Skip to main content
Glama
┌┬┐┌─┐┌─┐┬ ┬┌─┐
│││├┤ └─┐├─┤  │   agents ──▶ mesh7 ──▶ tools
┴ ┴└─┘└─┘┴ ┴  ┴   policy · approval · trace

flux7-mesh

GitHub release CI Go License

A governance proxy between AI agents and their tools. Policy, human approval and signed traces on every tool call, without changing agent code.

One Go binary, one YAML file, fail closed. Works with Claude Code, Cursor, Anthropic Managed Agents, the Agent SDK, LangChain, or anything that calls tools over MCP, HTTP or a CLI.

Full documentation: docs.flux7.art/mesh7

What it does

Policy

Allow, deny or ask, per agent and per tool: globs, conditions on arguments, per-agent files, hot reload. Writing policies

Human approval

A call that needs a human waits in a queue (terminal, CLI, HTTP, console); time-boxed grants act as sudo for agents. Approval flow

Emergency stop

Stop every call of one agent, one session or everything at once; pending approvals are denied, grants revoked and put back on resume. CLI, HTTP and console. Emergency stop

Traces

Every call and decision, grouped by session, HMAC hash-chained and verifiable, exported over OTLP. Trace integrity · Observability

Tool catalogue

Each tool classified (named or generic, read or write) from what it declares; a draft policy from discover; per-agent decisions; one tool's action changed from the control plane. Opt-in: pin upstream catalogues against silent changes, hide what can only be denied. Tool classification

Identity

JWT from your IdP, including the human an agent acts for. JWT authentication

Delegation

Past decisions auto-approve through flux7-memory; an L1 supervisor resolves the rest through flux7-supervisor. Memory integration

Provenance

Every call to an MCP upstream carries its trace in _meta, and the authenticated agent for upstreams that opt in (forward_identity): mem7 signs, chains and scopes memories with them. GET /traces?trace=<id> follows a memory back to its call. mem7 provenance

Related MCP server: agent-sudo-mcp

How it sits

flowchart LR
    A["Agents<br/>Claude Code · Cursor · Agent SDK<br/>LangChain · Managed Agents"]
    M["mesh7<br/>identity → rate limit → policy<br/>→ approval → forward → trace"]
    T["Tools<br/>MCP servers · REST APIs (OpenAPI)<br/>CLI binaries"]
    O["Traces<br/>JSONL · OTLP"]
    A -- "MCP stdio / HTTP · HTTP" --> M --> T
    M --> O

Agents see an ordinary tool surface. The operator sees every decision.

Install

curl -fsSL https://raw.githubusercontent.com/KTCrisis/flux7-mesh/main/install.sh | sh

Installs mesh7 (the proxy) and mesh (the approval CLI) in ~/.local/bin. Add -s -- --service to also run mesh7 as a systemd user service, or --system where the user manager is unavailable (some WSL setups). By hand:

curl -L https://github.com/KTCrisis/flux7-mesh/releases/latest/download/mesh7_linux_amd64.tar.gz | tar xz
sudo mv mesh7 mesh /usr/local/bin/

Other targets: mesh7_darwin_arm64.tar.gz, mesh7_linux_arm64.tar.gz, mesh7_windows_amd64.zip… (releases). From source (Go 1.24+): make install. Python SDK and the Claude Code harness hook: pip install flux7-mesh (Python SDK).

Quick start

# config.yaml
mcp_servers:
  - name: filesystem
    transport: stdio
    command: npx
    args: ["-y", "@modelcontextprotocol/server-filesystem", "/home/me/projects"]

policies:
  - name: claude
    agent: "claude"
    rules:
      - tools: ["filesystem.read_*", "filesystem.list_*"]
        action: allow
      - tools: ["filesystem.write_file", "filesystem.edit_file"]
        action: human_approval
  - name: default
    agent: "*"
    rules:
      - tools: ["*"]
        action: deny
mesh7 discover --config config.yaml --generate-policy   # or start from a commented draft
claude mcp add mesh7 -- mesh7 --mcp --config config.yaml

Restart Claude Code: the tools are there, the rules apply, every call is traced. When a call needs approval, the agent relays an id: run mesh approve <id> (or use the console), and its retry of the same call goes through. For a long-running daemon, OpenAPI and CLI sources, and every YAML key, see Getting started and Configuration.

Documentation

Next

  1. Policy on the delegation: rules on the pair this agent, for this user, from the identity the token already carries.

  2. Conditions v2: AND/OR, claims from the token, parsed arguments instead of text matching.

  3. Policy on content: a local classifier annotates arguments and results (indirect injection first); the condition engine decides.

Shipped features are listed per version in the releases.

Why a mesh

Envoy sits between services and adds identity, policy and telemetry without changing their code. mesh7 does the same between agents and their tools: invisible to the agent, visible to the operator.

License

Apache 2.0

Maintenance

ActivityActive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Security, cost, and health governance proxy for MCP infrastructure. Enforces YAML-configurable security policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features OAuth 2.1/OIDC with RBAC, web dashboard, payload normalization, semantic shell AST analysis, mTLS, and a formal STRIDE threat model.
    4
    76 npm
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Local zero-trust permission gateway for AI agents. Enforces policy-based tool authorization, human approvals, scoped permissions, and cryptographically verifiable audit logs.
    4
    39 PyPI
    5
    Apache 2.0
  • F
    license
    A
    quality
    A
    maintenance
    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or HTTP/SSE) and blocks destructive tool calls before they execute, with TOFU catalog pinning against rug pulls and tool-poisoning/result-injection scanning. Single Rust binary, Apache-2.0.
    14
    11
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    A minimal guardrails framework for AI agents, acting as an MCP proxy to enforce policies, approvals, and audit logging on tool calls.
    1
    MIT