AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Openbouncer

mcp-openbouncer-openbouncer · by OpenBouncer

A reverse-captcha gateway and public registry for the agentic web. Cloudflare for agents — let verified agents in, politely deny humans.

No reviews yet
0 installs
20 views
0.0% view→install

Install

$ agentstack add mcp-openbouncer-openbouncer

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-openbouncer-openbouncer)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Openbouncer? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

OpenBouncer

A reverse-captcha gateway for the agentic web.

[](https://www.npmjs.com/package/@openbouncer/gate) [](./LICENSE) [](https://openbouncer.com) [](https://pump.fun/coin/4QyAdfEMBmPgMqtVy1gd6NthGsHzMctobUVEJqpwpump)

Cloudflare protects sites from bots. OpenBouncer protects agent-only spaces from humans — and routes verified agents to the sites that want them.


What it is

OpenBouncer is two things in one shape:

  1. A verification gateway that sits in front of endpoints which only

software should be calling. It exposes a single POST /api/verify that evaluates a layered set of proofs and returns pass or deny in under 40 ms.

  1. A public registry that agents query as a discovery layer. Sites

adopting OpenBouncer publish a .well-known/openbouncer.json document; agents read it to learn how to enter.

Why? The agentic web (MCP, Computer Use, Operator, Gemini Agents) is shipping fast but there is no standard layer for "this is an agent talking, not a human." OpenBouncer plays the same network-effect game as Cloudflare did for bot defense — flipped.

The layered protocol

L1   prompt-following challenge   — agent extracted the page's hidden nonce
L2   sub-200 ms latency window    — request arrived faster than humans can
L3   parallel reasoning proof     — sub-second multi-task challenge (v0.2)
L4   provider attestation         — signed token from a recognized runtime
                                    (Anthropic, OpenAI, Google)

A request that matches any layer passes. The marketing site demo ships L1 and L4; L2/L3 land with the v0.2 spec.

Try it from a terminal

The public-preview gateway accepts a static demo nonce so anyone can curl-test the flow.

# pass — agent payload
curl -X POST https://openbouncer.com/api/verify \
  -H 'Content-Type: application/json' \
  -H 'X-Agent-Provider: anthropic' \
  -d '{"nonce":"ob_demo_a8f3c9e2","attest":""}'

# deny — browser-style bare click
curl -X POST https://openbouncer.com/api/verify \
  -H 'Content-Type: application/json' \
  -d '{}'

Discovery:

curl https://openbouncer.com/.well-known/openbouncer.json

Fresh per-session nonce for real integrations:

curl https://openbouncer.com/api/challenge

Embed the gate on your site

bun add @openbouncer/gate@preview
# or: npm install @openbouncer/gate@preview
import { OpenBouncerGate } from '@openbouncer/gate'

export default function ProtectedPage({ nonce }: { nonce: string }) {
  return (
    
      {/* rendered only for verified agents */}
      
    
  )
}

Three lines. Headless: zero CSS dependency, inline-styled defaults, ESM + CJS + .d.ts, ~24 KB unpacked. See [packages/gate/README.md](./packages/gate/README.md) for the full API reference.

For non-React runtimes (Bun, Node, Workers, CLIs), import the pure async primitive:

import { verify } from '@openbouncer/gate'

const r = await verify({
  nonce: 'ob_demo_a8f3c9e2',
  provider: 'anthropic',
  attest: '',
})
// → { ok: true, decision: "pass", matched_layers: [1,4], token: "ob_..." }

Repo layout

.
├── server/                       Fetch-API style handlers (Bun + Vite plugin)
│   ├── index.ts                  standalone Bun server (production)
│   └── lib/
│       ├── decision.ts           layered evaluation (L1, L2, L3, L4)
│       ├── verify.ts             POST /api/verify
│       ├── challenge.ts          GET  /api/challenge
│       ├── well-known.ts         GET  /.well-known/openbouncer.json
│       ├── router.ts             tiny shared route table
│       ├── rate-limit.ts         in-memory per-IP token bucket
│       ├── token.ts              opaque pass-token envelope (v0.1)
│       └── json.ts               cors + security-header helper
├── src/
│   ├── components/
│   │   ├── OpenBouncerGate.tsx   the widget — both 3rd-party gate + demo
│   │   ├── Hero.tsx              + the rest of the marketing site
│   │   └── ...
│   ├── App.tsx
│   └── index.css
├── vite-plugin-openbouncer.ts    dev plugin wiring the same handlers
├── vite.config.ts
└── package.json

Development

bun install
bun run dev               # vite + api on the same origin (http://localhost:5173)
bun run server            # bun-serve the api standalone (defaults to :3001)
bun run typecheck         # tsc -b
bun run build             # vite build

Deploy

OpenBouncer ships as a single Cloudflare Pages project: the Vite-built static site under dist/ plus a functions/[[path]].ts catchall that runs the same Fetch-API handlers used in dev and in the standalone Bun server. One origin, no CORS dance, edge-deployed globally.

bunx wrangler login                  # one-time, opens browser
bun run deploy                       # bun run build + wrangler pages deploy

bun run deploy is sugar for:

wrangler pages deploy dist --project-name=openbouncer

To bind the custom domain (after the first deploy creates the project):

bunx wrangler pages domain add openbouncer.com --project-name=openbouncer

Cloudflare provisions the SSL cert automatically once DNS is verified. Subsequent deploys push to the same project — set up the GitHub integration in the Cloudflare Pages dashboard for auto-deploy on push to main.

Status (v0.1.draft)

| Surface | State | | --- | --- | | Reverse-captcha widget | ✅ live on openbouncer.com | | /api/verify (L1 + L4 stub) | ✅ live | | /api/challenge (fresh nonce) | ✅ live | | /.well-known/openbouncer.json | ✅ live | | @openbouncer/gate npm package | ✅ published (preview tag) | | Per-session nonce store | ⏳ v0.2 | | Ed25519-signed pass tokens | ⏳ v0.2 | | Real provider-attestation verification | ⏳ v0.2 | | Stable @openbouncer/gate on the latest tag | ⏳ v0.2 | | Public registry UI | ⏳ v0.2 | | MCP server for agent discovery | ⏳ v0.2 |

License

[MIT](./LICENSE).

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.