Provider credentials stay in encrypted Worker secrets, outside model-visible inputs, results, and evidence.
Give the agent power.
Keep consequential control.
Taploop is designed so credentials, money, approvals, provider ambiguity, and outcome claims remain governed outside the model.
Fail closed at the expensive boundaries.
These statements describe the deployed control plane—not a compliance certification.
Workspace-bound MCP tokens are stored as SHA-256 digests, carry server-selected scopes, and can be revoked independently.
The agent sees two allowlisted public-web tools instead of the upstream provider's raw tool catalog.
Every priced public-web request requires sufficient Taploop service credit and creates immutable wallet usage evidence.
Consequential plan execution still requires exact human approval and an explicit commitment ceiling.
Unknown provider outcomes remain explicit instead of being guessed successful or failed.
Important controls are still work, not claims.
The deployed manual MCP-token flow is workspace-bound and revocable. Taploop does not represent it as OAuth, and clients that require OAuth are not yet supported.
- MCP OAuth 2.1 for clients that require interactive authorization instead of a personal bearer token
- Two-factor authentication and expanded session controls
- Workspace and adapter emergency-stop controls
- Published retention schedule, DPA, trust center, and security questionnaire
- Independent assurance work such as SOC 2
Separate authority by action, not by marketing label.
Read
Inspect bounded connected information with scoped access and source evidence.
Draft
Prepare a plan or artifact without publishing, sending, spending, or changing external state.
Execute
Require explicit authority, policy checks, commitment limits, and human approval where consequential.