mcpcut
Local proxy in front of any MCP server: journals every tool call with secrets redacted, holds risky calls for your approval, quarantines changed tools; the journal is tamper-evident with an external anchor.
Install
Install and configure the MCP from https://github.com/RostislavMatov/mcpcut now. Follow the repository's installation instructions, ask me for anything you can't complete yourself, and verify its tools load.mcpcut
See every tool call your AI agent makes over MCP, hold the risky ones for your approval, and keep a secret-redacted journal that is tamper-evident with an external anchor.
Self-hosted · Apache-2.0 · Node.js 24+ · two runtime dependencies. Start with one server on your laptop; grow into a control plane for many agents.
Quick start
Requires Node.js 24+ (node -v); on older Node, mcpcut prints one line and exits — install Node 24 with nvm, fnm or volta. Nothing else to install.
See. Put mcpcut in front of a server — here for Claude Code; in any other client, the server's command becomes npx -y mcpcut@0.2.4 wrap -- <your server>:
claude mcp add fs -- npx -y mcpcut@0.2.4 wrap --server fs -- npx -y @modelcontextprotocol/server-filesystem ~/project
The first start downloads mcpcut and the server; if your client gives up on it, start it once more. Let the agent work, then npx -y mcpcut@0.2.4 sessions and npx -y mcpcut@0.2.4 show <id>: every request and response, secrets redacted (with a policy, every decision too). --server fs names the server in the decisions a policy writes to the journal and in the approval queue.
Stop. Save this as policy.json — reads pass, everything else waits for you (quarantine of new tools is off, so the first minute shows one gate: see Quarantine) — and re-add the server with --policy "$PWD/policy.json" right after wrap (claude mcp remove fs first):
{ "version": 1, "defaultDecision": "require-approval", "classDefaults": { "read": "allow" },
"quarantine": { "enabled": false } }
A write now waits. Approve it from another terminal within the agent's wait (60 s; after it, the agent's retry passes) — no token needed until you add your first admin (Approvals):
npx -y mcpcut@0.2.4 approvals list
npx -y mcpcut@0.2.4 approvals approve <id>
Prove. Sign the history, export it, and check it offline — with nothing but the directory:
npx -y mcpcut@0.2.4 keygen && npx -y mcpcut@0.2.4 export --report --out ./report
npx -y mcpcut@0.2.4 verify --report ./report
npx -y mcpcut@0.2.4 verify --sign
The last line signs the chain head: keep what it prints somewhere this host cannot rewrite — the out-of-band anchor is what makes the journal tamper-evident, not the hashes alone.
Grow. npm install -g mcpcut, then mcpcut: a setup wizard, then a server registry, per-agent keys and grants, a credential vault, a web UI, a terminal console and one address per agent (Install and first run).
What you get
- Journal — every request, response and decision, with secrets redacted before anything is written. Optionally fail-closed: no record, no call.
- Policy per tool —
allow,denyorrequire-approvalby server, tool name or tool class; read-only tools can pass on their own. - Approvals — a risky call waits until someone approves it from the CLI, the web UI or the terminal console.
- Quarantine — a new tool, or one whose description or schema changed after you trusted it, is held until reviewed, with a diff of what changed.
- Agents and grants — a registry of servers, a key per agent, per-tool grants, groups, and an encrypted vault, so server credentials never sit in an agent's config.
- One address per agent — every server an agent is granted behind one endpoint; grant or revoke without touching the client.
- Evidence — a hash chain with a signed head, and an audit report anyone can verify offline with a public key.
- Admin UI and terminal console — named admins with
owner,operatorandviewerroles; every change is attributed in the journal.
How it works
AI agent ── stdio or HTTP ──▶ mcpcut ──────────────────▶ MCP servers
(Claude Code, grants → policy → (filesystem,
Cursor, …) quarantine → approval GitHub, …)
│
▼
journal.db — redacted, hash-chained
│ export --report
▼
verify offline, anywhere
Three ways in, one gate:
wrap— in front of one server, with no setup and no identity: the Quick start above.connectandserve— named servers from the registry, a key per agent, credentials from the vault.- The pool (
/mcp) — one address per agent for every server it is granted;connect --urlbridges a stdio client on another machine to it.
The full picture, with the trust boundaries: docs/ARCHITECTURE.md.
Documentation
| Guide | Covers |
|---|---|
| Install and first run | npm or source, the setup wizard, the first owner, reaching the service by IP |
| Wrapping a server and reading the journal | wrap, sessions, show, .mcp.json, fail-closed journaling, known limits |
| Policies, approvals and quarantine | policy.json, tool classes, approvals, quarantine, tools/list filtering |
| Registry, agents and the vault | servers, agent keys and grants, groups, revoking access, the vault |
| HTTP agents and the pool | serve, one address per agent, connect --url |
| Admin UI | the web console, admins and roles, its threat model |
| The terminal console | mcpcut in a terminal, the remote console |
| Services, Docker and backups | start/stop/status, systemd and launchd, Docker, backup and restore |
| Audit reports and retention | export --report, verify --report, the out-of-band anchor, prune |
| CLI reference | every command and flag |
| Status | what is shipped, and the evidence behind each line |
Status
mcpcut is 0.x. The core — proxy, policy, approvals, quarantine, journal, audit report, admin UI and console — is shipped and covered by tests; Status lists each capability with its evidence.
- Preview: the remote console (
mcpcut --remote) and theconnect --urlbridge. They work and are tested against a VPS over TLS, but they put a token on the network, have had only an internal security review, and may change within 0.x. - Tamper-evident means with an external anchor. A process running as the same OS user can rewrite the journal and re-sign it; only a chain head recorded somewhere this host cannot write exposes that. mcpcut is not tamper-proof, and whether a report satisfies an audit is the auditor's call.
- A brake for mistakes, not a sandbox. An agent that also has a shell as your user can reach the same
approvals approveyou run: an admin token records who approved, it does not stop the same OS user (Approvals). The error a held call returns tells the agent a human must approve and never names the command.
Security
Please report vulnerabilities privately — SECURITY.md says how. The whole product had an internal security audit in September 2026; no independent audit has been done yet.
Contributing
Issues and pull requests are welcome — see CONTRIBUTING.md.
License
Apache-2.0 — see NOTICE.
