cco-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cco-mcpshow pending approvals"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CCO-MCP (Claude Code Oversight)
Real-time audit and approval system for Claude Code tool calls. Get instant visibility and control over AI agent actions with a sleek web dashboard.

Overview
CCO-MCP provides a security layer between Claude Code and your system, enabling you to monitor and control AI tool calls in real-time. It acts as a firewall for AI actions, allowing you to review sensitive operations before they execute while auto-approving safe ones based on configurable rules. This let's you scale to many more non-interactive Claude Code instances running in the background without incurring "tab-switching fatigue".
Related MCP server: PearClaw
Get Started
Clone and run with Docker Compose
git clone https://github.com/onegrep/cco-mcp.git
cd cco-mcp
docker-compose upConfigure Claude Code
Install CCO-MCP at the user scope:
claude mcp add -s user -t http cco-mcp http://localhost:8660/mcpThis will add the following to your Claude Code config:
{
"mcpServers": {
"cco-mcp": {
"type": "http",
"url": "http://localhost:8660/mcp"
}
}
}For self-hosted deployments, replace http://localhost:8660/mcp with your deployment URL.
Visit http://localhost:8660 to access the dashboard.
Enable Approval Prompts
To use CCO-MCP for approval prompts, run Claude Code in non-interactive mode with the appropriate Permission Prompt Tool flag:
claude code -p "your prompt here" --permission-prompt-tool mcp__cco-mcp__approval_promptThis enables Claude to request approval through CCO-MCP before executing sensitive operations without using the "dangerously skip permissions" option.
Main Features
š”ļø Smart Approval Rules
Create rules to auto-approve safe operations (like file reads) while requiring manual approval for sensitive ones (like running bash commands).
š Real-Time Dashboard
Monitor all tool calls as they happen with live updates via Server-Sent Events.
š Detailed Audit Logs
Every tool call is logged with full context including agent identity, parameters, and approval status.
Configuration Options
All configuration can be managed through the web interface at http://localhost:8660/config.
Default Action and Timeouts
Default Action: Choose whether unmatched requests are automatically approved or require manual review
Auto-Deny Timeout: Set how long to wait for manual approval before automatically denying (default: 5 minutes)
Entry TTL: Configure how long audit log entries are retained (default: 24 hours)
Approval Rules
Rules use a priority system (lower numbers = higher priority) to determine actions:
Tool Matching: Match specific tools (built-in like Read/Write or MCP server tools)
Agent Matching: Create rules for specific agent identities
Pattern Matching: Use wildcards for flexible rule creation
Actions: Set rules to auto-approve or auto-deny matching requests
Environment Variables
PORT- Server port (default: 8660)CCO_CONFIG_PATH- Config file location (default: ~/.cco-mcp/config.json)
Development
Project Structure
cco-mcp/
āāā src/ # TypeScript backend
ā āāā audit/ # Core audit service
ā āāā routes/ # REST API endpoints
ā āāā server.ts # MCP server
āāā ui/ # React frontend
ā āāā src/
ā āāā components/
ā āāā pages/
āāā dist/ # Build outputDesign Principles
Simplicity first - Enabling core use-case of approving background agents
Real-time by default - SSE for instant updates
Type safety - Full TypeScript coverage
User-friendly - Intuitive UI with helpful defaults
Local Development
# Install required tools
just brew
# Setup project dependencies
just setup
# Run both backend and UI
just dev-all
# Run tests
just test
# Format code
just format
# Build everything
just build-allContributing
We welcome contributions! Please see our Contributing Guide for details.
License
MIT License - Copyright 2025 OneGrep, Inc.
Acknowledgments
Built for use with Claude Code and the Model Context Protocol by Anthropic.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityAmaintenancePolicy-based governance for AI agent tool calls. YAML policies, approval gates, risk assessment, and audit logging across LangChain, OpenAI, Anthropic, and MCP.Last updated512MIT
- FlicenseAqualityDmaintenanceProvides real-time oversight for Claude Code by connecting it to an OpenClaw agent that reviews, approves, blocks, or modifies actions before they execute.Last updated3
- AlicenseAqualityBmaintenanceHuman-in-the-loop approval gateway for agent tool calls: agents request, policies decide, humans approve via Slack/Discord/web ā with an OWASP-LLM-Top-10-tagged audit trail. Self-hostable.Last updated101830MIT
- AlicenseBqualityAmaintenanceGovernance runtime for AI agents: a guard tool evaluates risky actions against policy before they execute (block / warn / require human approval), approvals route to a human queue, and every action becomes a replayable decision record with per-action spend tracking. Runs over stdio via npx @dashclaw/mcp-server; works with Claude Code, Codex, LangChain, CrewAI, or any MCP host.Last updated68284MIT
Related MCP Connectors
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Runtime permission, approval, and audit layer for AI agent tool execution.
Human-in-the-loop for AI coding agents ā ask questions, get approvals via Slack.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/toolprint/cco-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server