mcpcut
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcpcutapprove the pending write to the filesystem"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcpcut
See every tool call your AI agent makes over MCP, hold the risky ones for your approval, and keep a secret-redacted journal that is tamper-evident with an external anchor.
Self-hosted · Apache-2.0 · Node.js 24+ · two runtime dependencies. Start with one server on your laptop; grow into a control plane for many agents.

Quick start
Requires Node.js 24+ (node -v); on older Node, mcpcut prints one line and exits — install Node 24 with nvm, fnm or volta. Nothing else to install.
See. Put mcpcut in front of a server — here for Claude Code; in any other client, the server's command becomes npx -y mcpcut@0.1.2 wrap -- <your server>:
claude mcp add fs -- npx -y mcpcut@0.1.2 wrap -- npx -y @modelcontextprotocol/server-filesystem ~/projectThe first start downloads mcpcut and the server; if your client gives up on it, start it once more. Let the agent work, then npx -y mcpcut@0.1.2 sessions and npx -y mcpcut@0.1.2 show <id>: every request, response and decision, secrets redacted.
Stop. Save this as policy.json — reads pass, everything else waits for you (quarantine of new tools is off, so the first minute shows one gate: see Quarantine) — and re-add the server with --policy "$PWD/policy.json" right after wrap (claude mcp remove fs first):
{ "version": 1, "defaultDecision": "require-approval", "classDefaults": { "read": "allow" },
"quarantine": { "enabled": false } }A write now waits. Approve it from another terminal within the agent's wait (60 s; after it, the agent's retry passes) — no token needed until you add your first admin (Approvals):
npx -y mcpcut@0.1.2 approvals list
npx -y mcpcut@0.1.2 approvals approve <id>Prove. Sign the history, export it, and check it offline — with nothing but the directory:
npx -y mcpcut@0.1.2 keygen && npx -y mcpcut@0.1.2 export --report --out ./report
npx -y mcpcut@0.1.2 verify --report ./reportRecord the chain head somewhere this host cannot rewrite — the out-of-band anchor is what makes the journal tamper-evident, not the hashes alone.
Grow. npm install -g mcpcut, then mcpcut: a setup wizard, then a server registry, per-agent keys and grants, a credential vault, a web UI, a terminal console and one address per agent (Install and first run).
Related MCP server: enterprise-agent-lab
What you get
Journal — every request, response and decision, with secrets redacted before anything is written. Optionally fail-closed: no record, no call.
Policy per tool —
allow,denyorrequire-approvalby server, tool name or tool class; read-only tools can pass on their own.Approvals — a risky call waits until someone approves it from the CLI, the web UI or the terminal console.
Quarantine — a new tool, or one whose description or schema changed after you trusted it, is held until reviewed, with a diff of what changed.
Agents and grants — a registry of servers, a key per agent, per-tool grants, groups, and an encrypted vault, so server credentials never sit in an agent's config.
One address per agent — every server an agent is granted behind one endpoint; grant or revoke without touching the client.
Evidence — a hash chain with a signed head, and an audit report anyone can verify offline with a public key.
Admin UI and terminal console — named admins with
owner,operatorandviewerroles; every change is attributed in the journal.
How it works
AI agent ── stdio or HTTP ──▶ mcpcut ──────────────────▶ MCP servers
(Claude Code, grants → policy → (filesystem,
Cursor, …) quarantine → approval GitHub, …)
│
▼
journal.db — redacted, hash-chained
│ export --report
▼
verify offline, anywhereThree ways in, one gate:
wrap— in front of one server, with no setup and no identity: the Quick start above.connectandserve— named servers from the registry, a key per agent, credentials from the vault.The pool (
/mcp) — one address per agent for every server it is granted;connect --urlbridges a stdio client on another machine to it.
The full picture, with the trust boundaries: docs/ARCHITECTURE.md.
Documentation
Guide | Covers |
npm or source, the setup wizard, the first owner, reaching the service by IP | |
| |
| |
servers, agent keys and grants, groups, revoking access, the vault | |
| |
the web console, admins and roles, its threat model | |
| |
| |
| |
every command and flag | |
what is shipped, and the evidence behind each line |
Status
mcpcut is 0.x. The core — proxy, policy, approvals, quarantine, journal, audit report, admin UI and console — is shipped and covered by tests; Status lists each capability with its evidence.
Preview: the remote console (
mcpcut --remote) and theconnect --urlbridge. They work and are tested against a VPS over TLS, but they put a token on the network, have had only an internal security review, and may change within 0.x.Tamper-evident means with an external anchor. A process running as the same OS user can rewrite the journal and re-sign it; only a chain head recorded somewhere this host cannot write exposes that. mcpcut is not tamper-proof, and whether a report satisfies an audit is the auditor's call.
Security
Please report vulnerabilities privately — SECURITY.md says how. The whole product had an internal security audit in September 2026; no independent audit has been done yet.
Contributing
Issues and pull requests are welcome — see CONTRIBUTING.md.
License
Apache-2.0 — see NOTICE.
This server cannot be deployed
Maintenance
Related MCP Connectors
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Runtime permission, approval, and audit layer for AI agent tool execution.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceProvides a secure MCP boundary for AI agents, intercepting and validating tool calls, redacting secrets, and requiring human approval for sensitive actions with a tamper-evident audit trail.-
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.1-
- AlicenseNot gradedqualityCmaintenanceProvides permission gates and tamper-evident audit logging for AI agent tool executions, with declarative policies, consent ladders, and hash-chained verification.MIT

agentguardofficial
AlicenseNot gradedqualityCmaintenanceEnforces policy controls for AI agents, including spend limits, action approvals, kill switch, scoped credentials, dry-run diffs, loop prevention, and auditable hash-chained logs.MIT