All documents · Competition

Competition challenge — 18 September 2026

Role. Adversarial competition challenger. Kill clones of well-funded or OSS-default tools (Langfuse, Helicone, LangSmith, Okta, IBM, Portkey, Phoenix) unless the wedge is crisp and defensible in 90 days. Named competitors only. Prices and product facts from vendor pages/docs opened or crawled on this date, plus first-party blogs.

Scope. ideas/agentic-ideas.md (Hallpass, BurnNotice, Permitfile, Rehearse, Workslip, SchemaPin) and ideas/quantum-ideas.md (Q1–Q10, all already self-killed). Also BRIEF candidates A–E. research/competition.md is treated as a briefing, not gospel — it is too bullish on candidate A and misses the closest clone.

Rule used. “A + B + C, and nobody ships all three” is not a wedge. That is how every doomed aggregator dies. A wedge is a job, a buyer, and an object incumbents will not ship this quarter because it fights their positioning.


Scoreboard

ID Idea Verdict Named competitors that kill or force the fix
A / Hallpass English MCP permit gateway + spend cap + signed receipts, one hosted URL KILL as specified Permit.io MCP Gateway, Preloop, Portkey MCP Gateway, LiteLLM, mcp-doorman, Cordon, Obot
A′ Same job, not a hosted MCP/LLM proxy (see patched survivor) FIX → SURVIVE Survives only if it refuses the gateway category
B / Permitfile agent-permit.yaml + GitHub App + hosted runtime URL KILL as product GitHub Copilot allowedMcpServers, Microsoft APM apm-policy.yml, agentperms, agents-spec, Preloop YAML+CEL
C / Workslip Freelance/client signed work record KILL as product ProofAgent, Agent Receipts/Obsigna, OrgX Agent Work Receipt, agent-custody, IETF draft-sahu-agent-action-receipts-00
D / Q1 Quantum circuit classroom KILL IBM Composer, IBM Quantum Learning, IBM Classroom Accounts, Quirk, Qiskit, qBraid
Q2–Q10 All other quantum-shaped VPS products KILL IBM / AWS / Azure / Classiq / qBraid / Qualys / Cloudflare / Gurobi — see §Quantum
BurnNotice File-drop loop/spend autopsy FIX Helicone (if you add a live proxy), Langfuse cost, provider usage CSVs. Not a company; a module
Rehearse Non-executing blast-radius plan KILL as product Claude Code plan/ask, Cursor plan, Codex, Permit.io tool risk class, PolicyLayer census
SchemaPin Hosted MCP schema lockfile + badge KILL Invariant/Snyk mcp-scan (tool pinning), mcp-doorman rug-pull hash-pin, agentperms lock
Slip (invented) Public blast card + English→YAML + hashed receipt; decision API / local PEP, never a token-holding proxy SURVIVE Patches Hallpass/Permit.io/Preloop/Portkey kills. See last section

Do not ship a Langfuse/Helicone/LangSmith/Phoenix clone. Confirmed: Helicone is in maintenance mode after the Mintlify deal (3 Mar 2026, both parties). That is a migration pool, not a hole. Langfuse Core is $29/mo MIT. Phoenix self-host is $0. Instant death.

Do not ship Okta/IBM/Broadcom GRC. Agent SSO is free on core Okta SSO (GA 24 Aug 2026). watsonx Orchestrate AgentOps Agent GA 31 Aug 2026, floor $530/mo. AgentMinder GA 31 Aug 2026, VMware-bundled, no list price.

Do not ship Portkey. Portkey is on the BRIEF kill list and already has virtual-key budgets, an MCP Gateway (auth, tool provisioning, logs, rate limits; GA Jan 2026), and is being absorbed into Palo Alto Prisma AIRS. Production $49/mo. Cloning “gateway + MCP + budget” is suicide.


Research error you must not inherit

research/competition.md says the remaining white space is “English allow/deny/ask + hard spend cap on the user’s keys + a receipt a third party can verify,” and names Preloop as the closest threat.

That table omits Permit.io MCP Gateway (permit.io/mcp-gateway, hosted at *.agent.security). Permit.io is a funded authorization company (SOC 2 Type II, free Community tier, Startup from $5/mo, Pro from $25/mo). The MCP Gateway is literally:

That is BRIEF candidate A and is Hallpass without the English textarea and the pretty /r/ page. “We are not enterprise GRC” is positioning, not a product. Permit.io already sells a hosted, self-serve, no-code MCP permit URL. If Hallpass ships as “paste your MCP URL, get a gateway,” the homepage is a worse app.agent.security.

Preloop is the second clone, not the first: Apache 2.0 MCP firewall, ordered allow/deny/require-approval/require-justification, YAML+CEL, human approvals (mobile/watch/Slack), model gateway with hard budgets, preloop agents discover rewires Claude Code/Cursor/Codex, one-line claude mcp add. GitHub ~62 stars (small), but the mechanism is complete. Their own docs show layered dollar rules on a pay tool (allow <$100, ask $100–$500, deny >$2,000). “English rules” is an LLM compiler in front of that YAML. Not a 90-day moat.

LiteLLM (53k+ stars, 240M+ Docker pulls) already ships hard $ caps that reject, not alert, plus an MCP gateway with six-level tool permissions and a Tool Permission Guardrail (regex allow/deny on tool name + argument patterns). Cloudflare AI Gateway has spend limits (429 or fallback) as of 9 Sep 2026. Token spend control is solved.

The research “intersection” argument is therefore false as a moat: Permit.io has the URL, Preloop has allow/deny/ask + budgets + approvals, LiteLLM/Portkey have BYOK $ caps, Obsigna/ProofAgent have receipts. Gluing them is a feature bundle, not a company.


Instant-kill clones (do not let PM “just add” these)

If the homepage, SDK, or pricing looks like any of these, KILL the pivot regardless of the idea name:

Shape Who already owns it Floor
Trace / span / session replay Langfuse, LangSmith, AgentOps, Phoenix, Datadog $0–$40
Prompt manager + datasets + LLM-as-judge Langfuse, LangSmith, Phoenix, Braintrust $0–$249
OpenAI-compatible proxy whose value is logs Helicone (frozen), LiteLLM, Portkey $0–$79
Virtual keys, fallbacks, cache, routing LiteLLM OSS, Portkey $49, Cloudflare $0
Agent SSO / first-class agent identity Okta Agent SSO, $0 extra $0
Enterprise agent control plane IBM Orchestrate $530+, Broadcom AgentMinder, Dataiku, WSO2 Agent Manager (GA 17 Sep 2026), AWS Bedrock AgentCore sales
MCP gateway / catalog / hosting Permit.io, Portkey, Obot ($35M seed), LiteLLM, Docker MCP Gateway, Microsoft Foundry AI gateway $0–sales
MCP firewall as control plane Preloop, Cordon, mcp-doorman, mcp-restrictor, Microsoft Agent Governance Toolkit MCPGateway $0 OSS
“We make you AI Act / SOC2 compliant” Preloop already warns against this; BRIEF forbids it

Safe to borrow as an implementation detail, never as the product: hash-chained signatures (Obsigna pattern), OTel export out to Langfuse, BYOK.


Agentic ideas

1. Hallpass — KILL (as specified)

Claim. One hosted MCP URL. English rules. Allow/deny/ask. Cap dollars on your key. Signed shareable receipt. Let’s Encrypt for agent permissions.

This is Permit.io MCP Gateway + Preloop + a receipt skin. The inventor’s own failure mode is the verdict: “if the homepage says ‘MCP gateway’ instead of ‘English rules + receipt’, we are a worse MintMCP.” The spec is a gateway: “Paste one MCP URL into Cursor… Copy-paste https://cryptobook.space/mcp/{id}.”

Named competitors (mechanism, not vibes):

Competitor What they already ship that Hallpass duplicates
Permit.io MCP Gateway Hosted *.agent.security/mcp drop-in, 5-minute setup, allow/deny, consent/ask, trust ceilings, audit, Cursor/Claude snippets, free Community. Two dashboards (app.agent.security + app.permit.io) — heavy, but the job is identical.
Preloop OSS MCP firewall, allow/deny/ask/justify, CEL on args, hard model budgets, Slack/mobile approve, session ledger, one-command agent rewire. Example: dollar tiers on payments.
Portkey MCP Gateway Auth, per-user tool enable/disable, logs, rate limits, guardrails, budget limits on virtual keys (cost or tokens, weekly/monthly). Now Palo Alto. BRIEF-listed.
LiteLLM Hard max_budget reject; MCP allowed_tools / mcp_tool_permissions; Tool Permission Guardrail allow/deny + param regex. OSS $0.
mcp-doorman (Glama, 18 Sep 2026) One-command local proxy: glob allow/deny/approve, secret redaction, prompt-injection, rug-pull hash-pin, rate limits, MCP elicitation approval, JSONL audit. Zero infra.
Cordon (@getcordon/cli) Aggregating MCP proxy: allow/block/approve/read-only, Slack approval, sequence-aware, SQL-aware.
mcp-restrictor Default-deny YAML proxy; filters tools/list and re-checks tools/call.
Obot MIT MCP gateway + catalog + OAuth broker + audit; $35M seed; 14-day cloud trial.
Docker MCP gateway Cedar permit/forbid + @requireApproval (docs dated 12 Aug 2026).
Claude managed-agents Native always_allow / always_ask / server-eval permission policies (beta managed-agents-2026-04-01).
Agent Receipts / Obsigna, ProofAgent, agent-custody Signed hash-chained receipts; ProofAgent already has public proofagent.pro/receipt/… pages at $19/mo.

Why “English + receipts” is not a 90-day defense:

  1. English is a compiler. Preloop and Permit.io already have UI rule builders. An LLM that writes YAML is a weekend. The YAML will be the source of truth anyway (Hallpass even says so for EU disclosure). Incumbents add a textarea without changing their company.
  2. Dollar caps on an MCP-only hop are a lie. Hallpass admits it cannot see OpenAI/Anthropic invoices unless it sits on the LLM path or the user types a declared $/1k. Sitting on the LLM path = LiteLLM/Portkey/Helicone clone (BRIEF kill). Declared prices = a counter the user can game. Agent Wormhole (12 Sep 2026) measured 590 money-moving MCP tools, 88% unique names; their own name-list guard caught 13.4%. Do not market “$2 per session” as if it replaced the provider bill.
  3. Receipts are a protocol, not a SaaS. Obsigna (Apache-2.0, SDKs, MCP proxy, dashboard, updated 17 Sep 2026), OrgX Agent Work Receipt v0.1 (account-free), IETF draft-sahu-agent-action-receipts-00 (16 Aug 2026), ProofAgent ($19, public verify URL). Hosting /r/hp_7f3a is a weekend on top of an open spec. ProofAgent already did the “click a URL, see a receipt” aha.
  4. Time-to-first-permit is not 4 minutes vs 5. Permit.io is five minutes with an org. mcp-doorman is one command. Preloop is one claude mcp add. Hallpass’s 60-second playground is a demo on a fake filesystem, not enforcement on the user’s GitHub token. The moment you need a real upstream, you are in Permit.io’s onboarding.
  5. Cursor/Claude native policy is the existential 90-day risk Hallpass itself lists. Claude already defaults MCP toolsets to always_ask. OpenCode has allow/ask/deny in opencode.json. GitHub Copilot has org MCP allowlists (6 Aug 2026). The choke point moves into the client. A hosted URL the user must remember to paste loses by default.

KILL the hosted “paste MCP URL, we proxy it” product. That category is occupied by a funded IAM company, a Palo Alto gateway, an Apache-2.0 control plane, and several one-binary OSS proxies. Combining three occupied features does not create a fourth.

FIX path (only if PM still wants this job): see Slip at the end. Headline cannot contain “MCP gateway.” No token custody. No model proxy. Receipt + blast card are the product; policy is a compiler; enforcement is local.


2. BurnNotice — FIX (module, not the company)

Claim. Drop last night’s log/CSV. Circle the loop and the dollars. Optional kill-switch later.

Not a Langfuse clone if it stays a coroner. Langfuse/Helicone/AgentOps want instrumentation before the fire. The job “the fire already happened on an un-instrumented laptop” is real (Revenium/ZDNet-class $3.7k–$47k loops; OpenAI’s hard spend limit is gone; Google “budgets” are alerts). File-drop in 60s, no SDK, is a legitimate aha.

Named competitors / death modes:

Competitor Overlap
Helicone Cost + request timeline via proxy. Maintenance mode, but the mental model is “see what burned.” If BurnNotice adds the “optional live tail proxy,” it becomes Helicone 2 — instant KILL under BRIEF.
Langfuse Core $29 Cost attribution per trace/user/feature once instrumented. Cheap default.
Provider consoles OpenAI/Anthropic usage CSV is the input. They will add loop clustering.
Claude Code /cost, Cursor usage In-client spend already exists for the hottest buyer.
LiteLLM spend reports /global/spend/report for anyone already on a proxy.

Why not SURVIVE as the company:

FIX, not KILL: keep the file-drop as a homepage module and a CI action (“fail if this JSONL contains a loop signature”). Do not productize a proxy. Do not add traces, evals, or prompt playgrounds. Do not promise provider-invoice accuracy. Monetize, if at all, as a GitHub Action on the same backend as Slip — not as a $29 coroner SaaS.


3. Permitfile — KILL as a product

Claim. Dependabot for MCP tools: agent-permit.yaml in the repo, GitHub App shames the PR, hosted URL enforces it.

Named competitors:

Competitor What they already ship
GitHub Copilot (6 Aug 2026) Enterprise/org allowedMcpServers. Server-level, not per-tool — the inventor is right — but GitHub adding per-tool is a one-quarter copy, not a 12-month copy. They own the PR surface.
Microsoft APM apm-policy.yml Org-global YAML, auto-discovered from git remote, allow/deny MCP servers and transports, enforcement: block. Docs 15 Sep 2026.
agentperms mcp.policy.yaml, scan / lock / record / infer / enforce. Least-privilege generated from traces.
agents-spec / agent-perms Vendor-neutral .agents/permissions.json across Claude Code, Codex, OpenCode, Crush, Cursor.
Preloop Policy-as-code YAML in git, validate, diff, apply.
OpenCode permission allow/ask/deny in opencode.json, per-agent overrides.
Claude Code Native permission policies.

Dependabot worked because GitHub was the runtime. Permitfile’s runtime is a hosted MCP URL the IDE can bypass with stdio. The inventor admits this. A bot comment without enforcement is a linter; paid linters die to mcp-scan in CI (Snyk, free). A bot comment with enforcement is Hallpass again — Permit.io clone, plus a GitHub App security review.

Viral “every public MCP PR is an ad” is real distribution. It is not a product. Keep agent-permit.yaml as the file format for Slip. Do not build a second company around a GitHub App. GitHub will eat per-tool policy the way they ate Dependabot clones.


4. Rehearse — KILL as a product

Claim. Paste a task + tool catalog. Show the blast radius without calling any real server.

Named competitors: Claude Code plan/ask modes, Cursor plan, Codex, Copilot. Permit.io auto-classifies tools low/medium/high on import (delete/destroy = high). PolicyLayer already published a 32,820-server destructive-tool census. mcp-scan flags toxic flows. The emotional “your agent would delete 12 repos” is a landing-page animation, not a $29 subscription.

Plan ≠ reality (inventor admits). If the playground uses our LLM wallet, BRIEF kill (token reseller). If it is a scripted demo, it is marketing HTML. If it uses the user’s key to plan, we are a thin wrapper around the same model that would have planned inside Cursor.

KILL the SKU. Steal the jump-scare as a scripted homepage module for Slip. Label it “demo, not a proof.” No CI “golden plan” product — that is evals (Braintrust/Phoenix).


5. Workslip — KILL as a product

Claim. Client-readable signed timesheet of mixed human+agent labor. Verify URL. No escrow.

Named competitors:

Competitor Object
ProofAgent Public verify URL, SHA-256, $19/mo, “no code required.” Wrong object (GPS-tagged generic actions) but same aha.
Agent Receipts / Obsigna Open protocol, SDKs, MCP proxy, dashboard. Updated 17 Sep 2026.
OrgX Agent Work Receipt v0.1 Apache-2.0, account-free, portable intent/actor/actions/artifacts/cost.
agent-custody Signed receipts, Cedar, Merkle, provenance labels (attested/observed/claimed).
IETF draft-sahu-agent-action-receipts-00 16 Aug 2026. Offline-verifiable hash chain.
Hello.ai / PipeLab “Receipts or it didn’t happen” product copy.
Dropwatch MCP receipts $0.01 USDC/call — wrong rails, but the MCP receipt exists.

Freelance TAM is narrow (BRIEF already asked). Freelancers will not pay $29/mo to defend a rate when they can paste a Git log. Clients who ask “did a human look” want the PR + tests, not a pink verify page. Signature proves Workslip ingested a file at time T, not that the work is good (inventor admits). The moment copy says “proves the work,” FTC + UPL-adjacent — also a legal kill.

KILL the standalone. The receipt page is the viral artifact for Slip. Do not build invoice software. Do not add client logins, ratings, or “pay this invoice.”


6. SchemaPin — KILL

Claim. Hash-pin tool name+description+schema. Deny on silent rewrite. README badge.

Named competitors: Invariant Labs invented this attack class (tool poisoning, rug-pull). mcp-scan / Snyk Agent Scan does tool pinning and proxy guardrails; Snyk acquired Invariant (Jun 2025); CLI is free (uvx snyk-agent-scan). mcp-doorman hash-pins on first use and blocks swaps until re-pin — in the enforcement path, today. agentperms lock pins tool identity. A hosted badge is SSL Labs: free, no conversion. Qualys/Tenable already taught this lesson.

Benign description edits = noise. Fetching customer MCP URLs from this VPS = SSRF. A pinned malicious server stays malicious (inventor admits). Marketing “secure MCP” would be theater.

KILL. If Slip’s local PEP hashes the tools/list it saw, that is a checkbox, not a SKU.


Quantum lane — KILL (all of it)

Agree with ideas/quantum-ideas.md and research/quantum-market.md. Independent competition check:

ID Idea Verdict Why, named
Q1 / BRIEF D Circuit classroom KILL IBM Composer (free, visual, real or sim backends). IBM Quantum Learning (free courses). Classroom Accounts (28 May 2026): 5–100 students, no card, real QPUs, 10 min/student/month. Quirk. Qiskit textbook. Cannot beat free + real hardware + IBM credential.
Q2 Hosted Aer KILL pip install qiskit-aer. IBM Open Plan unlimited simulators. This box caps ~31–32 qubits statevector. A workstation.
Q3 BYO-key QPU proxy KILL qBraid ($0/$20/$100), Strangeworks, Classiq ($200M+, AWS Marketplace), AWS Braket, Azure Quantum. Also a key-custody honeypot.
Q4 Cost estimator KILL IBM Platform estimates QPU-seconds. quantumcomputingcost.com tables. Not SaaS.
Q5 Quantum spend receipts KILL IBM Open Plan already caps. PayGo users have IBM Cloud/AWS billing alerts. Tiny TAM. Same clone as Hallpass, worse buyer.
Q6 Advantage honesty analyzer KILL No WTP. IBM Advantage Tracker / Benchpress / MQT already exist for researchers.
Q7 Quantum-inspired optimizer KILL Theater vs Gurobi / CPLEX / OR-Tools / HiGHS. Constraint 7.
Q8 QRNG / QKD KILL Hardware or /dev/urandom in a lab coat. ANU QRNG, Cloudflare. Theater.
Q9 VQE / chemistry toy KILL Novo’s application layer is Phasecraft / Algorithmiq / QunaSys with QPUs and PhDs. 32-qubit VQE does not change an experiment. Zapata (hardware-agnostic software) → $0 revenue 2025/H1 2026.
Q10 PQC scanner KILL Off-mission (cryptography, not QC). Cloudflare Radar, Qualys SSL Labs, testssl.sh, IBM Quantum Safe Explorer, SandboxAQ, PQShield. Scanner monetization is historically terrible. “Quantum-safe” badge = theater.

Novo Holdings (11 Sep 2026) does not rescue a VPS: ~70% of $13.9B went to hardware; general developer tools “struggle to capture lasting value” because clouds bundle them; investable apps are multi-year scientific embeddings. IBM Starling is 2029. Vendor revenue ~$1.8B (2025), QCaaS $0.25B. Demand is minutes on someone else’s fridge.

Do not put “quantum” on the homepage to sound 2026. That is constraint 7.


BRIEF candidates A–E (if PM reads the brief, not the idea files)

Candidate Verdict One line
A Permit gateway KILL as a hosted MCP/LLM proxy Permit.io + Preloop + Portkey + LiteLLM
B agent-permit.yaml runtime KILL as a standalone GitHub / Microsoft APM / agentperms; keep the file format
C Freelance receipts KILL as a standalone ProofAgent / Obsigna / OrgX; keep the /r/ object
D Quantum classroom KILL IBM free stack
E “more genius” SURVIVE only as Slip Below

Patched survivor — Slip (FIX of Hallpass that actually patches the kills)

BRIEF: if every idea is killed, invent one that patches the kill reasons.

Hallpass died because it is a gateway. Workslip died because receipts are a protocol. Permitfile died because GitHub owns PRs. BurnNotice/Rehearse/SchemaPin died as companies but are useful objects.

What Slip is

A policy compiler + public evidence object for people who already run coding agents this month.

  1. Homepage, no account, <60s. - Scripted Rehearse jump-scare on a pinned GitHub-MCP catalog (“this task wants delete_repo × 12”). - BurnNotice sample: one-click $3,762 loop autopsy (redacted, hashed args). - English box: never delete; ask before push; at most 20 tool calls / session. - Compiler shows the YAML (agent-permit.yaml) next to the English. YAML is source of truth. User can edit it. - Output: a Blast Card (/b/{id}) — tool list classified allow/deny/ask, destructive count, schema hashes — and a Receipt (/r/{id}) of the demo session. Both public, no login, signature verifiable in-browser.
  2. Paid conversion is not a proxy. - Copy a decision snippet: local stdio wrapper / Claude Code hook / base_url-free PEP that sends {tool, arg_hash, policy_id} and gets {allow, deny, ask} + a receipt id. - Cloud stores policy versions, hashes, and receipts. Never the model key, never GitHub/Slack tokens, never tool results, never prompt bodies. - Optional: user pastes a usage CSV into BurnNotice. Still no live LLM proxy.
  3. Honest spend. Cap tool-call counts and named denies, not “$2 of Anthropic.” If we cannot see the invoice, we do not print a fake dollar ticker as if we could. (That single sentence is what stops Hallpass from being a fraud next to LiteLLM.)
  4. Price. $0 watermarked receipts/cards. $19–29/mo unlimited personal receipts + policy history (under Langfuse Core’s $29 ceiling). $99 team: shared rulebook, webhook on ASK (email; Telegram later). Bill receipts/policies, not spans.
  5. Non-goals (printed on the homepage). Not an MCP gateway. Not an LLM proxy. Not SSO. Not a catalog. Not evals. Not traces. Not “AI Act compliant.” Not a legal attestation.

Why this is not the clones

Kill reason against Hallpass How Slip patches it
Permit.io is the one-URL MCP proxy We do not proxy customer MCP servers or hold upstream OAuth. Different category. Permit.io’s buyer is IAM; two dashboards. They will not become a public /r/ + /b/ for freelancers this quarter.
Preloop is the OSS firewall + budgets Preloop is a control-plane install (CLI, CEL, operator console, ~62 stars, no 60s playground, unpublished cloud price). Slip is a browser object. If we ship YAML+CEL and a Grafana, we become Preloop and die.
Portkey/LiteLLM are BYOK $ caps + MCP gateways We never sit on chat/completions. BRIEF-safe. No virtual keys, no routing, no cache.
mcp-doorman is a free local proxy They have JSONL on disk, not a forwardable page. We can tell the user to run their PEP; we sell the card/receipt and the English compiler.
Obsigna/ProofAgent own receipts ProofAgent is generic GPS hashes. Obsigna is a spec for tinkerers. The object we host is policy + blast radius + hashed decisions a non-engineer can read. We should emit Obsigna-compatible JSON, not invent a fifth protocol.
Langfuse/Helicone No traces, no spans, no prompt store. BurnNotice is upload-and-delete forensics, hashed.
Okta/IBM No identity, no agent directory, no RFP.
GitHub Copilot allowlists We don’t fight GitHub for org policy. Repo YAML is an export, not the company.
Fake $ caps We don’t claim them.

90-day defensibility (honest)

Survives 90 days if the site is a playground that produces a card and a receipt without an account, and paid users get history + webhooks, and we never hold secrets.

Dies in 90 days if:

What we steal from the killed ideas (one VPS process)

Killed idea Keep as
Hallpass English rules Compiler only; YAML shown
Permitfile File format agent-permit.yaml; no GitHub App in v1
Workslip Skin on /r/ (“share with a client”)
Rehearse Scripted homepage jump-scare
BurnNotice Sample + optional CSV drop; CI later
SchemaPin Hash the catalog on the blast card; no badge SKU

That is still one Node/Python app behind nginx: compiler, signer, static playground, Postgres for policy versions and receipt hashes.


PM-facing recommendation (competition only)

  1. Do not build Hallpass-as-spec. It is Permit.io with a pink theme. Research that called this “white space” missed Permit.io MCP Gateway. That error would ship a me-too.
  2. Do not build any quantum SKU. Confirmed kill by market, IBM’s free stack, and honesty.
  3. Do not build Langfuse/Helicone/Portkey/Okta/IBM shapes even as “just v2.”
  4. Build Slip, or kill the pivot. If the first sprint is an MCP reverse proxy, the competition verdict flips back to KILL.
  5. Price under $29. Langfuse Core is the psychological ceiling for infra the user is not sure they need.
  6. One-sentence test: If we cannot explain how we are not Permit.io, Preloop, and Portkey in one sentence, we are dead.

Slip: a public blast-radius card and a signed decision receipt for your coding agent, from English rules, without becoming your MCP gateway, your LLM vendor, your IdP, or your auditor.

If that sentence is not on the homepage, this file’s verdict is KILL the pivot.