Preloop

by preloop

334 downloads Not rated yet
GitHub

About

Preloop is the MCP Governance Layer. Add approval gates to AI tool calls. Intercept risky actions, collect human decisions, and keep an audit trail.

Explore

| Variable | Default | Description |
|----------|---------|-------------|
| REGISTRATION_ENABLED | true | Enable self-registration. Set to false to disable public signups and require admin invitation. |

Preloop Enterprise Edition extends the open-source core with additional features for teams and organizations:

| Feature | Open Source | Enterprise |
|---------|:-----------:|:----------:|
| MCP Server with 6 built-in tools | ✅ | ✅ |
| Basic approval workflows | ✅ | ✅ |
| Email notifications | ✅ | ✅ |
| Mobile app notifications (iOS/Watch; Android) | ✅ | ✅ |
| Issue tracker integration | ✅ | ✅ |
| Vector search & duplicate detection | ✅ | ✅ |
| Agentic flows | ✅ | ✅ |
| Web UI | ✅ | ✅ |
| Role-Based Access Control (RBAC) | ❌ | ✅ |
| Team management | ❌ | ✅ |
| CEL conditional approval policies | ❌ | ✅ |
| Team-based approvals with quorum | ❌ | ✅ |
| Approval escalation | ❌ | ✅ |
| Slack notifications | ❌ | ✅ |
| Mattermost notifications | ❌ | ✅ |
| Admin dashboard | ❌ | ✅ |
| Audit logging & impersonation tracking | ❌ | ✅ |
| Billing & subscription management | ❌ | ✅ |
| Priority support | ❌ | ✅ |

Contact [email protected] for Enterprise Edition licensing.

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Preloop
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

- Python 3.11+
- PostgreSQL 14+
- PGVector extension for PostgreSQL (for vector search capabilities)


python -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate

pip install -e ".[dev]"

cp .env.example .env

Preloop is configured via environment variables. Copy .env.example to .env and customize as needed.

REGISTRATION_ENABLED=false

When registration is disabled:
- The "Sign Up" button is hidden from the UI
- The /register page redirects to /login
- The /api/v1/auth/register API endpoint returns 403 Forbidden - preventing direct API registration attempts
- New users must be invited by an administrator

Security Note: With REGISTRATION_ENABLED=false, the backend API enforces the restriction at the endpoint level. Any attempt to register via the API (including scripts or direct HTTP requests) will be rejected with a 403 status code.

To invite users when registration is disabled, use the admin API or CLI (Enterprise Edition includes a full admin dashboard for user management).


Preloop can be deployed to Kubernetes using the provided Helm chart:

bash

helm install preloop ./helm/preloop

helm install preloop ./helm/preloop --values custom-values.yaml


For more details about the Helm chart, see the chart README.

results = requests.get(
f"{base_url}/issues/search",
headers=headers,
params={
"organization": "spacecode",
"project": "astrobot",
"query": "authentication problems",
"limit": 5
}
)
print(json.dumps(results.json(), indent=2))

- POST /api/v1/auth/token - Get authentication token
- POST /api/v1/auth/refresh - Refresh authentication token

- GET /api/v1/tool-configurations - List tool configurations
- POST /api/v1/tool-configurations - Create tool configuration
- PUT /api/v1/tool-configurations/{id} - Update tool configuration
- DELETE /api/v1/tool-configurations/{id} - Delete tool configuration

PUSH_PROXY_URL=https://preloop.ai/api/v1/push/proxy
PUSH_PROXY_API_KEY=your-api-key-here

4. Enable push notifications in the Notification Preferences page in your Preloop Console
5. Register your mobile device by scanning the QR code shown in Notification Preferences

Once configured, approval requests will trigger push notifications on your registered iOS or Android devices.

> Note: The mobile apps (iOS/Watch and Android) are designed to work with self-hosted Preloop instances. They connect to your server URL extracted from the QR code.

To run all tests:

```bash

preloop

This is the name you will use to refer to the server (e.g., `@preloop get_issue ...`).

- GET /api/v1/tool-configurations - List tool configurations
- POST /api/v1/tool-configurations - Create tool configuration
- PUT /api/v1/tool-configurations/{id} - Update tool configuration
- DELETE /api/v1/tool-configurations/{id} - Delete tool configuration

The Preloop API now includes integrated MCP tool endpoints with dynamic tool filtering, allowing any HTTP-based MCP client to connect directly. This is the recommended way to automate issue management workflows.

Authentication: All MCP endpoints use the same Bearer Token authentication as the rest of the API.

Dynamic Tool Visibility: MCP tools are only visible when your account has one or more trackers configured. This ensures tools have the necessary context to operate effectively. If you connect with an account that has no trackers, you will see an empty tool list.

Connecting with Claude Code:

You can connect Claude Code directly to your Preloop instance using the claude mcp add command.

1. Get your Preloop API Key: You can find or create an API key in your Preloop user settings.
2. Add the MCP Server: Run the following command, replacing YOUR_PRELOOP_URL and YOUR_API_KEY with your details.

    claude mcp add \
      --transport http \
      --header "Authorization: Bearer YOUR_API_KEY" \
      preloop \
      https://YOUR_PRELOOP_URL/mcp/v1
    

- --transport http: Specifies that the server uses the HTTP transport.
- --header "Authorization: Bearer YOUR_API_KEY": Provides the necessary authentication header for all requests.
- preloop: This is the name you will use to refer to the server (e.g., @preloop get_issue ...).
- https://YOUR_PRELOOP_URL/mcp/v1: This is the base URL for the Preloop MCP endpoints.

Example Workflow (using curl):

If you are not using an MCP client and want to interact with the tool endpoints directly, you can use any HTTP client like curl.

1. Create an Issue:

    curl -X POST "https://YOUR_PRELOOP_URL/api/v1/mcp/create_issue" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"project": "your-org/your-project",
"title": "New Feature Request",
"description": "Add a dark mode to the dashboard."
}'

Preloop provides approval workflows for tool execution. Control which operations require approval before execution.

Key Concepts:
- Tool Configuration: Enable/disable tools and assign approval policies
- Approval Policies: Define approval requirements, approvers, timeouts, and notification channels
- Email Notifications: Receive approval requests via email with one-click approve/decline

Example: Create an Approval Policy

curl -X POST "https://YOUR_PRELOOP_URL/api/v1/approval-policies" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "name": "Critical Operations",
  "description": "Require approval for critical issue operations",
  "is_default": false,
  "approver_user_ids": ["user-id-1", "user-id-2"],
  "approvals_required": 1,
  "timeout_seconds": 600,
  "notification_channels": ["email"]
}'

Configure a tool to require approval:

curl -X POST "https://YOUR_PRELOOP_URL/api/v1/tool-configurations" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
  "tool_name": "update_issue",
  "tool_source": "preloop_builtin",
  "is_enabled": true,
  "approval_policy_id": "<policy_id_from_above>"
}'

> Enterprise Features: Preloop Enterprise Edition adds CEL-based conditional approvals, team-based approvals with quorum, escalation policies, and multi-channel notifications (Slack, Mattermost, mobile push). Contact [email protected] for more information.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "preloop": {
            "preloop": {
                "url": "https://preloop.ai/mcp/v1",
                "transport": "http-streaming",
                "headers": {
                    "Authorization": "Bearer YOUR_API_KEY_HERE"
                }
            }
        }
    }
}

McpServers

{
    "preloop": {
        "url": "https://preloop.ai/mcp/v1",
        "transport": "http-streaming",
        "headers": {
            "Authorization": "Bearer YOUR_API_KEY_HERE"
        }
    }
}

License
Python 3.11+

Overview

Preloop is an open-source, event-driven automation platform with built-in human-in-the-loop safety. AI agents respond to events across your tools automatically. When agents call sensitive operations, Preloop intercepts the request and routes it for human approval.

Preloop acts as an MCP proxy and can be integrated in existing workflows without any infrastructure changes.

Key Features

Core Platform (Open Source)

- Event-Driven Automation: AI agents respond to events across your tools automatically
- Human-in-the-Loop Safety: Intercept sensitive operations and route for human approval
- MCP Server: Standards-based Model Context Protocol (MCP) server
- 6 built-in tools: get_issue, create_issue, update_issue, search, estimate_compliance, improve_compliance
- JWT authentication with per-user tool visibility
- StreamableHTTP transport for Claude Code and other MCP clients
- Tool Management: Configure and manage tool access
- Support for external MCP servers and tool proxying
- Basic approval workflows (single-user) with email + mobile app notifications
- Agentic Flows: Event-driven workflows triggered by issue tracker events
- Issue Tracker Integration: Jira, GitHub, GitLab support with continuous sync
- Vector Search: Intelligent similarity search using embeddings
- Duplicate Detection: Automated detection of duplicate and overlapping issues
- Compliance Metrics: Evaluate issue compliance and get improvement recommendations
- Web UI: Modern interface built with Lit, Vite, and Shoelace Web Components

> Looking for Enterprise features? Preloop Enterprise Edition adds RBAC, team-based approvals, advanced audit logging, and more. See Enterprise Features below.

Open Source vs Enterprise (important)

- Open Source: single-user approvals with email + mobile app notifications.
- Enterprise: adds advanced conditions (CEL), team-based approvals (quorum), escalation, and Slack & Mattermost notifications.
- Mobile & Watch apps: the iOS/Watch and Android apps can be used with self-hosted / open-source Preloop deployments.

Supported Issue Trackers

- Jira Cloud and Server
- GitHub Issues
- GitLab Issues
- (More to be added in future releases, including Azure DevOps and Linear)

Architecture

Preloop is designed with a modular architecture:

1. Preloop (./backend/preloop): The main RESTful HTTP API server that provides access to issue tracking systems and vector search capabilities.
2. Preloop Models (./backend/preloop/models): Contains the database models (using SQLAlchemy and Pydantic) and CRUD operations for interacting with the PostgreSQL database, including vector embeddings via PGVector.
3. Preloop Sync (./backend/preloop/sync): A service responsible for polling configured issue trackers, indexing issues, projects, and organizations in the database, and updating issue embeddings.
4. Preloop Console (./frontend): A web application built using Lit, Vite, TypeScript, and Shoelace Web Components.

This structure allows:
- Clear separation of concerns between the API layer, data models, and synchronization logic.
- Independent development and versioning of the core components.

Preloop Console

The Preloop Console is in the frontend directory. It is built using modern web technologies to provide a fast, responsive, and feature-rich user experience.

- Technology Stack: Lit, Vite, TypeScript, and Material Web Components.

Installation

Prerequisites

- Python 3.11+
- PostgreSQL 14+
- PGVector extension for PostgreSQL (for vector search capabilities)

Local Setup

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.