
writ
io.github.withwritv0.1.3Updated Oct 2, 2026
Commit-time policy checks for AI agent writes (ALLOW/DENY/STEP_UP) with a tamper-evident audit log.
Overview
Lets an agent request a commit-time policy decision (ALLOW, DENY, or STEP_UP) before a consequential write, with a tamper-evident audit trail.
- What it does
- Writ is a gate an MCP-compatible agent calls before performing a consequential write. The agent calls writ_check with a sponsor, agent, verb, target, and purpose, and receives ALLOW, DENY, or STEP_UP; an ALLOW returns a 90-second token bound to that exact write, which writ_verify_token re-checks immediately before execution. Sponsor-side tools grant a STEP_UP, revoke or reinstate a principal, and agent-side tools read receipts and tenant verb policy. A writ_sandbox tool offers a free demo grant without a key.
- When to use it
- Use it when an assistant performs writes that should be authorized at the point of action rather than only at setup, and when you want a decision record for each attempt. It suits teams that need a human approval step for sensitive operations and an audit trail of what was allowed or denied.
- Requirements
- Runs locally over stdio as the writ-mcp command from the PyPI package writ-mcp, requiring Python 3.9+ (installable with uvx). A Writ API key is required in the WRIT_API_KEY environment variable; sponsor tools additionally need WRIT_SPONSOR_TOKEN. WRIT_BASE_URL optionally overrides the default API endpoint, so network access to the Writ API is needed.
Installation
In SourceWeft
- Open writ in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
writ-mcp
The Writ gate as an MCP server. Give any MCP-compatible
agent point-of-action control: the agent calls Writ before a consequential
write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an
audit receipt.
Install
Requires Python 3.9+. Installs the writ-mcp command (stdio transport).
Configure
Add to your agent
Claude Code:
Claude Desktop (claude_desktop_config.json):
Any MCP client (generic stdio config):
Hermes (NousResearch/hermes-agent) catalog entry — once published, this
package is installable from the optional-mcps catalog:
The check-before-write loop
The tool descriptions teach the agent this flow, but the short version:
writ_check(sponsor_id, agent_id, verb, target, purpose)— before the write.ALLOW→ you get a 90-secondauthTokenbound to that exact write.writ_verify_token(auth_token, verb, target, purpose)— immediately before executing, to prove the authorization still matches what you're doing.DENY→ do not proceed.STEP_UP→ a human sponsor approves (viawrit_grantor the dashboard), then check again.
Tools
Try it with no key: writ_sandbox → writ_check with verb="demo_write".
Source
Public repo: withwrit/pywrit (mcp/
directory). License: MIT.
Source: mcp/README.md at commit 500c8c4
Tools
0Version history
1- v0.1.3LatestOct 2, 2026