agent-rewind
Provides a Gmail connector that records email actions, redacts sensitive fields, holds high-blast-radius operations for approval, and supports per-action undo and rewind.
Provides a Slack connector that records messaging actions, redacts sensitive fields, holds high-blast-radius operations for approval, and supports per-action undo and rewind.
Provides a Stripe connector that records payment operations, redacts sensitive fields, holds high-blast-radius operations for approval, and supports per-action undo and rewind.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-rewindRewind to before the bulk delete"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agent Rewind
The flight recorder + undo button for AI agents.
AI agents take real, irreversible actions — they delete files, send emails, call APIs. When one goes off the rails, there is no black box to read and no undo button to press. Agent Rewind is both: a transparent proxy between your agent and its tools that records every action, snapshots state before anything destructive runs, holds oversized operations for human approval, and gives you per-action Undo, Rewind-to-a-point-in-time, and a kill switch the agent cannot talk its way around.

See it in 60 seconds
git clone https://github.com/moholo-founder/agent-rewind.git
cd agent-rewind && pnpm install && pnpm demoOpen http://localhost:4820. A scripted rogue agent wipes a 200-message inbox, deletes files, and queues embarrassing emails — then you press ⏪ Rewind and watch everything come back, with a per-action report that never claims more than it restored.
Related MCP server: undo
Use it with your agent
Any MCP client (Claude Code, Claude Desktop, Cursor, ...) — one config block:
{
"mcpServers": {
"agent-rewind": { "command": "npx", "args": ["-y", "agent-rewind"] }
}
}Every tool call your agent makes through the proxy is journaled, snapshotted, policy-gated, and reversible from the timeline UI at http://localhost:4821.
Native Claude Code sessions (built-in Bash/Edit/Write, no MCP involved) — hooks mode:
agent-rewind hooks install # wires this project's .claude/settings.json
agent-rewind ui # operator consoleFile edits become undoable (snapshotted before they land), dangerous shell patterns escalate to an explicit permission prompt, and the STOP switch refuses every native tool until a human resumes.
What you get
Live timeline — every action as it happens: who, what, blast radius, risk class, status, before/after diffs.
Undo — one click restores what an action destroyed, byte-identical, from content-addressed snapshots captured before execution.
Rewind — pick a point in time, preview exactly what will be undone, confirm, and unwind it all in strict reverse order of execution.
Kill switch — STOP refuses every side-effecting call until a human resumes. The flag lives in Agent Rewind's own storage, outside the agent's context — context compaction and creative reasoning cannot clear it.
Blast-radius holds — actions over a per-connector threshold (delete 40 files, wipe 200 messages) wait in an approval tray instead of executing.
Append-only journal — tamper-resistant evidence (SQLite triggers refuse deletes and rewrites), with secrets redacted at write time.
Honest failure — an undo that fails says so, loudly, per action.
Fully restoredis only ever claimed when it is true.
How it works
[ agent / MCP client ]
│ MCP
▼
Agent Rewind proxy — classify → gate (allow / hold / block) →
snapshot pre-state → execute → journal + live UI
│ MCP
▼
[ your tool servers: filesystem, email, ... ]Reversibility is per-connector: each tool declares its class (read /
reversible / destructive) and ships a compensator — capture what the action
will destroy, and how to restore it. Reads pass through untouched. Unknown
tools are held for approval, never silently executed. v1 ships a sandboxed
filesystem connector and a self-contained mock email connector (
delayed outbox with a recall window — after delivery, undo honestly reports
not-reversible). The interface is designed so real connectors (Gmail,
Slack, Stripe) drop in without touching core.
Zero native dependencies — pure JavaScript on Node 22.13+ (SQLite via
node:sqlite). Install is seconds, no compiler. CI-verified on Linux, macOS,
and Windows.
License
Source-available under the Business Source License 1.1, © 2026 Moholo Inc. Free for individuals, nonprofits, education, and organizations under 25 people / US $2M revenue — including production. Larger organizations need a commercial license (founders@moholo.co). Every version becomes Apache 2.0 open source four years after release. See TERMS.md and CONTRIBUTING.md.
Roadmap
Real connectors: Gmail, Slack, Stripe (OAuth), with per-field redaction
Reversible-shell tier: filesystem snapshots (APFS/btrfs) bracketing agent sessions, so even arbitrary Bash can be rolled back
Enterprise: audit export, SSO, retention policies, multi-operator
HTTP/SSE MCP transport; held-action persistence across restarts
Developer docs, architecture details, and the build history live in docs/DEVELOPMENT.md.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenanceLocal zero-trust permission gateway for AI agents. Enforces policy-based tool authorization, human approvals, scoped permissions, and cryptographically verifiable audit logs.45Apache 2.0
- AlicenseAqualityAmaintenanceProvides checkpoint and rollback capabilities for AI agents, reversing file system changes and recording network mutations.1671MIT
- Alicense-qualityBmaintenanceSafe, reversible tool execution for AI agents. It sits between an agent and its tool servers, adding contracts, dry-run planning, policy, approvals, saga execution, and rewind.MIT
- Alicense-qualityCmaintenanceGates agent tool execution with human approval, audit trails, and replay-resistant permits, enabling safe use of tools in agent loops.MIT
Related MCP Connectors
Runtime permission, approval, and audit layer for AI agent tool execution.
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/moholo-founder/agent-rewind'
If you have feedback or need assistance with the MCP directory API, please join our Discord server