Skip to content
PERMISSION/PROTOCOL

MCP Guard · Open source

MCP authorization for your agent’s tool calls.

MCP Guard is an open-source stdio MCP proxy. Check routed tool calls against your policy before they reach the server: allow, block, or require a human decision.

What you are connecting

Your MCP client → MCP Guard → your stdio MCP server.

Start on a test server, review the decision log, then enable the rules you need.

Policy preview
Example actiondeploy_production
  1. Tool call requested

    The client routes the call through the proxy.
  2. Policy requires approval

    Enforce mode holds the routed call.
  3. Human approves

    The configured approval UI records the decision.
  4. Call forwarded

    The stdio server receives the approved call.
Tool call requested
Illustrative enforce-mode flow with the approval UI configured. No actions are sent.

The protected path

MCP server access and tool-call approval

MCP authorization can refer to access tokens for an HTTP server. MCP Guard works on configured stdio routes, where it evaluates the requested tool and arguments. Keep the server’s credential controls and add rules for the actions that need review.

Choose the calls that need a decision

For example, your policy can allow a read, block a destructive tool, and hold a production deployment for human approval. In enforce mode, the configured proxy applies the decision before forwarding the call. Test each outcome on your own tool path.

Read the MCP policy enforcement guide

From setup to a tested decision

Connect one workflow, then verify it.

  1. Choose the server path

    Use a stdio MCP server you can launch through the proxy. Update the client configuration so calls use that path.

  2. Define and observe the rules

    Match tool names and arguments to allow, block, or require approval. Observe mode logs decisions while forwarding calls.

  3. Enable approval and test enforcement

    Enable the local approval UI for held calls. Switch to enforce mode and test allowed, blocked, approved, denied, and timed-out calls.

npm install @permission-protocol/mcp-guardnpx mcp-guard --config pp.config.yaml --mode observe -- node my-mcp-server.js# After reviewing your rules, enable enforcement and the local approval UI:npx mcp-guard --config pp.config.yaml --mode enforce --approval-port 3100 -- node my-mcp-server.js

Replace the example server command and tool names with your own. Review your package version’s setup instructions before running it.

Scope and boundaries

What this controls, and what it doesn’t.

  • Only calls routed through the proxy are evaluated. Direct credentials and other tool paths remain outside it.
  • Observe mode does not block. Without the approval UI, a require-approval rule returns a hold error rather than opening an approval session.
  • Local JSONL decision records include payload hashes. A hash alone is not a cryptographic signature or independent proof of human authorization.
  • Confirm the transport, package version, record fields, and signing requirements for your deployment.

The record behind the decision

Decide what evidence you need.

Match the record format to your review requirements. If you need independently signed human-approval evidence, confirm that requirement and the signing integration before rollout.

How to choose which AI actions need human approval

Your first workflow

Ready to test your first workflow?

Work through setup, approval, denial, and evidence inspection. Keep track of your checks before expanding the rollout.

Open the test checklist