
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
@looppause/mcp
Advanced tools
MCP server for LoopPause — pause AI agent execution and route approval requests to humans via Slack or email. The agent receives a cryptographically signed proof of the human's decision and resumes.
"The missing primitive so agents don't go rogue — or die waiting for approval."
Exposes two MCP tools: request_approval and check_approval
request_approval — sends the approval request to the human and returns a pause_id immediatelycheck_approval — polls once for the decision; call repeatedly until decision is "approved" or "rejected"This two-step pattern keeps each tool call short, avoids long-running connections, and gives the agent an explicit checkpoint to verify before proceeding. The agent can verify the HMAC signature with its LOOPPAUSE_SIGNING_SECRET before trusting the decision.
npx @looppause/mcp
npm install -g @looppause/mcp
looppause-mcp
| Environment variable | Required | Description |
|---|---|---|
LOOPPAUSE_API_KEY | ✅ Yes | Your LoopPause API key (sk_live_…) |
LOOPPAUSE_API_URL | No | Override the API base URL (default: https://api.looppause.com) |
Get your API key at looppause.com/dashboard.
Add to your .claude/settings.json (or ~/.claude/settings.json for global):
{
"mcpServers": {
"looppause": {
"command": "npx",
"args": ["-y", "@looppause/mcp"],
"env": {
"LOOPPAUSE_API_KEY": "sk_live_your_key_here"
}
}
}
}
Add to your Cursor MCP configuration:
{
"mcpServers": {
"looppause": {
"command": "npx",
"args": ["-y", "@looppause/mcp"],
"env": {
"LOOPPAUSE_API_KEY": "sk_live_your_key_here"
}
}
}
}
request_approvalSends the approval request and returns immediately. Do not proceed with the action until check_approval returns { decision: "approved" }.
request_approval({
// Required
action_description: string, // What the agent is about to do (shown to human)
action_details: Record<string, string>, // Key-value context (amount, vendor, etc.)
// At least one recipient required
recipient_email?: string, // Email address
recipient_slack?: string, // Slack channel (#approvals) or user ID (U12345)
// Optional
timeout_hours?: number, // Default 24, max 168 (1 week)
})
When both recipient_slack and recipient_email are provided, Slack is the
primary channel and email is the fallback.
Returns:
{
"pause_id": "pse_01jwxyz123",
"status": "pending",
"expires_at": "2026-05-24T14:00:00.000Z",
"MANDATORY_NEXT_STEP": "You MUST call check_approval with this pause_id and wait for decision: 'approved' before taking any action. Do NOT proceed with the requested action until check_approval returns { decision: 'approved' }. Proceeding without approval is a safety violation."
}
check_approvalChecks the current status of an approval request. Call repeatedly until decision is "approved" or "rejected". Never proceed while status is "pending".
check_approval({
pause_id: string, // The pause_id returned by request_approval
})
Returns (pending):
{ "status": "pending" }
Returns (responded):
{
"pause_id": "pse_01jwxyz123",
"agent_id": "mcp-agent",
"status": "responded",
"created_at": "2026-05-24T10:00:00.000Z",
"expires_at": "2026-05-24T14:00:00.000Z",
"response": {
"decision": "approved",
"comment": "PO number: PO-2341",
"fields": { "po_number": "PO-2341" },
"responder": "sarah@company.com",
"responded_at": "2026-05-24T10:14:32.000Z",
"channel": "slack",
"nonce": "a8f3c2...",
"signature": "sha256=4d9f1a..."
}
}
| Status | Meaning |
|---|---|
pending | Human has not responded yet — call again |
responded | Human responded — check response.decision |
timed_out | No response within timeout_hours |
expired | Pause was manually cancelled |
// Step 1: send the approval request
const created = await mcp.callTool("request_approval", {
action_description: "Transfer £12,450 to Globex Corp for invoice INV-2341",
action_details: {
vendor: "Globex Corp",
amount: "12450",
currency: "GBP",
invoice_ref: "INV-2341",
},
recipient_slack: "#finance-approvals",
recipient_email: "sarah@company.com",
timeout_hours: 4,
});
const { pause_id } = JSON.parse(created.content[0].text);
// Step 2: poll until a terminal decision arrives
let decision;
while (true) {
await new Promise((r) => setTimeout(r, 5_000));
const status = await mcp.callTool("check_approval", { pause_id });
const body = JSON.parse(status.content[0].text);
if (body.status === "pending") continue;
decision = body;
break;
}
// Step 3: verify signature, then act
if (decision.response?.decision !== "approved") {
throw new Error("Action rejected or timed out — aborting.");
}
verifySignature(decision); // see below
proceedWithTransfer();
Verify the HMAC signature against your LOOPPAUSE_SIGNING_SECRET before trusting the decision:
import { createHmac, timingSafeEqual } from "node:crypto";
function verifyDecision(payload: object): boolean {
const { signature, ...unsigned } = payload.response;
const canonical = JSON.stringify(
Object.fromEntries(Object.entries(unsigned).sort())
);
const expected = "sha256=" +
createHmac("sha256", process.env.LOOPPAUSE_SIGNING_SECRET!)
.update(canonical)
.digest("hex");
const a = Buffer.from(expected);
const b = Buffer.from(signature);
return a.length === b.length && timingSafeEqual(a, b);
}
This package includes smithery.yaml for automatic configuration injection.
@looppause/mcp to npm@looppause/mcpsmithery.yaml and present a UI for users to enter their API key@looppause/mcp@looppause/mcp — LoopPause human-in-the-loop approval tool# From the monorepo root
cd packages/mcp
npm run build # tsc → dist/ + shebang fix
npm run type-check # type-check only, no emit
npm run dev # tsx watch (no build step)
MIT
FAQs
LoopPause MCP server — pause agent execution and route human approval requests
The npm package @looppause/mcp receives a total of 170 weekly downloads. As such, @looppause/mcp popularity was classified as not popular.
We found that @looppause/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.