Skip to main content
Glama
declaw-ai

declaw-mcp-server

Official
by declaw-ai
README.md
# Declaw MCP Server

MCP server for [Declaw](https://declaw.ai) — secure sandbox execution for AI agents with network policies, PII scanning, prompt injection defense, and audit logging.

Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool.

## Quick Start

### Claude Desktop / Cursor / Windsurf

Add to your MCP config:

```json
{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key"
      }
    }
  }
}
```

### Claude Code

```bash
claude mcp add declaw -- npx -y @declaw/mcp-server
```

Set `DECLAW_API_KEY` in your environment.

## Tools

| Tool | Description |
|------|-------------|
| `create_sandbox` | Create a secure sandbox with configurable security policies |
| `run_command` | Execute a shell command inside a sandbox |
| `read_file` | Read a file from a sandbox |
| `write_file` | Write a file to a sandbox |
| `list_files` | List directory contents in a sandbox |
| `kill_sandbox` | Destroy a sandbox |
| `list_sandboxes` | List all active sandboxes |

## Security Presets

When creating a sandbox, choose a security preset:

- **`none`** — No guardrails. Full internet access.
- **`standard`** (default) — PII scanning + audit logging. Full internet access.
- **`strict`** — PII scanning + prompt injection defense + audit logging + network deny-all.

You can also pass `allowed_domains` to restrict outbound traffic to specific domains:

```
create_sandbox with template="python", security_preset="strict", allowed_domains=["pypi.org", "github.com"]
```

## Why Declaw?

| | Declaw | Other Sandbox Providers |
|---|---|---|
| Sandbox execution | Yes | Yes |
| Non-bypassable network controls | Yes | ?? |
| PII scanning | Yes | No |
| Injection defense | Yes | No |
| Full audit trail | Yes | Basic |
| Snapshots | Yes | Varies |
| Multiple templates | 8 built-in | Varies |
| Interactive stdio | Yes | Varies |

## Environment Variables

| Variable | Required | Description |
|----------|----------|-------------|
| `DECLAW_API_KEY` | Yes | Your Declaw API key |
| `DECLAW_DOMAIN` | No | Custom API domain (for on-prem deployments) |

## On-Prem

For self-hosted Declaw deployments, set the domain:

```json
{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key",
        "DECLAW_DOMAIN": "declaw.internal.company.com"
      }
    }
  }
}
```

## License

Apache-2.0

TDQS

A3.9/5.0

Scored across 7 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: sandbox lifecycle (create, kill, list) versus in-sandbox operations (run command, read/write file, list files). No overlapping functionality.

Naming Consistency5/5

All tools follow a consistent verb_noun snake_case pattern (create_sandbox, kill_sandbox, run_command, read_file, etc.), with predictable alignment between verbs and actions.

Tool Count5/5

Seven tools is well-scoped for a sandbox server, covering both lifecycle management and common file/command operations without redundancy or bloat.

Completeness4/5

Core lifecycle and file operations are covered, but there is no file delete or directory removal tool, which would be a natural expectation for file management in a sandbox.

Maintenance

ActivityMaintained
ResponsivenessNo issues