👑 PromptKing← All Insights
PRODUCT MILESTONEProduct · MCP · OAuth

One URL to Governed

One server-side endpoint can teach a compatible client the governed handshake, carry it through policy review, and return a verifiable receipt. The recorded path completed in under 60 seconds; compatibility remains client- and version-specific.

July 14, 2026 · @PromptKing32
1
URL to Connect
30s
To Connected (OAuth + Consent)
60s
To Governed (CHK-0 → CHK-3)
27
Tools in the Full Surface

What Just Changed

Connecting an agent to a governance service usually begins with configuration, credentials and transport-specific setup. PromptKing reduced the tested path to one server-side MCP URL and a self-describing four-stage handshake: enrollment, registration, policy check and evidence receipt. In the recorded test, a compatible client completed that handshake in under 60 seconds without a PromptKing operator in the room. That result describes the tested path, not every client or deployment.

How It Works

A compatible server-side MCP client reaches the endpoint and follows the advertised authentication and discovery flow. After consent, the full profile exposes 27 tools; narrower profiles reduce the executable surface for governance, finance, read-only or enrollment work. Client support still depends on transport and OAuth compatibility. The access grant is explicit about what it permits and what remains outside the tool surface.

The Self-Teaching Protocol

The first tool returns the governance protocol: four stages, required fields, concrete examples and repair instructions. A cold agent can discover the sequence, enroll, register with a designated human principal, request a policy decision and record an evidence receipt without out-of-band documentation for the handshake. The receipt carries a SHA-256 integrity hash, correlation identifier and declared-versus-recorded cost fields. It preserves what the system recorded and the limits of that record; it does not turn a reported outcome into independently established business truth.

What This Means for Enterprise AI

For a compatible client, evaluation can begin before a long implementation project: connect, run the governed handshake and inspect the resulting policy decision and receipt. The value is not universal client compatibility. It is a stable server-side control surface that headless services can reach without a browser, while the evidence model remains independent of the model or orchestrator that performed the work.

The Out-of-Path Principle

PromptKing does not sit in the execution path. It does not see prompts, read workload content or control the runtime. It receives declared intent and metadata, evaluates policy and issues evidence receipts; the surrounding stack remains responsible for enforcement. The receipt makes the recorded decision and evidence boundary inspectable. It does not prove facts that were never captured.

THE GOVERNED HANDSHAKE

CHK-0
ENROLLExchange single-use token for org credentials
CHK-1
REGISTERAgent registers with a named human principal
CHK-2
POLICYDeclare intent, receive verdict — allowed or restricted
CHK-3
RECEIPTRecord outcome, receive SHA-256 evidence receipt

TRY IT NOW

Use this URL with a compatible server-side MCP client. Support depends on Streamable HTTP and OAuth behavior in that client and version.

https://www.promptking32.com/api/mcp/mcp
Generate Your Enrollment Token →

👑 PromptKing Inc. · promptking32.com · @PromptKing32 · info@promptking32.com

One URL to a Governed Handshake | PromptKing | PromptKing — Independent Evidence Plane