Skip to content
PERMISSION/PROTOCOL
← Integrations

MCP Guard setup path

Put policy on the MCP server path you control.

MCP Guard evaluates tools/call requests passing between a client and its configured stdio server. Start with one server and a small set of tool rules.

What setup requires.

  1. 01

    Choose a stdio MCP server and confirm how the client launches it.

  2. 02

    Run the server through MCP Guard and review decisions in observe mode.

  3. 03

    Enable the approval UI for held calls, then switch to enforcement.

  4. 04

    Test allowed, blocked, approved, denied, and timed-out calls using the installed version.

Coverage and limits.

  • Observe mode forwards calls without blocking.
  • Without the approval UI, require-approval calls return a hold error.
  • Local decision records and independently signed authority receipts are different evidence formats. Confirm what your workflow needs.

Have a different execution path?

Bring the action, target system, and required evidence. We can assess the integration work before you commit to a rollout.

Discuss your workflow