mild run

mild run

Your AI agent can't touch Stripe, Gmail, Slack or more, without your tap. mild.run intercepts every sensitive action and sends you a notification to approve or block — before anything executes. Agent never holds credentials.

Category
Visit Server

README

mild.run — Human Approval Gate for AI Agents

smithery badge

Before your AI agent does anything irreversible — your tap required.

mild.run is an MCP server that intercepts sensitive AI agent actions (Stripe refunds, email sends, data deletes) and sends you a notification (Telegram or email) to approve or block before anything happens. Your agent has no credentials — the gate is enforced at the infrastructure level.


The Problem

You're running AI agents that touch real money, real emails, and real data. When the agent misunderstands your intent or hallucinates a parameter, the damage is immediate and irreversible.

"My agent issued a $1,500 refund. I said $150."
"My agent emailed my entire CRM with a test message."
"My agent cancelled a subscription I didn't mean to cancel."

Telling the agent to "ask before acting" doesn't work — you're asking a non-deterministic system to police itself. mild.run enforces the gate at the infrastructure level. No approval → no action. The agent cannot bypass it.


How It Works

  1. Sign up at mild.run — free
  2. Connect Stripe (paste your restricted API key — charges:Read + refunds:Write only)
  3. Connect Telegram (click a bot link → send one message → verified) or use email approval
  4. Paste your MCP URL into your agent platform:
https://mcp.mild.run/mcp?mcp_token=YOUR_TOKEN

That's it. Every sensitive action now requires your tap before it fires.


What It Gates

Action Stakes Status
Stripe refund Money ✅ Live
Stripe subscription cancel Revenue ✅ Live
Stripe customer delete Data ✅ Live
Stripe payout Cash ✅ Live
Gmail send email Reputation ✅ Live
Slack message Communication ✅ Live

Compatible Platforms

Works with any MCP-compatible agent platform:

  • base44 — paste the URL in one chat message
  • Claude Desktop — add to claude_desktop_config.json
  • ChatGPT — requires Developer Mode (Settings → Connectors), then add as a connector with no auth
  • n8n — add as an MCP node
  • Cursor / Windsurf — add to MCP settings
  • Any MCP client — Streamable HTTP transport (/mcp)

A legacy SSE endpoint (/sse) is still available for any client that hasn't moved to Streamable HTTP yet, but it's deprecated — new integrations should use the /mcp URL above.


The Approval Flow

When your agent tries a gated action:

  1. Agent calls the tool (e.g. stripe_refund)
  2. mild.run logs the request and immediately returns a confirmation to the agent
  3. You receive a notification (Telegram tap or email link) to approve or block:
🌊 mild.run — Approval Required

Action: Stripe Refund
Charge: ch_3abc...
Amount: $150.00
Reason: Customer request

[✅ Approve]  [🚫 Block]
  1. Tap Approve → refund fires. Tap Block → nothing happens.
  2. No decision within 24 hours → auto-blocked.
  3. Every decision is logged in your dashboard at mild.run.

Why Not Just Prompt the Agent to Ask?

Prompts are advisory — the agent can ignore them, especially under prompt injection. mild.run holds your Stripe restricted key. The agent has no credentials. There is no path from agent to Stripe except through mild.run.

Prompt-based mild.run
Enforced by The agent itself Infrastructure
Bypassable? Yes No
Credential bypass path? Yes No
Audit trail? No Yes

Pricing

Plan Price Included
Free $0/month 30 approvals/month, Stripe + Gmail, Telegram
Solo $12/month Unlimited approvals, all integrations, 90-day audit log

Sign up free at mild.run.


MCP Tools

mild.run exposes the following MCP tools. All require mcp_token as a parameter (your personal token from mild.run/dashboard).

Tool Description
stripe_refund Issue a Stripe refund after human approval
stripe_subscription_cancel Cancel a Stripe subscription after human approval
stripe_customer_delete Delete a Stripe customer after human approval
stripe_payout Create a Stripe payout after human approval
gmail_send_email Send a Gmail message after human approval
slack_post_message Post a Slack message after human approval
get_approval_status Check the status of a pending approval request

Security

  • Stripe restricted keys are stored encrypted — never in plaintext
  • Your mcp_token is a UUID — no email or personal data in the URL
  • Telegram webhook validated with secret token
  • Every approval decision is logged with timestamp and stored server-side
  • mild.run never stores your email content beyond the approval request

Links

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured