writ-mcp
The Writ gate as an MCP server. Give any MCP-compatible
agent commit-time control: the agent calls Writ before a consequential
write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an
audit receipt.
Install
Requires Python 3.9+. Installs the writ-mcp command (stdio transport).
export WRIT_API_KEY="writ_..."
export WRIT_SPONSOR_TOKEN="..."
Add to your agent
Claude Code:
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp
Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"writ": {
"command": "writ-mcp",
"env": { "WRIT_API_KEY": "writ_..." }
}
}
}
Any MCP client (generic stdio config):
{
"command": "writ-mcp",
"env": {
"WRIT_API_KEY": "writ_...",
"WRIT_SPONSOR_TOKEN": "writ_sp_..."
}
}
Hermes (NousResearch/hermes-agent) catalog entry โ once published, this
package is installable from the optional-mcps catalog:
The check-before-write loop
The tool descriptions teach the agent this flow, but the short version:
writ_check(sponsor_id, agent_id, verb, target, purpose) โ before the write.
ALLOW โ you get a 90-second authToken bound to that exact write.
writ_verify_token(auth_token, verb, target, purpose) โ immediately before
executing, to prove the authorization still matches what you're doing.
DENY โ do not proceed. STEP_UP โ a human sponsor approves
(via writ_grant or the dashboard), then check again.
| Tool | Who | What |
|---|
writ_check | agent | Decision + 90s purpose-bound token |
writ_verify_token | agent | Commit-time token verification |
writ_grant | sponsor | Approve a STEP_UP (one-time grant) |
writ_revoke / writ_reinstate | sponsor | Kill switch on/off for a principal |
writ_receipts | agent | Audit trail of decisions |
writ_policy | agent | Tenant verb policy |
writ_sandbox | anyone | Free 90-second demo grant, no key needed |
Try it with no key: writ_sandbox โ writ_check with verb="demo_write".
Source
Public repo: AvenueDAdmin/pywrit (mcp/
directory). License: MIT.