writ

io.github.AvenueDAdminv0.1.2Updated Oct 1, 2026

Commit-time policy checks for AI agent writes (ALLOW/DENY/STEP_UP) with a tamper-evident audit log.

Installation

In SourceWeft

  1. Open writ in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

writ-mcp

The Writ gate as an MCP server. Give any MCP-compatible agent commit-time control: the agent calls Writ before a consequential write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an audit receipt.

Install

bash
pip install writ-mcp

Requires Python 3.9+. Installs the writ-mcp command (stdio transport).

Configure

bash
export WRIT_API_KEY="writ_..."        # required; get one free: POST /v1/keys with an emailexport WRIT_SPONSOR_TOKEN="..."       # only for sponsor tools (grant, revoke, reinstate)# export WRIT_BASE_URL="..."          # default: https://api.withwrit.com

Add to your agent

Claude Code:

bash
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp

Claude Desktop (claude_desktop_config.json):

json
{  "mcpServers": {    "writ": {      "command": "writ-mcp",      "env": { "WRIT_API_KEY": "writ_..." }    }  }}

Any MCP client (generic stdio config):

json
{  "command": "writ-mcp",  "env": {    "WRIT_API_KEY": "writ_...",    "WRIT_SPONSOR_TOKEN": "writ_sp_..."  }}

Hermes (NousResearch/hermes-agent) catalog entry — once published, this package is installable from the optional-mcps catalog:

bash
hermes mcp install writ

The check-before-write loop

The tool descriptions teach the agent this flow, but the short version:

  1. writ_check(sponsor_id, agent_id, verb, target, purpose) — before the write.
  2. ALLOW → you get a 90-second authToken bound to that exact write.
  3. writ_verify_token(auth_token, verb, target, purpose) — immediately before executing, to prove the authorization still matches what you're doing.
  4. DENY → do not proceed. STEP_UP → a human sponsor approves (via writ_grant or the dashboard), then check again.

Tools

ToolWhoWhat
writ_checkagentDecision + 90s purpose-bound token
writ_verify_tokenagentCommit-time token verification
writ_grantsponsorApprove a STEP_UP (one-time grant)
writ_revoke / writ_reinstatesponsorKill switch on/off for a principal
writ_receiptsagentAudit trail of decisions
writ_policyagentTenant verb policy
writ_sandboxanyoneFree 90-second demo grant, no key needed

Try it with no key: writ_sandbox → writ_check with verb="demo_write".

Source

Public repo: AvenueDAdmin/pywrit (mcp/ directory). License: MIT.

Source: mcp/README.md at commit 6f3cb93

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.2LatestOct 1, 2026