MCP Warden
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP WardenAs analyst-agent, search the catalog for customer PII columns."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Warden — Policy-enforcing gateway between AI agents and MCP servers

Why
Enterprises adopting MCP need the same controls they already have for APIs: least privilege per agent, data-classification-aware responses, and an audit trail. Putting those controls in each MCP server duplicates effort and the rules drift. MCP Warden is the gateway that centralises authentication, policy, obligations, and audit for the teams operating those agents.
Related MCP server: Proofpane
Quickstart
From a fresh checkout, with uv installed:
uv run python -m examples.quickstartThat starts the catalog and admin fixture upstreams, applies examples/policy.yaml, and prints the analyst and steward outcomes. The bearer keys for the fixture principals are analyst-secret, steward-secret, and rogue-secret.
How it works
flowchart LR
Agent[Agent] --> Warden[MCP Warden]
Warden --> Policy[Native YAML or OPA]
Warden --> Catalog[catalog]
Warden --> Admin[admin]
Warden --> Audit[JSONL audit chain]An agent sends tools/list and tools/call to Warden. Warden authenticates the bearer key, asks the policy engine, drops hidden tools, and on an allow applies obligations in this order: redact fields, strip inferences, mask PII, then truncate. Names from upstream servers are published as {server}__{tool}.
Warden denies by default, including when authentication or policy evaluation fails. Destructive tools are blocked unless a rule allows them. API keys are stored and compared as SHA-256 hashes. The audit log keeps digests rather than raw arguments or responses. The chain is tamper-evident, not tamper-proof: every audit.anchor_every records (default 100) the latest hash is printed to stdout. The example config binds to localhost; terminate TLS at a reverse proxy.
Results / example output
uv run mcp-warden check-policy -c examples/warden.yaml on the fixture upstreams:
principal | tool | action | effect | rule_ids | reason
analyst-agent | catalog__get_column_profile | list | ALLOW | analysts-read-catalog | allow
analyst-agent | catalog__get_column_profile | call | ALLOW | analysts-read-catalog | allow
analyst-agent | catalog__search_assets | list | ALLOW | analysts-read-catalog | allow
analyst-agent | catalog__search_assets | call | ALLOW | analysts-read-catalog | allow
analyst-agent | admin__delete_asset | list | DENY | - | default deny
analyst-agent | admin__delete_asset | call | DENY | no-destructive | Destructive tools are blocked through the gateway.
analyst-agent | admin__list_jobs | list | DENY | - | default deny
analyst-agent | admin__list_jobs | call | DENY | - | default deny
steward-agent | catalog__get_column_profile | list | ALLOW | stewards-read-catalog | allow
steward-agent | catalog__get_column_profile | call | ALLOW | stewards-read-catalog | allow
steward-agent | catalog__search_assets | list | ALLOW | stewards-read-catalog | allow
steward-agent | catalog__search_assets | call | ALLOW | stewards-read-catalog | allow
steward-agent | admin__delete_asset | list | DENY | - | default deny
steward-agent | admin__delete_asset | call | DENY | no-destructive | Destructive tools are blocked through the gateway.
steward-agent | admin__list_jobs | list | DENY | - | default deny
steward-agent | admin__list_jobs | call | DENY | - | default deny
rogue-agent | catalog__get_column_profile | list | DENY | - | default deny
rogue-agent | catalog__get_column_profile | call | DENY | - | default deny
rogue-agent | catalog__search_assets | list | DENY | - | default deny
rogue-agent | catalog__search_assets | call | DENY | - | default deny
rogue-agent | admin__delete_asset | list | DENY | - | default deny
rogue-agent | admin__delete_asset | call | DENY | no-destructive | Destructive tools are blocked through the gateway.
rogue-agent | admin__list_jobs | list | DENY | - | default deny
rogue-agent | admin__list_jobs | call | DENY | - | default denyAfter the quickstart, uv run mcp-warden verify-log audit/warden.jsonl prints:
OKDesign decisions
Roadmap
A human approval step for high-risk tools
An anchor sink other than stdout
Publishing the package
Licence
Apache-2.0
This server cannot be deployed
Maintenance
Related MCP Connectors
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- FlicenseNot gradedqualityNot gradedmaintenanceA transparent proxy and execution firewall that intercepts and audits AI agent tool calls against configurable security policies before forwarding them to downstream MCP servers. It provides safe execution environments with features like data redaction, anti-loop protection, and unified alert dispatching.-
- AlicenseBqualityAmaintenanceA governance proxy for AI tools — every MCP/agent tool call is policy-gated, secret-redacted, and written to a hash-chained, offline-verifiable audit trail.13MIT

evav-gatewayofficial
AlicenseNot gradedqualityBmaintenanceGoverned MCP gateway that lets AI agents call tools with policy enforcement, prompt-injection screening, a kill-switch, and tamper-evident signed audit logs.Apache 2.0- FlicenseNot gradedqualityCmaintenanceMCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.-