Skip to main content
Glama

Related Servers

Alternatives to opa-mcp-server

  • A
    license
    Not graded
    quality
    C
    maintenance
    A Model Context Protocol (MCP) server that provides safe, read-only access to Kubernetes resources for debugging and inspection. Built with security in mind, it offers comprehensive cluster visibility without modification capabilities.
    43
    MIT

Related Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    An MCP server that enforces authorization by evaluating Rego policies or querying an OpenID AuthZEN-compliant PDP, providing accurate access decisions for AI agents. It includes tools for policy evaluation, AuthZEN evaluation, batch evaluation, and PDP discovery.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables developers to wrap existing MCP servers with a deterministic policy enforcement gate that intercepts tool discovery and tools/call requests over stdio, allowing only authorized calls to reach the downstream server. It supports dynamic tool exposure or hiding, allow/deny/approval-required decisions, configurable error disclosure modes, and Ed25519-signed retry credentials for approved workflows.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enforces deterministic security policies as an inline firewall for MCP server tool calls, with AST-based validation, cryptographic audit logging, and CLI-based evaluation and verification.
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    A specialized MCP server that provides expert-level OpenFGA authorization modeling guidance, enabling users to create and manage authorization models for ReBAC systems directly from VS Code.
    2
    9
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that exposes governance, trust-scoring, compliance, guardrail, cost, drift, and supply-chain scanning tools and resources to any MCP client over stdio, Streamable HTTP, or legacy HTTP+SSE. It lets agents route every tool call through a deterministic five-way decision (allow, redact, require approval, deny, or quarantine) with hash-chained evidence, human approval workflows, and in-agent trust gates for LangChain, LangGraph, and Google ADK.
    30
    53 PyPI
    2
    MIT

TDQS

A3.7/5.0

Scored across 52 tools

Disambiguation3/5

The toolset spans many domains, but several clusters blur boundaries: rego_eval/opa_exec/opa_query_decision/rego_compile_query/opa_compile_query all evaluate or compile policies in different local/server contexts, and rego_eval_with_explain/rego_explain_decision/rego_explain_undefined overlap in tracing. opa_config and opa_status return the same configuration document under different keys, adding a redundant choice. Descriptions mitigate much of this, so the set is manageable but not cleanly disambiguated.

Naming Consistency4/5

Names consistently use snake_case with clear domain prefixes (rego_, opa_, conftest_, mcp_), which creates predictable grouping. However, several names use noun/state forms (rego_capabilities, rego_deps, opa_health, mcp_server_info) rather than a strict verb_noun pattern, and the eval/explain variants append qualifiers, so naming is mostly rather than fully consistent.

Tool Count1/5

52 tools is far beyond the 3-15 well-scoped range and triggers the rubric's 50+ extreme-mismatch category. Although OPA is broad, many tools are narrow variants (three explain/eval flavors, separate local/server compile, format vs format_write, etc.), so the surface is bloated rather than each tool earning a distinct place.

Completeness5/5

Coverage is excellent: policy CRUD and data CRUD on the server, local authoring/format/lint/check/test/coverage/benchmark, bundle build/sign/verify, Conftest integration, schema inference/validation, migration, diff, and formal verification. Almost every lifecycle stage an OPA agent would need has a tool; any missing pieces (e.g., server start/stop) are plausibly out of scope.

Maintenance

ActivityActive
ResponsivenessNo issues