mcp-boundary
MCP Boundary
A local proxy that wraps your MCP servers and checks each tool call against your policy and the current state before any server tool is called. When it blocks, the agent gets back a reason it can act on.
Website: https://mcpboundary.com · Docs: https://mcpboundary.com/docs/mcp-boundary
What it does
Wrap an existing local MCP server — your agent keeps the same tools, every call passes the boundary first.
Choose which tools the agent sees — expose, hide, or keep dashboard-only.
Allow, block, or hold for review — with a structured reason the agent can act on.
Restrict specific arguments, not whole tools — e.g. allow only certain recipients or IDs.
Limit response sizes and timeouts — and throttle repeated calls to contain runaway loops.
Bind writes to observed state — don't run a write if the world changed since the read.
Inspect every call, decision, reason, and outcome in a local dashboard.
Related MCP server: @palveron/mcp-server
How it works
MCP Boundary sits between your MCP client and your local MCP servers. Your agent connects to MCP Boundary as a server entry; MCP Boundary checks each tool call against your policy and the current state, then forwards only admitted calls to the real server. When it blocks, the agent gets back a reason it can act on — re-check state, narrow scope, or stop retrying.
Download
Windows and Linux builds with SHA-256 checksums (current release v0.2.3): → https://mcpboundary.com
Quick start from an extracted package — Windows: .\mcpboundary.exe quickstart email · Linux: ./mcpboundary quickstart email
Docs
Getting started, policy examples, tested servers — https://mcpboundary.com/docs/mcp-boundary
How it works — https://mcpboundary.com/how-it-works
MCP Tool Rules (writing policies) — https://mcpboundary.com/mcp-tool-rules
Scope
MCP Boundary works best with local command-based stdio MCP servers. Only calls routed through MCP Boundary are covered. It is not an enterprise security gateway, a DLP system, a prompt-injection detector, or a replacement for code review, database permissions, or email approval processes.
License
MCP Boundary is free to download and use, distributed under its own license and terms — see LICENSE.md and TERMS.md in the release package. All rights reserved.
Built by Impact Boundary Labs.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP enforcement layer that intercepts AI agent actions and blocks rule violations before execution.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Related MCP Servers
- AlicenseAqualityAmaintenanceSecurity-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical2113Apache 2.0
- AlicenseAqualityAmaintenanceProvides advisory AI-governance checks for MCP hosts and coding agents, enabling policy verdicts, PII masking, and audit traces before executing tool calls.344MIT
- AlicenseNot gradedqualityBmaintenanceA policy-enforcing MCP gateway that intercepts all tool calls to downstream MCP servers, applying allow/deny/ask rules with human approval and audit logging for safe access to dangerous tools.8MIT
- FlicenseNot gradedqualityCmaintenanceMCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.-