under identical safety envelopes. The 3.4Γ— divergence between frontier backends is measurable, reproducible, and persistent.
  • MCP security (arXiv:2601.17549): 10 documented real-world MCP breaches in under 8 months, including a CVSS 9.6 command injection affecting 437,000 downloads.
  • SROS2: Formally demonstrated to contain 4 critical vulnerabilities at ACM CCS 2022, including access-control bypasses permitting arbitrary command injection.
  • Unitree BLE worm (September 2025): Hardcoded crypto keys enabled wormable BLE/Wi-Fi command injection across robot fleets β€” precisely the scenario SINT's per-agent token scoping and real-time revocation prevent.

Core guarantees:

  • No agent action ever bypasses the Policy Gateway (invariant I-G1: No Bypass)
  • Every decision is recorded in a tamper-evident SHA-256 hash-chained ledger (invariant I-G3: Ledger Primacy)
  • Physical constraints (velocity, force, geofence) are enforced at the protocol level β€” in the token, not in config
  • Tier-gated verifiable compute hooks support provable-execution evidence on critical actions
  • E-stop is universal across all non-terminal DFA states (invariant I-G2: E-stop Universality)
  • Per-agent capability tokens with real-time revocation

Quick Start

# Prerequisites: Node.js >= 22, pnpm >= 9
pnpm install
pnpm run build
pnpm run test        # full workspace test suite

Start the Gateway Server

pnpm --filter @sint/gateway-server dev
# β†’ http://localhost:3100/v1/health
# β†’ http://localhost:3100/v1/ready
# β†’ http://localhost:3100/v1/docs

Start Production-Like Stacks (One Command)

pnpm run stack:dev
pnpm run stack:edge
pnpm run stack:prod-lite
pnpm run stack:gazebo-validation
pnpm run stack:isaac-sim-validation

Compose profiles:

Developer Docs Site (docs.sint.gg)

pnpm run docs:dev
pnpm run docs:build
pnpm run docs:preview

Docs source lives in docs/, VitePress config is in docs/.vitepress/config.mts, and deployment is handled by docs-site.yml.

Deploy note:

  • branch builds validate docs locally and in CI
  • public docs.sint.gg deployment publishes from main under GitHub Pages environment rules

Community/adoption assets:

Run a Single Package

pnpm --filter @sint/gate-policy-gateway test
pnpm --filter @sint/bridge-mcp test

Consumer Domains: Smart Home & Health

SINT extends far beyond industrial robotics. Two major consumer domains now have governance frameworks:

Consumer Smart Home (Home Assistant + Matter)

AI agents accessing your smart home go through the Policy Gateway:

import { HAInterceptor } from "@sint/bridge-homeassistant";

const interceptor = new HAInterceptor({
  policyGateway,
  homeAssistantHost: "homeassistant.local",
});

// Claude says: "unlock the front door"
const result = await interceptor.intercept({
  toolName: "call_service",
  toolInput: { domain: "lock", service: "unlock", entity_id: "lock.front_door" },
});
// β†’ Escalates to T2_ACT (requires human approval)
// β†’ Evidence Ledger records the decision and outcome

Tier-appropriate defaults:

  • T0 (OBSERVE): Security cameras, sensors (read-only, no facial recognition)
  • T1 (PREPARE): Lights, thermostats, media players (logged auto-allow)
  • T2 (ACT): Smart locks, garage doors, alarms (requires approval)
  • T3 (COMMIT): Create/modify automations (mandatory human review)

See packages/bridge-homeassistant and packages/bridge-matter.

Health Fabric (FHIR + HealthKit/Health Connect)

Patient data accessed by AI agents goes through consent-based governance:

import { createFHIRConsentToken } from "@sint/bridge-health";

// Patient grants AI agent 7-day read access to health observations
const consentToken = createFHIRConsentToken(
  "did:key:patient123",   // grantor (patient)
  "did:key:aiagent456",   // grantee (AI agent)
  ["Observation", "DiagnosticReport"],
  ["read"],
  new Date(Date.now() + 7 * 24 * 60 * 60 * 1000),
  { scope: "patient-privacy", purposeOfUse: ["TREAT"] }
);

await policyGateway.issueToken(consentToken);

Civil liberties guarantees:

  • On-device first: Raw sensor data (heart rate, blood pressure) stays on device; only aggregates egress
  • Differential privacy: Every query consumes an epsilon budget; exhausted budget = no more access
  • Caregiver delegation: Elderly parent grants adult child 30-day, revocable access to health data
  • HIPAA + GDPR: Consent tokens, user-owned keys, audit ledger export for patient access rights

See packages/bridge-health and the consumer smart home integration guide.

---

SINT Operator Interface

A voice-first, HUD-based control surface for SINT operators. Every command flows through the Policy Gateway.

pnpm run stack:interface  # starts gateway + interface + postgres + redis
# Opens: http://localhost:3202

Features:

  • Voice input: Web Speech API, zero external dependencies, real-time transcript
  • Command HUD: three-panel approvals, action stream, and context view
  • Operator memory: ledger-backed persistent context (@sint/memory)
  • Proactive notifications: sint__notify runs as T2 and requires confirmation
  • T2/T3 approvals: one-click approve/deny with timeout countdown

See docs/guides/sint-interface.md for full setup and usage.

For AI Agents

If you are an AI agent (Claude, GPT, Gemini, Cursor, etc.) working in this repo, read AGENTS.md first. It covers key invariants, common mistakes, and entry points for the most common tasks. For deeper implementation details, see CLAUDE.md.

Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  AI Agents / Foundation Models                               β”‚
β”‚  (Claude, GPT, Gemini, open-source)                         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                   β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  SINT Bridge Layer (L1)                                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚ bridge-mcp β”‚ β”‚ bridge-ros2β”‚ β”‚ bridge-a2a β”‚ β”‚ bridge-  β”‚  β”‚
β”‚  β”‚ MCP tools  β”‚ β”‚ ROS topics β”‚ β”‚ Google A2A β”‚ β”‚ open-rmf β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚ bridge-mqtt-sparkplugβ”‚ β”‚ bridge-opcua                  β”‚  β”‚
β”‚  β”‚ Industrial IoT       β”‚ β”‚ PLC / OT control plane bridge β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
│  Per-resource state: UNREGISTERED→PENDING_AUTH→AUTHORIZED    │
│  →ACTIVE→SUSPENDED (real-time revocation without restart)    │
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                   β”‚ SintRequest (UUIDv7, Ed25519, resource, action, physicalContext)
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  SINT Gate (L2) β€” THE choke point                           β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚  PolicyGateway.intercept()                              β”‚ β”‚
β”‚  β”‚  1. Schema validation (Zod)                             β”‚ β”‚
β”‚  β”‚  2. Token validation (Ed25519 + expiry + revocation)    β”‚ β”‚
β”‚  β”‚  3. Resource scope check                                β”‚ β”‚
β”‚  β”‚  4. Per-token rate limiting (sliding window)            β”‚ β”‚
β”‚  β”‚  5. Physical constraint enforcement                     β”‚ β”‚
β”‚  β”‚  6. Forbidden action sequence detection                 β”‚ β”‚
β”‚  β”‚  7. Tier assignment: max(BaseTier, Ξ”_human, Ξ”_trust...) β”‚ β”‚
β”‚  β”‚  8. T2/T3 β†’ escalate to approval queue                 β”‚ β”‚
β”‚  β”‚  9. T0/T1 + approved T2/T3 β†’ allow                     β”‚ β”‚
β”‚  β”‚  10. Bill via EconomyPlugin (if configured)             β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚                          ↓                                   β”‚
β”‚  EvidenceLedger (SHA-256 hash chain + ProofReceipt)        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

APS vs SINT Primitives

| APS Concept | SINT Implementation | |-------------|-------------------| | Principal | agentId (Ed25519 public key) + W3C DID identity | | Capability | SintCapabilityToken (Ed25519-signed, scoped, attenuatable) | | Authority | PolicyGateway.intercept() β€” single choke point | | Confinement | Per-token resource scope + physical constraints (velocity, force, geofence) | | Revocation | RevocationStore + ConsentPass endpoint (real-time) | | Audit | EvidenceLedger β€” append-only, SHA-256 hash-chained |

Packages

Gate (Security Core)

| Package | Description | Tests | |---------|-------------|-------| | @sint/core | Types, Zod schemas, tier constants, formal DFA states | β€” | | @sint/gate-capability-tokens | Ed25519 tokens, delegation, W3C DID identity | 55 | | @sint/gate-policy-gateway | Authorization engine: tiers, constraints, rate limiting, M-of-N quorum | 256 | | @sint/gate-evidence-ledger | SHA-256 hash-chained append-only audit log with pluggable attestation | 45 |

Bridges (15 bridges)

Industrial & Robotics (9)

| Package | Description | Tests | |---------|-------------|-------| | @sint/bridge-mcp | MCP tool call interception and risk classification | 66 | | @sint/bridge-ros2 | ROS 2 topic/service/action interception with physics extraction | 20 | | @sint/bridge-a2a | Google A2A Protocol bridge for multi-agent coordination | 38 | | @sint/bridge-iot | Generic MQTT/CoAP edge IoT bridge with gateway session interception | 21 | | @sint/bridge-mqtt-sparkplug | MQTT Sparkplug profile mapping with industrial command tiering defaults | 8 | | @sint/bridge-opcua | OPC UA node/method mapping with safety-critical write/call promotion | 6 | | @sint/bridge-open-rmf | Open-RMF fleet/facility mapping for warehouse dispatch workflows | 5 | | @sint/bridge-grpc | gRPC service/method profile mapping with default tier assignment | 5 | | @sint/bridge-mavlink | MAVLink drone/UAV command bridge | 15 |

Coordination & Economics (2)

| Package | Description | Tests | |---------|-------------|-------| | @sint/bridge-economy | Economy bridge: balance, budget, trust, billing ports | 47 | | @sint/bridge-swarm | Multi-robot swarm coordination bridge | 9 |

Consumer & Health (3) β€” Phase 1-5 Physical AI Governance

| Package | Description | Tests | |---------|-------------|-------| | @sint/bridge-homeassistant | Consumer smart home MCP interceptor with device profiles (locks, cameras, alarms, climate, vacuums) β€” Phase 1 | 36 | | @sint/bridge-health | FHIR R5 + HealthKit/Health Connect with differential privacy, consent tokens, and caregiver delegation β€” Phase 5 | β€” | | @sint/bridge-matter | Matter protocol bridge for unified smart home device governance β€” Phase 2 | β€” |

Note: some consumer/health bridges are currently in β€œprototype API” state. CI may temporarily skip their build/typecheck/test scripts until their public interfaces are aligned with the @sint/core request/decision model.

Reference Implementation (1)

| Package | Description | Tests | |---------|-------------|-------| | @sint/sint-pdp-interceptor | Reference SEP-1763 PDP adapter for MCP interceptor hosts backed by PolicyGateway.intercept() | 5 |

Engine (AI Execution Layer)

| Package | Description | Tests | |---------|-------------|-------| | @sint/engine-system1 | Neural perception: sensor fusion, ONNX inference, anomaly detection | 42 | | @sint/engine-system2 | Symbolic reasoning: behavior trees, task planning, System 1/2 arbitration | 86 | | @sint/engine-hal | Hardware Abstraction Layer: auto-detect hardware, select deployment profile | 26 | | @sint/engine-capsule-sandbox | WASM/TS capsule loading, validation, and sandboxed execution | 36 | | @sint/avatar | Avatar Layer (L5): behavioral identity profiles, CSML-driven tier escalation | 25 |

Reference Capsules

| Package | Description | Tests | |---------|-------------|-------| | @sint/capsule-navigation | Waypoint following navigation reference capsule | 11 | | @sint/capsule-inspection | Visual anomaly detection for manufacturing QA | 8 | | @sint/capsule-pick-and-place | Gripper control for pick-and-place tasks | 12 |

Persistence

| Package | Description | Tests | |---------|-------------|-------| | @sint/persistence | Storage interfaces + in-memory/PG/Redis implementations | 26 | | @sint/persistence-postgres | Production PostgreSQL adapters for ledger, revocation, and rate-limit durability | 14 |

Apps & SDKs

| Package | Description | Tests | |---------|-------------|-------| | @sint/gateway-server | Hono HTTP API with approvals, SSE streaming, A2A routes | β€” | | sint-mcp | Security-first multi-MCP proxy server | β€” | | @sint/interface | Voice HUD and Conductor approvals for operator review | 25 | | @sint/dashboard | Archived real-time approval dashboard with operator auth | 29 | | @sint/client | TypeScript SDK for the Gateway API (delegation, SSE) | β€” | | @sint/sdk | Zero-dependency public TypeScript SDK aligned to gateway v0.2 contracts | 9 | | @sint/conformance-tests | Security regression suite β€” all phases | β€” |

Total: 49 repo packages, apps, examples, and capsules Β· CI-backed full-suite and conformance coverage

Note: Run pnpm test to get the current exact passing test count.

Approval Tiers

Graduated authorization mapped to physical consequence severity:

| Tier | Name | DFA States | Auto-approved? | Example | |------|------|------------|---------------|---------| | T0 | OBSERVE | β†’ OBSERVING | Yes (logged) | Read sensor data, query database | | T1 | PREPARE | β†’ PREPARING | Yes (audited) | Write file, save waypoint, stage plan | | T2 | ACT | ESCALATING β†’ ACTING | Requires review | Move robot, operate gripper, publish /cmd_vel | | T3 | COMMIT | ESCALATING β†’ COMMITTING | Requires human + optional M-of-N | Execute trade, novel environment entry, irreversible action |

Tier escalation triggers (Ξ” factors):

  • Ξ”_human: Human presence sensor active in workspace β†’ +1 tier
  • Ξ”_trust: Agent trust score below threshold or recent failures β†’ +1 tier
  • Ξ”_env: Robot near physical boundary or unstructured environment β†’ +1 tier
  • Ξ”_novelty: Action outside validated distribution (novelty detector) β†’ +1 tier

Formal Specification

Request Lifecycle DFA

SINT models every request as a deterministic finite automaton with 12 states:

IDLE β†’ PENDING β†’ POLICY_EVAL β†’ PLANNING β†’ OBSERVING/PREPARING/ACTING β†’ COMMITTING β†’ COMPLETED
                     ↓                              ↓
                ESCALATING                      ROLLEDBACK  (estop, execution failure)
                     ↓
                  FAILED     (approval denied, timeout)

The ACTING state is only reachable via POLICY_EVAL with a valid token. Physical actuation is structurally impossible without a valid capability token.

Tier Assignment Function

Tier(r) = max(BaseTier(r), Ξ”_human(r), Ξ”_trust(r), Ξ”_env(r), Ξ”_novelty(r))

Formal Invariants

| Invariant | Description | |-----------|-------------| | I-T1 (Attenuation) | scope(child_token) βŠ† scope(parent_token) β€” delegation can only reduce permissions | | I-T2 (Unforgeability) | Capability tokens are Ed25519-signed; valid tokens are computationally unforgeable | | I-T3 (Physical Constraint Primacy) | Physical constraints (velocity, force, geofence) in a token cannot be weakened by any downstream layer | | I-G1 (No Bypass) | Physical actuation is only reachable from the ACTING DFA state, which is only reachable via POLICY_EVAL | | I-G2 (E-stop Universality) | The estop event transitions any non-terminal state to ROLLEDBACK unconditionally | | I-G3 (Ledger Primacy) | COMMITTING β†’ COMPLETED requires ledger_committed; no action completes without a ledger record |

Benchmark Results

PolicyGateway latency (measured on M3 MacBook Pro, pnpm run bench):

| Tier | p50 | p99 | |------|-----|-----| | T0 (OBSERVE) | ~1ms | ~3ms | | T1 (PREPARE) | ~1ms | ~3ms | | T2 (ACT) | ~1ms | ~3ms | | T3 (COMMIT) | ~1ms | ~3ms |

The gateway adds sub-3ms overhead at p99 for all tiers. Run benchmarks: pnpm run bench.

ROS2 control-loop target benchmark:

| Path | SLA Target | Command | |------|------------|---------| | ROS2 command path (/cmd_vel) | p99 < 10ms | pnpm run benchmark:ros2-loop |

Industrial benchmark artifacts:

Compliance mapping assets:

Key Concepts

Capability Tokens

Ed25519-signed capability tokens β€” the only authorization primitive. Unlike RBAC (ambient authority to principals), OCap requires explicit token presentation for every operation.

Token fields:

  • Resource scoping β€” what the agent can access (ros2:///cmd_vel, mcp://filesystem/, a2a://agents.example.com/)
  • Action restriction β€” what operations are allowed (publish, call, subscribe, a2a.send)
  • Physical constraints β€” max velocity (m/s), max force (N), geofence polygon, time window, rate limit
  • Verifiable compute requirements β€” optional proof type/verifier/freshness/public-input constraints for T2/T3 actions
  • Delegation chains β€” max 3 hops, attenuation only (invariant I-T1)
  • Revocation β€” instant invalidation via revocation store (ConsentPass endpoint)
  • W3C DID identity β€” did:key:z6Mk... format for agent portability

Evidence Ledger

Every policy decision is recorded in a SHA-256 hash-chained append-only log. Chain integrity: β„“_k.previousHash = SHA256(canonical(β„“_{k-1})). A gap or hash mismatch constitutes tamper evidence.

For portable verification across bridges and external tooling, SINT now routes receipt and tool-definition signing through a shared deterministic canonical JSON serializer instead of relying on insertion-order-sensitive JSON.stringify() behavior.

For strong-tier flows, SINT can emit a linked bilateral receipt pair: a gate receipt before execution is allowed to proceed and a completion receipt once execution settles. The pair shares a stable actionRef and linkageHash so auditors can verify both authorization and outcome as one governed action.

Retention policy:

| Tier | Retention | |------|-----------| | T0 (OBSERVE) | 30 days | | T1 (PREPARE) | 90 days | | T2 (ACT) | 180 days | | T3 (COMMIT) | 365 days (indefinite if legal hold) |

CSML: Composite Safety-Model Latency

A deployment metric that fuses behavioral and physical safety dimensions:

CSML(m, p, t) = Ξ±Β·AR_m + Ξ²Β·BP_m + Ξ³Β·SV_m - δ·CR_m + Ξ΅Β·πŸ™[ledger_intact(t)]

CSML above a deployment threshold ΞΈ automatically escalates all subsequent requests from that model backend to the next tier.

Compliance Mapping

IEC 62443 FR1–FR7

| FR | Title | SINT Mechanism | |----|-------|----------------| | FR1 | Identification & Authentication | SintCapabilityToken with Ed25519 agent identity; W3C DID portability | | FR2 | Use Control | Four-tier Approval Gate; maxRepetitions constraint; per-resource action allowlists | | FR3 | System Integrity | SHA-256 hash-chained Evidence Ledger; ProofReceipt for T2/T3 (TEE attestation planned) | | FR4 | Data Confidentiality | Zenoh TLS transport; capability scope prevents sensor access without explicit token | | FR5 | Restricted Data Flow | Policy Gateway allowlists; geofence constraint; SINT Bridge per-topic DFA | | FR6 | Timely Response | safety.estop.triggered event; E-stop universality invariant I-G2 | | FR7 | Resource Availability | Per-token rate limiting; maxRepetitions; budget enforcement in capsule sandbox |

EU AI Act Article 13

| Requirement | SINT Approach | |-------------|---------------| | Logging and traceability | SHA-256 hash-chained Evidence Ledger β€” tamper detection is cryptographic | | Human oversight | Dynamic Consent + T3 approval gate β€” T3 actions cannot execute without recorded human approval | | Risk management | Tier escalation based on real-time physical context (Ξ”_human, Ξ”_env, Ξ”_novelty) |

Tier Crosswalk (NIST AI RMF / ISO 42001 / EU AI Act)

| SINT Tier | NIST AI RMF | ISO/IEC 42001 | EU AI Act | |-----------|-------------|---------------|------------| | T0 Observe | MAP + MEASURE + MANAGE monitoring controls | Clause 9 + Clause 8 controls | Article 12 + Article 13 | | T1 Prepare | GOVERN + MANAGE controlled write path | Clause 8.1/8.2 operational risk treatment | Article 9 + Article 12 | | T2 Act | MANAGE risk response with accountable oversight | Clause 8 + Clause 6 operational controls | Article 14 + Article 15 | | T3 Commit | Highest-consequence GOVERN + MANAGE controls | Clause 8.3 + Clause 10 corrective governance | Article 14(4)(e) + Articles 9/12/15 |

Machine-readable crosswalk endpoint: GET /v1/compliance/tier-crosswalk

API Endpoints

| Method | Endpoint | Description | |--------|----------|-------------| | GET | /.well-known/sint.json | Public protocol discovery (version, bridges, profiles, schemas) | | GET | /v1/health | Health check | | POST | /v1/intercept | Evaluate a single request | | POST | /v1/intercept/batch | Evaluate multiple requests (207 Multi-Status) | | POST | /v1/tokens | Issue a capability token | | POST | /v1/tokens/delegate | Delegate (attenuate) a token | | POST | /v1/tokens/revoke | Revoke a token | | GET | /v1/ledger | Query audit ledger events | | GET | /v1/approvals/pending | List pending approval requests | | POST | /v1/approvals/:id/resolve | Approve or deny a request (M-of-N quorum) | | GET | /v1/approvals/events | SSE stream for real-time approval events | | GET | /v1/approvals/ws | WebSocket stream for low-latency approval events | | POST | /v1/a2a | JSON-RPC 2.0 A2A protocol endpoint | | GET | /v1/metrics | Prometheus metrics | | GET | /v1/openapi.json | OpenAPI surface for gateway integration | | GET | /v1/compliance/tier-crosswalk | SINT tier mapping to NIST AI RMF / ISO 42001 / EU AI Act controls | | POST | /v1/economy/route | Cost-aware route selection with optional x402 pay-per-call quotes |

Development Phases

SINT Protocol Core (6 phases complete)

| Phase | Description | Tests | |-------|-------------|-------| | Phase 1 (complete) | Security Wedge β€” capability tokens, PolicyGateway, EvidenceLedger | 425 | | Phase 2 (complete) | Engine Core β€” bridge-mcp, bridge-ros2, engine packages, persistence, gateway-server | +221 (646) | | Phase 3 (complete) | Economy Bridge β€” @sint/bridge-economy with port/adapter pattern, EconomyPlugin | +91 (737) | | Phase 4 (complete) | Standards Alignment β€” A2A bridge, rate limiting, M-of-N quorum, W3C DID identity | +78 | | Phase 5 (complete) | Protocol Surface v0.2 β€” discovery/OpenAPI/schema endpoints, industrial profiles | shipped | | Phase 6 (complete) | Engine layer β€” System1/2 engines, HAL, capsule sandbox, Avatar/CSML, reference capsules | shipped |

Physical AI Governance Roadmap 2026–2029 (Phases 1–5 in progress)

Extending SINT to consumer, health, and critical infrastructure domains:

| Phase | Focus | Status | Examples | |-------|-------|--------|----------| | Phase 1 | Consumer Smart Home (Q2–Q3 2026) | βœ… Complete | bridge-homeassistant β€” Home Assistant MCP interceptor with 12 device classes (locks, cameras, alarms, climate, robot vacuums). Tier-appropriate defaults: locks/alarmsβ†’T2, lights/climateβ†’T1, camerasβ†’T0. | | Phase 2 | Matter Protocol Unification (Q3–Q4 2026) | βœ… Complete | bridge-matter β€” Unified smart home governance across Matter-certified devices. Device discovery, service profiles, and tier assignment. | | Phase 3 | Occupancy & Human Presence (2027) | πŸ“‹ Planned | Ξ”_human plugin: escalate robot vacuums to T2 when occupancy detected. Build on Phase 1 sensor fusion. | | Phase 4 | Critical Infrastructure (2027–2028) | πŸ“‹ Planned | Power grids, water systems, industrial facilities. Formalized risk models and emergency-mode escalation. | | Phase 5 | Health Fabric & Wellbeing (Q4 2026–Q1 2027) | βœ… Complete | bridge-health β€” FHIR R5 consent governance, HealthKit/Health Connect on-device processing, differential privacy ledger, and caregiver delegation tokens. HIPAA + GDPR alignment. |

See docs/roadmaps/PHYSICAL_AI_GOVERNANCE_2026-2029.md for full roadmap.

Deployment

Railway (Recommended)

brew install railway
railway login
./scripts/railway-setup.sh
railway variables --set SINT_STORE=postgres SINT_CACHE=redis SINT_API_KEY=$(openssl rand -hex 32)
railway up

Docker Compose

docker-compose up
# Gateway:   http://localhost:3100
# Dashboard: http://localhost:3201
# Postgres:  localhost:5432
# Redis:     localhost:6379

Tech Stack

  • Runtime: Node.js 22+
  • Language: TypeScript 5.7 (strict mode)
  • Monorepo: pnpm workspaces + Turborepo
  • HTTP: Hono
  • Validation: Zod
  • Crypto: @noble/ed25519, @noble/hashes (audited, zero-dependency)
  • MCP SDK: @modelcontextprotocol/sdk
  • Dashboard: React 19, Vite 6
  • Testing: Vitest (run pnpm test for current count)
  • Infra: Docker, PostgreSQL 16+, Redis 7, GitHub Actions CI, Railway

Docs & Artifacts

Physical AI Governance (Consumer, Health, Critical Infrastructure)

Design Principles

  1. Single choke point β€” Every agent action flows through PolicyGateway.intercept(); no bridge adapter makes authorization decisions independently
  2. Result\<T, E\> over exceptions β€” All fallible operations return discriminated unions, never throw
  3. Attenuation only β€” Delegated tokens can only reduce permissions, never escalate (I-T1)
  4. Append-only audit β€” The evidence ledger is INSERT-only with SHA-256 hash chain integrity (I-G3)
  5. Physical safety first β€” Velocity, force, and geofence constraints live in the token, not in external config
  6. Interface-first persistence β€” Storage adapters implement clean interfaces; swap in-memory for Postgres/Redis
  7. Fail-open on infrastructure β€” Economy/rate-limit infrastructure failures do not block the safety path
  8. E-stop universality β€” The hardware E-stop bypasses all token checks and is unconditional (I-G2)

References

  • ROSClaw: Empirical safety analysis of LLM-controlled physical AI β€” arXiv:2603.26997 (IROS 2026)
  • MCP Security Analysis: Architectural vulnerabilities in the Model Context Protocol β€” arXiv:2601.17549
  • IEC 62443: Industrial automation and control systems cybersecurity standard
  • EU AI Act Article 13: Transparency requirements for AI systems
  • NIST AI RMF: AI Risk Management Framework
  • W3C DID Core: Decentralized Identifiers specification

Roadmap

The active execution pages are:

The current emphasis is straightforward:

  • production-ready gateway behavior
  • release and evidence discipline
  • collaborator-facing integration artifacts
  • stronger external adoption and maintainership signals

License

Apache-2.0

See related servers & alternatives β†’

Related MCP servers

Browse all β†’

Related guides

Hand-picked reading to help you choose and use Other servers.