Agent♥︎Age
Catalog

io.github.tomjwxf/protect-mcp

Official

by ScopeBlind · TypeScript

Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.

io.github.tomjwxf/protect-mcp MCP Server

The io.github.tomjwxf/protect-mcp MCP server provides a gate for AI agent tool calls, evaluating each call against Cedar policies and producing signed receipts. It is described as a fail-closed policy gate plus signed receipts, and it is used as a Claude Code hook and an MCP gateway.

🛠️ Key Features

  • Fail-closed Cedar policy gate for tool calls
  • Signed receipts for AI agent tool calls
  • MCP gateway integration
  • Mentions access-control, audit-trail, policy-engine, and rate-limiting
  • Topics include ed25519, IETF, zero-trust, and access control

🚀 Use Cases

  • Enforce Cedar policies before allowing tool execution by AI agents
  • Track and verify tool-call outcomes via signed receipts
  • Use as an MCP gateway for agent tool access control
  • Support environments integrating Claude Code, Claude Desktop, and Cursor

⚡ Developer Benefits

  • Centralized policy evaluation using Cedar
  • Signed-receipt verification for audit-trail workflows
  • Aligns with zero-trust and access-control requirements
  • Includes references to gateway and policy-engine patterns

⚠️ Limitations

  • Limited description provided beyond Cedar gating, signed receipts, and gateway/hook roles; specific runtime behavior is not detailed in the excerpt.

Topics

mcpcloudflare-workersgatewayaccess-controlai-agentai-securityaudit-trailcedarclaude-desktopcursored25519ietfmcp-serverpolicy-enginerate-limitingsigned-receiptszerozero-trust

Related servers

More in Security