Secure AI agent tool calls with signed receipts and Cedar policy enforcement. For developers building Claude Code integrations and MCP gateways who need audit trails and access control.
io.github.tomjwxf/protect-mcp
Local install
STDIO
No auth required
How models use it and what it is built for.
Secure AI agent tool calls with signed receipts and Cedar policy enforcement. For developers building Claude Code integrations and MCP gateways who need audit trails and access control.
Local install — runs as a subprocess.
Where to find authoritative docs and source for Tomjwxf Protect.
Paste any of these into Agent Studio after connecting Tomjwxf Protect.
Common questions about connecting and running Tomjwxf Protect.
What does protect-mcp actually do?
It creates signed receipts for AI agent tool calls and enforces Cedar-based access policies. This gives you an audit trail and fine-grained control over which tools Claude can invoke.
How do I set up protect-mcp with Claude Code?
Install via `npx protect-mcp@0.5.3` and configure it as an MCP gateway. The server runs over stdio and hooks into Claude Code's tool invocation pipeline to intercept and sign calls.
What is Cedar and why use it for policies?
Cedar is an open-source policy language designed for fine-grained access control. protect-mcp uses it to let you define exactly which agents can call which tools under what conditions.
Can I audit tool calls after they happen?
Yes—signed receipts create a tamper-proof record of each tool invocation. You can verify signatures and replay the audit log to see exactly what Claude executed and when.
Is there a cost or license requirement?
The registry metadata does not specify pricing or licensing terms. Check the project repository or documentation for details on commercial use and support.
MCP Playground runs 10,000+ hosted MCP servers — GitHub, Linear, Notion, Stripe, Sentry and more — across Claude, GPT, Gemini, DeepSeek and 60+ AI models. Compare model answers side-by-side, save agent presets, share runs. Zero install.
Open Agent StudioJudges Panel
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Addozhang Nexus
Query Sonatype Nexus Repository (OSS/Pro) for Maven, Python, and Docker artifacts
Cyanheads MCP Ts Template
TypeScript template for building MCP servers with declarative tooling, observability, and auth.
Chernistry Bernstein
Declarative agent orchestration for engineering teams