Authentication answers who is calling. Authorization answers the harder runtime question an autonomous agent faces before every consequential action: is this specific action allowed, right now, given what it touches and where the data goes? The Model Context Protocol (MCP) standardises connection and authentication, but deliberately leaves runtime authorization — should an authenticated tool call be permitted to execute — to you.
Instead of asking a model to judge free text, you describe the attempted action as a typed security context (subject, action, target, tool requested-vs-granted scopes, data classes + egress destination, provenance). A deterministic checker evaluates it against a pinned ruleset and returns PASS / REVIEW / BLOCK / SKIP with machine reason codes (e.g. EGRESS_SECRET_UNTRUSTED, UNVERIFIED_GRANT) and the conflict rule that fired. No LLM in the scoring path, so the same input always yields the same verdict. Every response embeds input_snapshot_hash (SHA-256 over the canonical request) and commit_sha so the decision is replayable byte-for-byte, offline, later. Timeouts and transport errors surface as SKIP — fail closed.
curl -X POST https://web-production-3df26.up.railway.app/sandbox/keys # → sk_sandbox_… + 1000 credits
curl -X POST https://web-production-3df26.up.railway.app/tsc/validate \
-H "X-API-Key: sk_sandbox_…" -H "Content-Type: application/json" \
-d '{"action":{"type":"tool.call","name":"http.post"},"target":{"url":"https://unknown-collector.example","data_classes":["secret"]}}'
# → { "decision": "BLOCK", "reason_codes": ["EGRESS_SECRET_UNTRUSTED"], "input_snapshot_hash": "sha256:…", "commit_sha": "…" }
Quesen is a portable decision + authority + evidence layer: it decides what an agent may do after authentication and interoperates with identity (Okta/Auth0/OIDC), MCP, payment rails (x402/AP2/UCP) and execution frameworks — it does not replace them. See the Quesen overview, try it free, and verify the evidence.
pip install quesen-sdk # Python
npm i quesen-sdk # JavaScript / TypeScript
pip install quesen-langchain # LangChain
pip install quesen-crewai # CrewAI
pip install quesen-autogen # AutoGen
Free sandbox key (no signup, no card): curl -X POST https://web-production-3df26.up.railway.app/sandbox/keys