writ

io.github.withwritv0.1.3Updated Oct 2, 2026

Commit-time policy checks for AI agent writes (ALLOW/DENY/STEP_UP) with a tamper-evident audit log.

Overview

AI-generated overview

Lets an agent request a commit-time policy decision (ALLOW, DENY, or STEP_UP) before a consequential write, with a tamper-evident audit trail.

What it does
Writ is a gate an MCP-compatible agent calls before performing a consequential write. The agent calls writ_check with a sponsor, agent, verb, target, and purpose, and receives ALLOW, DENY, or STEP_UP; an ALLOW returns a 90-second token bound to that exact write, which writ_verify_token re-checks immediately before execution. Sponsor-side tools grant a STEP_UP, revoke or reinstate a principal, and agent-side tools read receipts and tenant verb policy. A writ_sandbox tool offers a free demo grant without a key.
When to use it
Use it when an assistant performs writes that should be authorized at the point of action rather than only at setup, and when you want a decision record for each attempt. It suits teams that need a human approval step for sensitive operations and an audit trail of what was allowed or denied.
Requirements
Runs locally over stdio as the writ-mcp command from the PyPI package writ-mcp, requiring Python 3.9+ (installable with uvx). A Writ API key is required in the WRIT_API_KEY environment variable; sponsor tools additionally need WRIT_SPONSOR_TOKEN. WRIT_BASE_URL optionally overrides the default API endpoint, so network access to the Writ API is needed.
Before you install
WRIT_API_KEY and WRIT_SPONSOR_TOKEN are secrets passed as environment variables and should not be exposed. Decisions and receipts are sent to the Writ API, a third-party service, so write metadata such as verb, target, and purpose leaves the machine. Sponsor tools can grant, revoke, or reinstate principals, which changes who may act; DENY means the write must not proceed, and STEP_UP requires human approval before retrying.

Installation

In SourceWeft

  1. Open writ in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

writ-mcp

The Writ gate as an MCP server. Give any MCP-compatible agent point-of-action control: the agent calls Writ before a consequential write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an audit receipt.

Install

bash
pip install writ-mcp

Requires Python 3.9+. Installs the writ-mcp command (stdio transport).

Configure

bash
export WRIT_API_KEY="writ_..."        # required; get one free: POST /v1/keys with an emailexport WRIT_SPONSOR_TOKEN="..."       # only for sponsor tools (grant, revoke, reinstate)# export WRIT_BASE_URL="..."          # default: https://api.withwrit.com

Add to your agent

Claude Code:

bash
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp

Claude Desktop (claude_desktop_config.json):

json
{  "mcpServers": {    "writ": {      "command": "writ-mcp",      "env": { "WRIT_API_KEY": "writ_..." }    }  }}

Any MCP client (generic stdio config):

json
{  "command": "writ-mcp",  "env": {    "WRIT_API_KEY": "writ_...",    "WRIT_SPONSOR_TOKEN": "writ_sp_..."  }}

Hermes (NousResearch/hermes-agent) catalog entry — once published, this package is installable from the optional-mcps catalog:

bash
hermes mcp install writ

The check-before-write loop

The tool descriptions teach the agent this flow, but the short version:

  1. writ_check(sponsor_id, agent_id, verb, target, purpose) — before the write.
  2. ALLOW → you get a 90-second authToken bound to that exact write.
  3. writ_verify_token(auth_token, verb, target, purpose) — immediately before executing, to prove the authorization still matches what you're doing.
  4. DENY → do not proceed. STEP_UP → a human sponsor approves (via writ_grant or the dashboard), then check again.

Tools

ToolWhoWhat
writ_checkagentDecision + 90s purpose-bound token
writ_verify_tokenagentPoint-of-action token verification
writ_grantsponsorApprove a STEP_UP (one-time grant)
writ_revoke / writ_reinstatesponsorKill switch on/off for a principal
writ_receiptsagentAudit trail of decisions
writ_policyagentTenant verb policy
writ_sandboxanyoneFree 90-second demo grant, no key needed

Try it with no key: writ_sandbox → writ_check with verb="demo_write".

Source

Public repo: withwrit/pywrit (mcp/ directory). License: MIT.

Source: mcp/README.md at commit 500c8c4

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.3LatestOct 2, 2026