CAIN42-PROOF-PACKAGE: MCPGate enforcing LIVE consensus authorizations, 2026-09-27. Self-attested.

Authorizations were committed by the live CAIN-42 cluster cain-mr-02 (4 PBFT replicas on 4 servers in
4 regions: Atlanta, Los Angeles, Miami, Silicon Valley). Every tool call was sent over HTTP through the
MCPGate proxy (the consensus authorization gate in front) to a separate MCP server process. Whether a
call ran is taken from that server's own execution log, and each effect was checked by re-reading the
server's state. 5 authorized calls ran. 12 attacks were blocked, each with a signed denial returned to
the caller: replay, action substitution, tool substitution, capability escalation, identity
substitution, security-context drift, forged quorum certificate, forged certificate body,
post-consensus mutation of the authorized action, a certificate from another cluster (cain-mr-01),
no authorization, expired authorization.

Verify with one command (Python 3.8+, pip install cryptography, no CAIN code):

  BASE=https://cainstudio.online/proof/bundle/mcpgate-live-2026-09-27
  mkdir -p pkg/verifiers && cd pkg
  for f in calls.json cluster_commits.json gate_proofs.json manifest.json mcp_server_executed.json membership.json sandbox_state.json ; do curl -so $f "$BASE/$f"; done
  for v in cain_proof_verify verify_pbft_qc_bundle verify_dag_bundle; do curl -so verifiers/$v.py "$BASE/verifiers/$v.py.txt"; done
  python3 verifiers/cain_proof_verify.py .        # expect FINAL RESULT: VERIFIED

Change any byte and the result is INVALID.
Not claimed: that cainstudio.online enforces this gate on customer tool calls; a customer MCP server
(the downstream is a sandbox key-value server); hardware attestation; independent operators or
providers; third-party review. Source is not published (git commitments in manifest.json).
