Competition challenge — 18 September 2026
Role. Adversarial competition challenger. Kill clones of well-funded or OSS-default tools (Langfuse, Helicone, LangSmith, Okta, IBM, Portkey, Phoenix) unless the wedge is crisp and defensible in 90 days. Named competitors only. Prices and product facts from vendor pages/docs opened or crawled on this date, plus first-party blogs.
Scope. ideas/agentic-ideas.md (Hallpass, BurnNotice, Permitfile, Rehearse, Workslip, SchemaPin) and ideas/quantum-ideas.md (Q1–Q10, all already self-killed). Also BRIEF candidates A–E. research/competition.md is treated as a briefing, not gospel — it is too bullish on candidate A and misses the closest clone.
Rule used. “A + B + C, and nobody ships all three” is not a wedge. That is how every doomed aggregator dies. A wedge is a job, a buyer, and an object incumbents will not ship this quarter because it fights their positioning.
Scoreboard
| ID | Idea | Verdict | Named competitors that kill or force the fix |
|---|---|---|---|
| A / Hallpass | English MCP permit gateway + spend cap + signed receipts, one hosted URL | KILL as specified | Permit.io MCP Gateway, Preloop, Portkey MCP Gateway, LiteLLM, mcp-doorman, Cordon, Obot |
| A′ | Same job, not a hosted MCP/LLM proxy (see patched survivor) | FIX → SURVIVE | Survives only if it refuses the gateway category |
| B / Permitfile | agent-permit.yaml + GitHub App + hosted runtime URL |
KILL as product | GitHub Copilot allowedMcpServers, Microsoft APM apm-policy.yml, agentperms, agents-spec, Preloop YAML+CEL |
| C / Workslip | Freelance/client signed work record | KILL as product | ProofAgent, Agent Receipts/Obsigna, OrgX Agent Work Receipt, agent-custody, IETF draft-sahu-agent-action-receipts-00 |
| D / Q1 | Quantum circuit classroom | KILL | IBM Composer, IBM Quantum Learning, IBM Classroom Accounts, Quirk, Qiskit, qBraid |
| Q2–Q10 | All other quantum-shaped VPS products | KILL | IBM / AWS / Azure / Classiq / qBraid / Qualys / Cloudflare / Gurobi — see §Quantum |
| BurnNotice | File-drop loop/spend autopsy | FIX | Helicone (if you add a live proxy), Langfuse cost, provider usage CSVs. Not a company; a module |
| Rehearse | Non-executing blast-radius plan | KILL as product | Claude Code plan/ask, Cursor plan, Codex, Permit.io tool risk class, PolicyLayer census |
| SchemaPin | Hosted MCP schema lockfile + badge | KILL | Invariant/Snyk mcp-scan (tool pinning), mcp-doorman rug-pull hash-pin, agentperms lock |
| Slip (invented) | Public blast card + English→YAML + hashed receipt; decision API / local PEP, never a token-holding proxy | SURVIVE | Patches Hallpass/Permit.io/Preloop/Portkey kills. See last section |
Do not ship a Langfuse/Helicone/LangSmith/Phoenix clone. Confirmed: Helicone is in maintenance mode after the Mintlify deal (3 Mar 2026, both parties). That is a migration pool, not a hole. Langfuse Core is $29/mo MIT. Phoenix self-host is $0. Instant death.
Do not ship Okta/IBM/Broadcom GRC. Agent SSO is free on core Okta SSO (GA 24 Aug 2026). watsonx Orchestrate AgentOps Agent GA 31 Aug 2026, floor $530/mo. AgentMinder GA 31 Aug 2026, VMware-bundled, no list price.
Do not ship Portkey. Portkey is on the BRIEF kill list and already has virtual-key budgets, an MCP Gateway (auth, tool provisioning, logs, rate limits; GA Jan 2026), and is being absorbed into Palo Alto Prisma AIRS. Production $49/mo. Cloning “gateway + MCP + budget” is suicide.
Research error you must not inherit
research/competition.md says the remaining white space is “English allow/deny/ask + hard spend cap on the user’s keys + a receipt a third party can verify,” and names Preloop as the closest threat.
That table omits Permit.io MCP Gateway (permit.io/mcp-gateway, hosted at *.agent.security). Permit.io is a funded authorization company (SOC 2 Type II, free Community tier, Startup from $5/mo, Pro from $25/mo). The MCP Gateway is literally:
- Drop-in URL, no SDK, no rewrite of MCP servers.
https://<host>.agent.security/mcp?upstream_mcp=<upstream>— one URL, any MCP.- Docs: “secured gateway URL for any MCP server in under 5 minutes.”
- Allow/deny via trust levels (low/medium/high, auto-classified on import), human consent, admin ceiling.
- Audit of every allow/deny with human + agent + tool.
- Cursor / Claude Desktop / VS Code / Claude Code copy-paste configs.
That is BRIEF candidate A and is Hallpass without the English textarea and the pretty /r/ page. “We are not enterprise GRC” is positioning, not a product. Permit.io already sells a hosted, self-serve, no-code MCP permit URL. If Hallpass ships as “paste your MCP URL, get a gateway,” the homepage is a worse app.agent.security.
Preloop is the second clone, not the first: Apache 2.0 MCP firewall, ordered allow/deny/require-approval/require-justification, YAML+CEL, human approvals (mobile/watch/Slack), model gateway with hard budgets, preloop agents discover rewires Claude Code/Cursor/Codex, one-line claude mcp add. GitHub ~62 stars (small), but the mechanism is complete. Their own docs show layered dollar rules on a pay tool (allow <$100, ask $100–$500, deny >$2,000). “English rules” is an LLM compiler in front of that YAML. Not a 90-day moat.
LiteLLM (53k+ stars, 240M+ Docker pulls) already ships hard $ caps that reject, not alert, plus an MCP gateway with six-level tool permissions and a Tool Permission Guardrail (regex allow/deny on tool name + argument patterns). Cloudflare AI Gateway has spend limits (429 or fallback) as of 9 Sep 2026. Token spend control is solved.
The research “intersection” argument is therefore false as a moat: Permit.io has the URL, Preloop has allow/deny/ask + budgets + approvals, LiteLLM/Portkey have BYOK $ caps, Obsigna/ProofAgent have receipts. Gluing them is a feature bundle, not a company.
Instant-kill clones (do not let PM “just add” these)
If the homepage, SDK, or pricing looks like any of these, KILL the pivot regardless of the idea name:
| Shape | Who already owns it | Floor |
|---|---|---|
| Trace / span / session replay | Langfuse, LangSmith, AgentOps, Phoenix, Datadog | $0–$40 |
| Prompt manager + datasets + LLM-as-judge | Langfuse, LangSmith, Phoenix, Braintrust | $0–$249 |
| OpenAI-compatible proxy whose value is logs | Helicone (frozen), LiteLLM, Portkey | $0–$79 |
| Virtual keys, fallbacks, cache, routing | LiteLLM OSS, Portkey $49, Cloudflare | $0 |
| Agent SSO / first-class agent identity | Okta Agent SSO, $0 extra | $0 |
| Enterprise agent control plane | IBM Orchestrate $530+, Broadcom AgentMinder, Dataiku, WSO2 Agent Manager (GA 17 Sep 2026), AWS Bedrock AgentCore | sales |
| MCP gateway / catalog / hosting | Permit.io, Portkey, Obot ($35M seed), LiteLLM, Docker MCP Gateway, Microsoft Foundry AI gateway | $0–sales |
| MCP firewall as control plane | Preloop, Cordon, mcp-doorman, mcp-restrictor, Microsoft Agent Governance Toolkit MCPGateway |
$0 OSS |
| “We make you AI Act / SOC2 compliant” | Preloop already warns against this; BRIEF forbids it | — |
Safe to borrow as an implementation detail, never as the product: hash-chained signatures (Obsigna pattern), OTel export out to Langfuse, BYOK.
Agentic ideas
1. Hallpass — KILL (as specified)
Claim. One hosted MCP URL. English rules. Allow/deny/ask. Cap dollars on your key. Signed shareable receipt. Let’s Encrypt for agent permissions.
This is Permit.io MCP Gateway + Preloop + a receipt skin. The inventor’s own failure mode is the verdict: “if the homepage says ‘MCP gateway’ instead of ‘English rules + receipt’, we are a worse MintMCP.” The spec is a gateway: “Paste one MCP URL into Cursor… Copy-paste https://cryptobook.space/mcp/{id}.”
Named competitors (mechanism, not vibes):
| Competitor | What they already ship that Hallpass duplicates |
|---|---|
| Permit.io MCP Gateway | Hosted *.agent.security/mcp drop-in, 5-minute setup, allow/deny, consent/ask, trust ceilings, audit, Cursor/Claude snippets, free Community. Two dashboards (app.agent.security + app.permit.io) — heavy, but the job is identical. |
| Preloop | OSS MCP firewall, allow/deny/ask/justify, CEL on args, hard model budgets, Slack/mobile approve, session ledger, one-command agent rewire. Example: dollar tiers on payments. |
| Portkey MCP Gateway | Auth, per-user tool enable/disable, logs, rate limits, guardrails, budget limits on virtual keys (cost or tokens, weekly/monthly). Now Palo Alto. BRIEF-listed. |
| LiteLLM | Hard max_budget reject; MCP allowed_tools / mcp_tool_permissions; Tool Permission Guardrail allow/deny + param regex. OSS $0. |
| mcp-doorman (Glama, 18 Sep 2026) | One-command local proxy: glob allow/deny/approve, secret redaction, prompt-injection, rug-pull hash-pin, rate limits, MCP elicitation approval, JSONL audit. Zero infra. |
Cordon (@getcordon/cli) |
Aggregating MCP proxy: allow/block/approve/read-only, Slack approval, sequence-aware, SQL-aware. |
| mcp-restrictor | Default-deny YAML proxy; filters tools/list and re-checks tools/call. |
| Obot | MIT MCP gateway + catalog + OAuth broker + audit; $35M seed; 14-day cloud trial. |
| Docker MCP gateway | Cedar permit/forbid + @requireApproval (docs dated 12 Aug 2026). |
| Claude managed-agents | Native always_allow / always_ask / server-eval permission policies (beta managed-agents-2026-04-01). |
| Agent Receipts / Obsigna, ProofAgent, agent-custody | Signed hash-chained receipts; ProofAgent already has public proofagent.pro/receipt/… pages at $19/mo. |
Why “English + receipts” is not a 90-day defense:
- English is a compiler. Preloop and Permit.io already have UI rule builders. An LLM that writes YAML is a weekend. The YAML will be the source of truth anyway (Hallpass even says so for EU disclosure). Incumbents add a textarea without changing their company.
- Dollar caps on an MCP-only hop are a lie. Hallpass admits it cannot see OpenAI/Anthropic invoices unless it sits on the LLM path or the user types a declared $/1k. Sitting on the LLM path = LiteLLM/Portkey/Helicone clone (BRIEF kill). Declared prices = a counter the user can game. Agent Wormhole (12 Sep 2026) measured 590 money-moving MCP tools, 88% unique names; their own name-list guard caught 13.4%. Do not market “$2 per session” as if it replaced the provider bill.
- Receipts are a protocol, not a SaaS. Obsigna (Apache-2.0, SDKs, MCP proxy, dashboard, updated 17 Sep 2026), OrgX Agent Work Receipt v0.1 (account-free), IETF
draft-sahu-agent-action-receipts-00(16 Aug 2026), ProofAgent ($19, public verify URL). Hosting/r/hp_7f3ais a weekend on top of an open spec. ProofAgent already did the “click a URL, see a receipt” aha. - Time-to-first-permit is not 4 minutes vs 5. Permit.io is five minutes with an org. mcp-doorman is one command. Preloop is one
claude mcp add. Hallpass’s 60-second playground is a demo on a fake filesystem, not enforcement on the user’s GitHub token. The moment you need a real upstream, you are in Permit.io’s onboarding. - Cursor/Claude native policy is the existential 90-day risk Hallpass itself lists. Claude already defaults MCP toolsets to
always_ask. OpenCode has allow/ask/deny inopencode.json. GitHub Copilot has org MCP allowlists (6 Aug 2026). The choke point moves into the client. A hosted URL the user must remember to paste loses by default.
KILL the hosted “paste MCP URL, we proxy it” product. That category is occupied by a funded IAM company, a Palo Alto gateway, an Apache-2.0 control plane, and several one-binary OSS proxies. Combining three occupied features does not create a fourth.
FIX path (only if PM still wants this job): see Slip at the end. Headline cannot contain “MCP gateway.” No token custody. No model proxy. Receipt + blast card are the product; policy is a compiler; enforcement is local.
2. BurnNotice — FIX (module, not the company)
Claim. Drop last night’s log/CSV. Circle the loop and the dollars. Optional kill-switch later.
Not a Langfuse clone if it stays a coroner. Langfuse/Helicone/AgentOps want instrumentation before the fire. The job “the fire already happened on an un-instrumented laptop” is real (Revenium/ZDNet-class $3.7k–$47k loops; OpenAI’s hard spend limit is gone; Google “budgets” are alerts). File-drop in 60s, no SDK, is a legitimate aha.
Named competitors / death modes:
| Competitor | Overlap |
|---|---|
| Helicone | Cost + request timeline via proxy. Maintenance mode, but the mental model is “see what burned.” If BurnNotice adds the “optional live tail proxy,” it becomes Helicone 2 — instant KILL under BRIEF. |
| Langfuse Core $29 | Cost attribution per trace/user/feature once instrumented. Cheap default. |
| Provider consoles | OpenAI/Anthropic usage CSV is the input. They will add loop clustering. |
Claude Code /cost, Cursor usage |
In-client spend already exists for the hottest buyer. |
| LiteLLM spend reports | /global/spend/report for anyone already on a proxy. |
Why not SURVIVE as the company:
- One-shot. Upload once, screenshot, never return. $29/mo for 200 uploads is a guilty-conscience SKU, not a habit. The inventor’s mitigation (“live tail proxy”) is the Helicone clone.
- Parser hell is not a moat. Four formats + regex is a GitHub gist. Every new harness (Claude Code JSONL, Codex, Cursor, OpenCode, Aider) is a break.
- False loops. Pagination, retries,
read_file× N. If we are wrong on the $47k tweet, we are a joke. - Secrets. Storing prompts/args is a security-challenge KILL. Hash-only is the only honest v1, which makes the “timeline sparkline of what it said” weaker.
FIX, not KILL: keep the file-drop as a homepage module and a CI action (“fail if this JSONL contains a loop signature”). Do not productize a proxy. Do not add traces, evals, or prompt playgrounds. Do not promise provider-invoice accuracy. Monetize, if at all, as a GitHub Action on the same backend as Slip — not as a $29 coroner SaaS.
3. Permitfile — KILL as a product
Claim. Dependabot for MCP tools: agent-permit.yaml in the repo, GitHub App shames the PR, hosted URL enforces it.
Named competitors:
| Competitor | What they already ship |
|---|---|
| GitHub Copilot (6 Aug 2026) | Enterprise/org allowedMcpServers. Server-level, not per-tool — the inventor is right — but GitHub adding per-tool is a one-quarter copy, not a 12-month copy. They own the PR surface. |
Microsoft APM apm-policy.yml |
Org-global YAML, auto-discovered from git remote, allow/deny MCP servers and transports, enforcement: block. Docs 15 Sep 2026. |
| agentperms | mcp.policy.yaml, scan / lock / record / infer / enforce. Least-privilege generated from traces. |
| agents-spec / agent-perms | Vendor-neutral .agents/permissions.json across Claude Code, Codex, OpenCode, Crush, Cursor. |
| Preloop | Policy-as-code YAML in git, validate, diff, apply. |
| OpenCode | permission allow/ask/deny in opencode.json, per-agent overrides. |
| Claude Code | Native permission policies. |
Dependabot worked because GitHub was the runtime. Permitfile’s runtime is a hosted MCP URL the IDE can bypass with stdio. The inventor admits this. A bot comment without enforcement is a linter; paid linters die to mcp-scan in CI (Snyk, free). A bot comment with enforcement is Hallpass again — Permit.io clone, plus a GitHub App security review.
Viral “every public MCP PR is an ad” is real distribution. It is not a product. Keep agent-permit.yaml as the file format for Slip. Do not build a second company around a GitHub App. GitHub will eat per-tool policy the way they ate Dependabot clones.
4. Rehearse — KILL as a product
Claim. Paste a task + tool catalog. Show the blast radius without calling any real server.
Named competitors: Claude Code plan/ask modes, Cursor plan, Codex, Copilot. Permit.io auto-classifies tools low/medium/high on import (delete/destroy = high). PolicyLayer already published a 32,820-server destructive-tool census. mcp-scan flags toxic flows. The emotional “your agent would delete 12 repos” is a landing-page animation, not a $29 subscription.
Plan ≠ reality (inventor admits). If the playground uses our LLM wallet, BRIEF kill (token reseller). If it is a scripted demo, it is marketing HTML. If it uses the user’s key to plan, we are a thin wrapper around the same model that would have planned inside Cursor.
KILL the SKU. Steal the jump-scare as a scripted homepage module for Slip. Label it “demo, not a proof.” No CI “golden plan” product — that is evals (Braintrust/Phoenix).
5. Workslip — KILL as a product
Claim. Client-readable signed timesheet of mixed human+agent labor. Verify URL. No escrow.
Named competitors:
| Competitor | Object |
|---|---|
| ProofAgent | Public verify URL, SHA-256, $19/mo, “no code required.” Wrong object (GPS-tagged generic actions) but same aha. |
| Agent Receipts / Obsigna | Open protocol, SDKs, MCP proxy, dashboard. Updated 17 Sep 2026. |
| OrgX Agent Work Receipt v0.1 | Apache-2.0, account-free, portable intent/actor/actions/artifacts/cost. |
| agent-custody | Signed receipts, Cedar, Merkle, provenance labels (attested/observed/claimed). |
| IETF draft-sahu-agent-action-receipts-00 | 16 Aug 2026. Offline-verifiable hash chain. |
| Hello.ai / PipeLab | “Receipts or it didn’t happen” product copy. |
| Dropwatch MCP receipts | $0.01 USDC/call — wrong rails, but the MCP receipt exists. |
Freelance TAM is narrow (BRIEF already asked). Freelancers will not pay $29/mo to defend a rate when they can paste a Git log. Clients who ask “did a human look” want the PR + tests, not a pink verify page. Signature proves Workslip ingested a file at time T, not that the work is good (inventor admits). The moment copy says “proves the work,” FTC + UPL-adjacent — also a legal kill.
KILL the standalone. The receipt page is the viral artifact for Slip. Do not build invoice software. Do not add client logins, ratings, or “pay this invoice.”
6. SchemaPin — KILL
Claim. Hash-pin tool name+description+schema. Deny on silent rewrite. README badge.
Named competitors: Invariant Labs invented this attack class (tool poisoning, rug-pull). mcp-scan / Snyk Agent Scan does tool pinning and proxy guardrails; Snyk acquired Invariant (Jun 2025); CLI is free (uvx snyk-agent-scan). mcp-doorman hash-pins on first use and blocks swaps until re-pin — in the enforcement path, today. agentperms lock pins tool identity. A hosted badge is SSL Labs: free, no conversion. Qualys/Tenable already taught this lesson.
Benign description edits = noise. Fetching customer MCP URLs from this VPS = SSRF. A pinned malicious server stays malicious (inventor admits). Marketing “secure MCP” would be theater.
KILL. If Slip’s local PEP hashes the tools/list it saw, that is a checkbox, not a SKU.
Quantum lane — KILL (all of it)
Agree with ideas/quantum-ideas.md and research/quantum-market.md. Independent competition check:
| ID | Idea | Verdict | Why, named |
|---|---|---|---|
| Q1 / BRIEF D | Circuit classroom | KILL | IBM Composer (free, visual, real or sim backends). IBM Quantum Learning (free courses). Classroom Accounts (28 May 2026): 5–100 students, no card, real QPUs, 10 min/student/month. Quirk. Qiskit textbook. Cannot beat free + real hardware + IBM credential. |
| Q2 | Hosted Aer | KILL | pip install qiskit-aer. IBM Open Plan unlimited simulators. This box caps ~31–32 qubits statevector. A workstation. |
| Q3 | BYO-key QPU proxy | KILL | qBraid ($0/$20/$100), Strangeworks, Classiq ($200M+, AWS Marketplace), AWS Braket, Azure Quantum. Also a key-custody honeypot. |
| Q4 | Cost estimator | KILL | IBM Platform estimates QPU-seconds. quantumcomputingcost.com tables. Not SaaS. |
| Q5 | Quantum spend receipts | KILL | IBM Open Plan already caps. PayGo users have IBM Cloud/AWS billing alerts. Tiny TAM. Same clone as Hallpass, worse buyer. |
| Q6 | Advantage honesty analyzer | KILL | No WTP. IBM Advantage Tracker / Benchpress / MQT already exist for researchers. |
| Q7 | Quantum-inspired optimizer | KILL | Theater vs Gurobi / CPLEX / OR-Tools / HiGHS. Constraint 7. |
| Q8 | QRNG / QKD | KILL | Hardware or /dev/urandom in a lab coat. ANU QRNG, Cloudflare. Theater. |
| Q9 | VQE / chemistry toy | KILL | Novo’s application layer is Phasecraft / Algorithmiq / QunaSys with QPUs and PhDs. 32-qubit VQE does not change an experiment. Zapata (hardware-agnostic software) → $0 revenue 2025/H1 2026. |
| Q10 | PQC scanner | KILL | Off-mission (cryptography, not QC). Cloudflare Radar, Qualys SSL Labs, testssl.sh, IBM Quantum Safe Explorer, SandboxAQ, PQShield. Scanner monetization is historically terrible. “Quantum-safe” badge = theater. |
Novo Holdings (11 Sep 2026) does not rescue a VPS: ~70% of $13.9B went to hardware; general developer tools “struggle to capture lasting value” because clouds bundle them; investable apps are multi-year scientific embeddings. IBM Starling is 2029. Vendor revenue ~$1.8B (2025), QCaaS $0.25B. Demand is minutes on someone else’s fridge.
Do not put “quantum” on the homepage to sound 2026. That is constraint 7.
BRIEF candidates A–E (if PM reads the brief, not the idea files)
| Candidate | Verdict | One line |
|---|---|---|
| A Permit gateway | KILL as a hosted MCP/LLM proxy | Permit.io + Preloop + Portkey + LiteLLM |
B agent-permit.yaml runtime |
KILL as a standalone | GitHub / Microsoft APM / agentperms; keep the file format |
| C Freelance receipts | KILL as a standalone | ProofAgent / Obsigna / OrgX; keep the /r/ object |
| D Quantum classroom | KILL | IBM free stack |
| E “more genius” | SURVIVE only as Slip | Below |
Patched survivor — Slip (FIX of Hallpass that actually patches the kills)
BRIEF: if every idea is killed, invent one that patches the kill reasons.
Hallpass died because it is a gateway. Workslip died because receipts are a protocol. Permitfile died because GitHub owns PRs. BurnNotice/Rehearse/SchemaPin died as companies but are useful objects.
What Slip is
A policy compiler + public evidence object for people who already run coding agents this month.
- Homepage, no account, <60s.
- Scripted Rehearse jump-scare on a pinned GitHub-MCP catalog (“this task wants
delete_repo× 12”). - BurnNotice sample: one-click $3,762 loop autopsy (redacted, hashed args). - English box:never delete; ask before push; at most 20 tool calls / session. - Compiler shows the YAML (agent-permit.yaml) next to the English. YAML is source of truth. User can edit it. - Output: a Blast Card (/b/{id}) — tool list classified allow/deny/ask, destructive count, schema hashes — and a Receipt (/r/{id}) of the demo session. Both public, no login, signature verifiable in-browser. - Paid conversion is not a proxy.
- Copy a decision snippet: local stdio wrapper / Claude Code hook /
base_url-free PEP that sends{tool, arg_hash, policy_id}and gets{allow, deny, ask}+ a receipt id. - Cloud stores policy versions, hashes, and receipts. Never the model key, never GitHub/Slack tokens, never tool results, never prompt bodies. - Optional: user pastes a usage CSV into BurnNotice. Still no live LLM proxy. - Honest spend. Cap tool-call counts and named denies, not “$2 of Anthropic.” If we cannot see the invoice, we do not print a fake dollar ticker as if we could. (That single sentence is what stops Hallpass from being a fraud next to LiteLLM.)
- Price. $0 watermarked receipts/cards. $19–29/mo unlimited personal receipts + policy history (under Langfuse Core’s $29 ceiling). $99 team: shared rulebook, webhook on ASK (email; Telegram later). Bill receipts/policies, not spans.
- Non-goals (printed on the homepage). Not an MCP gateway. Not an LLM proxy. Not SSO. Not a catalog. Not evals. Not traces. Not “AI Act compliant.” Not a legal attestation.
Why this is not the clones
| Kill reason against Hallpass | How Slip patches it |
|---|---|
| Permit.io is the one-URL MCP proxy | We do not proxy customer MCP servers or hold upstream OAuth. Different category. Permit.io’s buyer is IAM; two dashboards. They will not become a public /r/ + /b/ for freelancers this quarter. |
| Preloop is the OSS firewall + budgets | Preloop is a control-plane install (CLI, CEL, operator console, ~62 stars, no 60s playground, unpublished cloud price). Slip is a browser object. If we ship YAML+CEL and a Grafana, we become Preloop and die. |
| Portkey/LiteLLM are BYOK $ caps + MCP gateways | We never sit on chat/completions. BRIEF-safe. No virtual keys, no routing, no cache. |
| mcp-doorman is a free local proxy | They have JSONL on disk, not a forwardable page. We can tell the user to run their PEP; we sell the card/receipt and the English compiler. |
| Obsigna/ProofAgent own receipts | ProofAgent is generic GPS hashes. Obsigna is a spec for tinkerers. The object we host is policy + blast radius + hashed decisions a non-engineer can read. We should emit Obsigna-compatible JSON, not invent a fifth protocol. |
| Langfuse/Helicone | No traces, no spans, no prompt store. BurnNotice is upload-and-delete forensics, hashed. |
| Okta/IBM | No identity, no agent directory, no RFP. |
| GitHub Copilot allowlists | We don’t fight GitHub for org policy. Repo YAML is an export, not the company. |
| Fake $ caps | We don’t claim them. |
90-day defensibility (honest)
Survives 90 days if the site is a playground that produces a card and a receipt without an account, and paid users get history + webhooks, and we never hold secrets.
Dies in 90 days if:
- The first screenshot is a “gateway dashboard” or a trace waterfall.
- We wrap user MCP URLs on our VPS (Permit.io clone and CFAA/key-custody kill).
- We add model routing “just to meter dollars.”
- We sell a “quantum-safe” or “AI Act” badge.
- Cursor ships a native per-tool policy UI that emails a share link — possible. Mitigation: be the share link, not the IDE.
What we steal from the killed ideas (one VPS process)
| Killed idea | Keep as |
|---|---|
| Hallpass English rules | Compiler only; YAML shown |
| Permitfile | File format agent-permit.yaml; no GitHub App in v1 |
| Workslip | Skin on /r/ (“share with a client”) |
| Rehearse | Scripted homepage jump-scare |
| BurnNotice | Sample + optional CSV drop; CI later |
| SchemaPin | Hash the catalog on the blast card; no badge SKU |
That is still one Node/Python app behind nginx: compiler, signer, static playground, Postgres for policy versions and receipt hashes.
PM-facing recommendation (competition only)
- Do not build Hallpass-as-spec. It is Permit.io with a pink theme. Research that called this “white space” missed Permit.io MCP Gateway. That error would ship a me-too.
- Do not build any quantum SKU. Confirmed kill by market, IBM’s free stack, and honesty.
- Do not build Langfuse/Helicone/Portkey/Okta/IBM shapes even as “just v2.”
- Build Slip, or kill the pivot. If the first sprint is an MCP reverse proxy, the competition verdict flips back to KILL.
- Price under $29. Langfuse Core is the psychological ceiling for infra the user is not sure they need.
- One-sentence test: If we cannot explain how we are not Permit.io, Preloop, and Portkey in one sentence, we are dead.
Slip: a public blast-radius card and a signed decision receipt for your coding agent, from English rules, without becoming your MCP gateway, your LLM vendor, your IdP, or your auditor.
If that sentence is not on the homepage, this file’s verdict is KILL the pivot.