Motivation
ToolHive already has Cedar authorization and validating webhooks. A useful integration would show how to combine them when the final tools/call arguments need a stateful, typed decision: Cedar still handles principal/resource grants, while an optional Semaprax decision service evaluates a narrow operation such as transfer(amount, destination) against task state before the MCP server sees it.
Proposal
Add a small example configuration and test using ToolHive's existing validating-webhook middleware. The example should send the post-mutation MCP request to the external Semaprax adapter, map allow/deny to ToolHive's webhook response, and fail closed when the decision service is unavailable. It should explicitly identify which identity fields came from ToolHive authentication and which fields are client-supplied. No replacement of Cedar or default dependency is proposed.
Acceptance
An allowed call reaches the upstream tool once. A denied or malformed call never reaches it, with a clear audit outcome. The test should include a mutating webhook so the policy evaluates the bytes actually dispatched; #6133 explains why that ordering matters.
ToolHive middleware: https://github.com/stacklok/toolhive/blob/main/docs/arch/02-core-concepts.md
Semaprax: https://github.com/wavect/semaprax
Motivation
ToolHive already has Cedar authorization and validating webhooks. A useful integration would show how to combine them when the final
tools/callarguments need a stateful, typed decision: Cedar still handles principal/resource grants, while an optional Semaprax decision service evaluates a narrow operation such astransfer(amount, destination)against task state before the MCP server sees it.Proposal
Add a small example configuration and test using ToolHive's existing validating-webhook middleware. The example should send the post-mutation MCP request to the external Semaprax adapter, map allow/deny to ToolHive's webhook response, and fail closed when the decision service is unavailable. It should explicitly identify which identity fields came from ToolHive authentication and which fields are client-supplied. No replacement of Cedar or default dependency is proposed.
Acceptance
An allowed call reaches the upstream tool once. A denied or malformed call never reaches it, with a clear audit outcome. The test should include a mutating webhook so the policy evaluates the bytes actually dispatched; #6133 explains why that ordering matters.
ToolHive middleware: https://github.com/stacklok/toolhive/blob/main/docs/arch/02-core-concepts.md
Semaprax: https://github.com/wavect/semaprax