Security gateway for MCP servers.
Shadow-mode logs. Per-tool policies. Optional signed receipts.
Website · MCP Docs · npm · Verify a Receipt · The Stack
Start with visibility. Add control when ready. Sign when you want proof. Each step is independently valuable.
# 1. Shadow — see what's happening (blocks nothing)
npx protect-mcp -- node your-server.js
# 2. Simulate — test a policy against recorded tool calls
npx protect-mcp simulate --policy strict.json
# 3. Enforce — apply the policy
npx protect-mcp --policy strict.json --enforce -- node your-server.js
# 4. Sign — generate keys, produce signed receipts
npx protect-mcp init
# 5. Report — generate a compliance report
npx protect-mcp report --period 30d --format md --output report.md
# 6. Verify — prove it to anyone, offline
npx @veritasacta/verify --self-test- Shadow mode (default) — logs every tool call, blocks nothing
- Enforce mode — per-tool policies:
block,rate_limit,min_tier,require_approval - Approval gates — high-risk tools pause for human approval (non-blocking, request_id scoped)
- Optional local signing — Ed25519-signed receipts for every decision
- Simulate — dry-run a policy against your recorded log before enforcing
- Report — compliance report from receipts (JSON or Markdown)
- Bundle export — self-contained audit bundles with embedded verification keys
- Demo —
npx protect-mcp demoruns a built-in MCP server with the gateway - Verification —
npx @veritasacta/verify --self-test(MIT, offline, no accounts)
- Bare
npx protect-mcp -- ...logs decisions without signing. Runprotect-mcp initfor signed receipts. - Trust tiers are live but manifest admission defaults to
unknownunless set programmatically. - External PDP adapters (OPA, Cerbos) and credential vault are exported as programmatic hooks.
{
"tools": {
"delete_database": { "block": true },
"send_email": { "require_approval": true },
"write_file": { "min_tier": "signed-known", "rate_limit": "10/minute" },
"*": { "rate_limit": "100/hour" }
},
"signing": {
"key_path": "./keys/gateway.json",
"enabled": true
}
}{
"mcpServers": {
"my-server": {
"command": "npx",
"args": ["protect-mcp", "--policy", "protect-mcp.json", "--enforce", "--", "node", "my-server.js"]
}
}
}Works with Claude Desktop, Cursor, VS Code, OpenClaw — any client that speaks MCP over stdio.
ScopeBlind is part of a three-layer evidence infrastructure. Each layer is independently useful and survives the failure of every other layer.
| Layer | What | License |
|---|---|---|
| BlindLLM | Coordination lab — blind AI battles, agent studio | blindllm.com |
| ScopeBlind | Commercial enforcement — policies, receipts, approval gates | FSL-1.1-MIT |
| Veritas Acta | Open evidence protocol — format, verifier, constitution | MIT |
Source-available under the Functional Source License (FSL-1.1-MIT). Free to use, modify, and self-host. You may not offer a competing hosted service. After 2 years, each version converts to MIT. Verification tools (
@veritasacta/verify,@veritasacta/protocol) are MIT from day one.
Built by tomjwxf