Skip to content

MCP Security Gateway

MCPGateway combines native ACS policy evaluation with MCP-specific host controls.

Create the gateway

from agent_control_specification import AgentControl
from agent_os.mcp_gateway import MCPGateway

runtime = AgentControl.from_path("policies/mcp-manifest.yaml")
gateway = MCPGateway(
    runtime,
    denied_tools=["shell"],
    sensitive_tools=["deploy"],
    rate_limit=100,
)

The manifest controls policy bindings and the tool catalog. Gateway arguments control host deny lists, approval routing, sanitization, rate limiting, metrics, response scanning, and audit sinks.

Evaluate a call

allowed, reason = gateway.intercept_tool_call(
    agent_id="agent-1",
    tool_name="search",
    params={"query": "status"},
)

The gateway applies host checks and native pre_tool_call evaluation before the tool side effect. Unexpected evaluation or approval errors fail closed.

Sensitive tools

Provide an approval callback for tools listed in sensitive_tools.

from agent_os.mcp_gateway import ApprovalStatus

def approve(agent_id: str, tool_name: str, parameters: dict) -> ApprovalStatus:
    if tool_name == "deploy" and parameters.get("environment") == "production":
        return ApprovalStatus.DENIED
    return ApprovalStatus.APPROVED

gateway = MCPGateway(
    runtime,
    sensitive_tools=["deploy"],
    approval_callback=approve,
)

Response scanning

Pass an MCPResponseScanner and choose ResponsePolicy.BLOCK, ResponsePolicy.SANITIZE, or ResponsePolicy.LOG. Credential and PII leaks remain blocked when sanitization cannot safely remove them.

Wrap server configuration

config = MCPGateway.wrap_mcp_server(
    {"command": "python", "args": ["-m", "my_server"]},
    denied_tools=["shell"],
    sensitive_tools=["deploy"],
    rate_limit=50,
)

wrap_mcp_server does not embed policy. Construct the gateway with the native runtime when starting the governed proxy.

Audit

Persisted audit payloads are redacted. Native policy details are available through the restricted PolicyEvaluation.audit_record() contract.

See MCP Trust Guide and MCP Governance.