Check a price change, order, refund or return against your commerce policy before an agent acts. Never writes to a marketplace.
This repository is the dedicated MIT-licensed source for the Decionis CommerceGate Claude Desktop extension. The extension runs locally over STDIO. It evaluates explicitly submitted commerce actions and reads signed evidence through the Decionis API; it contains no marketplace or ERP write client.
Shadow Mode evaluation only. CommerceGate never accepts, ships, cancels, refunds, reprices or changes stock on Walmart, Shopify, Adobe Commerce or Business Central; your tools act on the verdict.
commercegate_evaluate_action records a Shadow Mode policy evaluation but never executes the proposed action. commercegate_validate_erp_transaction returns an enforced policy and agent-budget decision for the complete submitted Dynamics 365 transaction but performs no ERP write. PROCEED or ALLOW is a policy result, not consent. Stop on HOLD, BLOCK, ESCALATE, errors, or ambiguous results.
Refund, oversell, and other connector execution paths are separate. Execution is available only when the specific marketplace exposes the required API, the merchant grants the required scope, and a connector implements and enables that path.
commercegate_describe_capabilities— inspect coverage, boundaries, and connection state without credentials.commercegate_evaluate_action— evaluate a price, stock, order, fulfillment, promotion, refund, or return proposal in Shadow Mode.commercegate_validate_erp_transaction— validate one complete Dynamics 365 Business Central transaction against policy and the agent budget.commercegate_get_dossier— read the signed Decision Dossier for a decision.commercegate_get_proof_packet— read a dossier proof packet.commercegate_list_shadow_reports— list recent Shadow Mode evaluations.commercegate_summarize_shadow_reports— summarize Shadow Mode outcomes and near misses.
The extension can start without credentials for capability discovery. Authenticated tools read configuration only from the extension environment:
| Variable | Secret | Purpose |
|---|---|---|
DECIONIS_API_KEY |
Yes | Authenticates policy and evidence calls. |
DECIONIS_ORG_ID |
No | Binds Protocol calls to one organization. |
DECIONIS_API_BASE |
No | Optional API origin; defaults to https://api.decionis.com. |
Never put credentials in tool arguments, source control, prompts, logs, fixtures, or screenshots.
Requirements: Node.js 20 or later and pnpm 9.15.3.
pnpm install --frozen-lockfile --ignore-scripts
pnpm verifypnpm verify formats, lints, type-checks, tests, builds, then uses the pinned @anthropic-ai/mcpb 2.1.2 CLI to validate, pack, unpack, byte-compare, and smoke-test the extension over JSON-RPC. Temporary bundles are deleted after validation. The GitHub Actions matrix repeats this process on macOS and Windows.
To create the same clean, verified bundle under artifacts/:
pnpm mcpb:packCommerceGate runs on your machine and talks to one service: the Decionis API at https://api.decionis.com (or the origin configured in DECIONIS_API_BASE). It has no telemetry, analytics, crash reporting, or other network destination. The full Decionis privacy policy is at https://decionis.com/privacy; this section describes this extension specifically.
What it collects. Nothing on its own. It sends only the facts supplied in a tool call: commerce facts being checked, an actor identifier, platform, idempotency key, dossier UUID for evidence reads, and report window for Shadow reports. It never reads files, browser data, the clipboard, or unrelated machine data.
Where it goes and why. Tool inputs go over HTTPS to the Decionis API for policy evaluation or to read evidence owned by the configured organization. Credentials come from the extension environment and are never written to disk or returned in tool results.
What is stored and retention. Decionis stores policy evaluations as signed Decision Dossiers in the organization's workspace. Retention follows the customer's Decionis plan and the Decionis privacy policy. The local extension stores no cache, log file, analytics record, or database.
Third parties. None. The extension contacts no third-party service. Claude Desktop may retain tool-call history under Anthropic's own policy.
Personal data. Commerce facts can include order identifiers and customer-related amounts if supplied. Submit only the bounded facts needed for the policy check.
Your controls. Remove DECIONIS_API_KEY and DECIONIS_ORG_ID to leave only unauthenticated capability discovery, or uninstall the extension to stop processing. For access, correction, deletion, or privacy questions, email commerce@decionis.com. Security reports go to security@decionis.com.
- Product documentation: https://commerce.decionis.com/mcp
- Support: https://decionis.com/contact
- Source: https://github.com/decionis/commercegate-claude-extension
- License: MIT