VerblLayer
An open-source MCP server that turns real business workflows into reviewed, agent-callable commands, enabling safe execution through REST and MCP.
README
Callable
Turn real business workflows into reviewed, agent-callable commands.
Callable is an open-source, self-hosted command layer for existing business software. It accepts real workflow evidence, helps an operator turn that evidence into a reviewed command contract, and exposes the command to AI agents through REST and MCP. Every execution, approval, drift check, and audit event is persisted.
It is not a chatbot, generic knowledge base, RPA clone, or simulated demo.
Why it exists
Agents need a safe way to act in business software. Raw APIs are often too low-level; opaque automation is too hard to review. Callable sits between them: it makes a workflow explicit, validates inputs, enforces approvals, calls a real target, and retains the evidence needed to understand what happened.
How it works
flowchart LR
Evidence["Real workflow evidence"] --> Review["Review candidate and command contract"]
Review --> Gateway["REST or MCP agent call"]
Gateway --> Execute["Real Acme or Zendesk API execution"]
Execute --> Records["Execution, approval, audit, and drift records"]
- Register a real target application.
- Upload SOPs, CSV exports, traces, or process text.
- Discover workflow candidates with a configured model provider.
- Review a candidate, define the API route and method, then publish a command version.
- Let an agent call the command through REST or MCP.
- Inspect persisted executions, approvals, audits, and route-level drift checks.
What is supported today
| Capability | Status | Boundary |
|---|---|---|
| Controlled Acme Support Admin | Implemented | Real PostgreSQL state and refund execution; fresh Docker-backed release proof is still required in this checkout. |
| Zendesk ticket update | Implemented | PUT /api/v2/tickets/{ticket_id}.json; only server environment-variable names are stored. Live credential proof is pending. |
| Workflow discovery | Available when configured | Uses OpenAI, Anthropic, or OpenRouter. Missing credentials return an unavailable state. |
| REST, MCP, and OpenAPI | Implemented | API-key scoped, persisted agent access. |
| Approvals, command versions, audit, and drift | Implemented | Commands are reviewed, versioned, and safety-paused after repeated real failures. |
| Other SaaS execution targets | Unavailable | Callable does not imply connector support that has not been built and verified. |
See docs/CAPABILITIES.md for the complete capability ledger.
Quick start
Prerequisites
- Node.js 20
- pnpm 10
- Docker Desktop with virtualization enabled
pnpm install
Copy-Item .env.example .env
pnpm db:up
pnpm prisma:migrate:deploy
pnpm prisma:seed
pnpm dev
Open http://localhost:3100. Local development uses the persisted seeded operator only when DEV_AUTH_ENABLED=true.
To prove the complete local path:
pnpm verify
Production deployment
Build and run the production server with pnpm build and pnpm start. Do not expose local development authentication publicly.
Production requires a trusted identity proxy and these environment settings:
AUTH_MODE=trusted_proxy
DEV_AUTH_ENABLED=false
TRUSTED_AUTH_PROXY_SECRET=<32+ character secret>
The proxy must remove every client-provided x-callable-* header, authenticate the request, then inject:
x-callable-auth-secret
x-callable-org
x-callable-email
Callable checks the shared secret, resolves the email and organisation to an existing user, and uses only the persisted role for authorisation. Keep API keys, provider keys, Zendesk credentials, and database credentials server-side. Put a rate-limiting reverse proxy or equivalent edge layer in front of a public deployment.
Agent access
Create a scoped API key at /mcp-api, then inspect the real command inventory before calling anything:
$headers = @{ Authorization = "Bearer <api_key>"; "Content-Type" = "application/json" }
Invoke-WebRequest -Method Post -Uri "http://localhost:3100/api/mcp" -Headers $headers -Body '{"tool":"list_commands","args":{}}'
Invoke-WebRequest -Method Get -Uri "http://localhost:3100/api/v1/openapi"
Use the returned input schema and command name for any subsequent call. Callable does not provide a fabricated example command.
Safety model
- Commands require explicit API routes and reviewed HTTP methods before publication.
- Inputs are validated server-side; high-risk amount thresholds can require persisted approval.
- Every publish creates an immutable command version.
- Executions carry real results or real errors. Dry runs do not call the target.
- Three consecutive non-dry-run failures pause a published command and create an audit event.
- Drift checks validate route reachability against the command's registered target.
Current limits
- No hosted login, SSO/SCIM, user provisioning, or generic connector framework.
- Zendesk supports ticket updates only; OAuth and browser execution are out of scope.
- Drift checks are route-level, not semantic contract validation.
- The in-process limiter is suitable for a single instance; use an edge gateway for multi-instance rate limiting.
Contributing and security
Read CONTRIBUTING.md, CODE_OF_CONDUCT.md, SUPPORT.md, and SECURITY.md before participating. Contributions must preserve the real, reviewable command path—no mock execution, discovery, audit, metric, or drift behaviour.
Release status
This public repository is preparing for its first v0.1.0-beta release. Before tagging it, maintainers must apply and verify migrations on a fresh database, confirm remote CI, and complete live Zendesk sandbox proof or retain its pending-verification label.
License
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。