mcpcut

io.github.RostislavMatovv0.2.3Updated Oct 1, 2026

Journals every MCP tool call with secrets redacted; with a policy, holds risky calls for approval

VerifiedSTDIODesktop onlyOther

Installation

In SourceWeft

  1. Open mcpcut in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

mcpcut

[CI] [npm] [License: Apache-2.0]

See every tool call your AI agent makes over MCP, hold the risky ones for your approval, and keep a secret-redacted journal that is tamper-evident with an external anchor.

Self-hosted · Apache-2.0 · Node.js 24+ · two runtime dependencies. Start with one server on your laptop; grow into a control plane for many agents.

[mcpcut in 60 seconds]

Quick start

Requires Node.js 24+ (node -v); on older Node, mcpcut prints one line and exits — install Node 24 with nvm, fnm or volta. Nothing else to install.

See. Put mcpcut in front of a server — here for Claude Code; in any other client, the server's command becomes npx -y [email protected] wrap -- <your server>:

claude mcp add fs -- npx -y [email protected] wrap --server fs -- npx -y @modelcontextprotocol/server-filesystem ~/project

The first start downloads mcpcut and the server; if your client gives up on it, start it once more. Let the agent work, then npx -y [email protected] sessions and npx -y [email protected] show <id>: every request and response, secrets redacted (with a policy, every decision too). --server fs names the server in the journal and the approval queue.

Stop. Save this as policy.json — reads pass, everything else waits for you (quarantine of new tools is off, so the first minute shows one gate: see Quarantine) — and re-add the server with --policy "$PWD/policy.json" right after wrap (claude mcp remove fs first):

{ "version": 1, "defaultDecision": "require-approval", "classDefaults": { "read": "allow" },  "quarantine": { "enabled": false } }

A write now waits. Approve it from another terminal within the agent's wait (60 s; after it, the agent's retry passes) — no token needed until you add your first admin (Approvals):

npx -y [email protected] approvals listnpx -y [email protected] approvals approve <id>

Prove. Sign the history, export it, and check it offline — with nothing but the directory:

npx -y [email protected] keygen && npx -y [email protected] export --report --out ./reportnpx -y [email protected] verify --report ./reportnpx -y [email protected] verify --sign

The last line signs the chain head: keep what it prints somewhere this host cannot rewrite — the out-of-band anchor is what makes the journal tamper-evident, not the hashes alone.

Grow. npm install -g mcpcut, then mcpcut: a setup wizard, then a server registry, per-agent keys and grants, a credential vault, a web UI, a terminal console and one address per agent (Install and first run).

What you get

  • Journal — every request, response and decision, with secrets redacted before anything is written. Optionally fail-closed: no record, no call.
  • Policy per tool — allow, deny or require-approval by server, tool name or tool class; read-only tools can pass on their own.
  • Approvals — a risky call waits until someone approves it from the CLI, the web UI or the terminal console.
  • Quarantine — a new tool, or one whose description or schema changed after you trusted it, is held until reviewed, with a diff of what changed.
  • Agents and grants — a registry of servers, a key per agent, per-tool grants, groups, and an encrypted vault, so server credentials never sit in an agent's config.
  • One address per agent — every server an agent is granted behind one endpoint; grant or revoke without touching the client.
  • Evidence — a hash chain with a signed head, and an audit report anyone can verify offline with a public key.
  • Admin UI and terminal console — named admins with owner, operator and viewer roles; every change is attributed in the journal.

How it works

 AI agent ── stdio or HTTP ──▶ mcpcut ──────────────────▶ MCP servers (Claude Code,                 grants → policy →          (filesystem,  Cursor, …)                   quarantine → approval       GitHub, …)                                 │                                 ▼                     journal.db — redacted, hash-chained                                 │  export --report                                 ▼                     verify offline, anywhere

Three ways in, one gate:

  • wrap — in front of one server, with no setup and no identity: the Quick start above.
  • connect and serve — named servers from the registry, a key per agent, credentials from the vault.
  • The pool (/mcp) — one address per agent for every server it is granted; connect --url bridges a stdio client on another machine to it.

The full picture, with the trust boundaries: docs/ARCHITECTURE.md.

Documentation

GuideCovers
Install and first runnpm or source, the setup wizard, the first owner, reaching the service by IP
Wrapping a server and reading the journalwrap, sessions, show, .mcp.json, fail-closed journaling, known limits
Policies, approvals and quarantinepolicy.json, tool classes, approvals, quarantine, tools/list filtering
Registry, agents and the vaultservers, agent keys and grants, groups, revoking access, the vault
HTTP agents and the poolserve, one address per agent, connect --url
Admin UIthe web console, admins and roles, its threat model
The terminal consolemcpcut in a terminal, the remote console
Services, Docker and backupsstart/stop/status, systemd and launchd, Docker, backup and restore
Audit reports and retentionexport --report, verify --report, the out-of-band anchor, prune
CLI referenceevery command and flag
Statuswhat is shipped, and the evidence behind each line

Status

mcpcut is 0.x. The core — proxy, policy, approvals, quarantine, journal, audit report, admin UI and console — is shipped and covered by tests; Status lists each capability with its evidence.

  • Preview: the remote console (mcpcut --remote) and the connect --url bridge. They work and are tested against a VPS over TLS, but they put a token on the network, have had only an internal security review, and may change within 0.x.
  • Tamper-evident means with an external anchor. A process running as the same OS user can rewrite the journal and re-sign it; only a chain head recorded somewhere this host cannot write exposes that. mcpcut is not tamper-proof, and whether a report satisfies an audit is the auditor's call.
  • A brake for mistakes, not a sandbox. An agent that also has a shell as your user can reach the same approvals approve you run: an admin token records who approved, it does not stop the same OS user (Approvals). The error a held call returns tells the agent a human must approve and never names the command.

Security

Please report vulnerabilities privately — SECURITY.md says how. The whole product had an internal security audit in September 2026; no independent audit has been done yet.

Contributing

Issues and pull requests are welcome — see CONTRIBUTING.md.

License

Apache-2.0 — see NOTICE.

Source: README.md at commit 4682794

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.2.3LatestOct 1, 2026