writ

io.github.withwritv0.1.3更新于 Oct 2, 2026

Commit-time policy checks for AI agent writes (ALLOW/DENY/STEP_UP) with a tamper-evident audit log.

概览

AI 生成的概览

让助手在执行重要写入前请求提交时策略判定(ALLOW、DENY 或 STEP_UP),并留下防篡改的审计记录。

功能
Writ 是一个供兼容 MCP 的助手在执行重要写入前调用的闸门。助手通过 writ_check 传入发起方、代理、动作、目标和用途,得到 ALLOW、DENY 或 STEP_UP;返回 ALLOW 时会给出一个 90 秒、绑定该次写入的令牌,执行前再用 writ_verify_token 复核。发起方工具可批准 STEP_UP、撤销或恢复某个主体,助手侧工具可读取回执与租户动作策略。writ_sandbox 提供无需密钥的免费演示授权。
适用场景
适用于助手执行需要在动作发生点获得授权、而不只是安装时授权的写入操作,并且希望每次尝试都有判定记录的场景。适合需要对敏感操作加入人工审批环节、并保留允许或拒绝审计轨迹的团队。
运行要求
以 stdio 方式在本地运行 PyPI 包 writ-mcp 提供的 writ-mcp 命令,需要 Python 3.9+(可用 uvx 安装)。必须在环境变量 WRIT_API_KEY 中提供 Writ API 密钥;发起方工具还需要 WRIT_SPONSOR_TOKEN。WRIT_BASE_URL 可覆盖默认 API 地址,因此需要能访问 Writ API 的网络。
安装前请注意
WRIT_API_KEY 与 WRIT_SPONSOR_TOKEN 是作为环境变量传入的机密,不应泄露。判定与回执会发送到第三方服务 Writ API,因此动作、目标和用途等写入元数据会离开本机。发起方工具可授予、撤销或恢复主体权限,从而改变谁可以执行操作;收到 DENY 时不得继续写入,STEP_UP 需人工批准后再重试。

安装

在 SourceWeft 中

  1. 打开 控制台中的 writ,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

writ-mcp

The Writ gate as an MCP server. Give any MCP-compatible agent point-of-action control: the agent calls Writ before a consequential write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an audit receipt.

Install

bash
pip install writ-mcp

Requires Python 3.9+. Installs the writ-mcp command (stdio transport).

Configure

bash
export WRIT_API_KEY="writ_..."        # required; get one free: POST /v1/keys with an emailexport WRIT_SPONSOR_TOKEN="..."       # only for sponsor tools (grant, revoke, reinstate)# export WRIT_BASE_URL="..."          # default: https://api.withwrit.com

Add to your agent

Claude Code:

bash
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp

Claude Desktop (claude_desktop_config.json):

json
{  "mcpServers": {    "writ": {      "command": "writ-mcp",      "env": { "WRIT_API_KEY": "writ_..." }    }  }}

Any MCP client (generic stdio config):

json
{  "command": "writ-mcp",  "env": {    "WRIT_API_KEY": "writ_...",    "WRIT_SPONSOR_TOKEN": "writ_sp_..."  }}

Hermes (NousResearch/hermes-agent) catalog entry — once published, this package is installable from the optional-mcps catalog:

bash
hermes mcp install writ

The check-before-write loop

The tool descriptions teach the agent this flow, but the short version:

  1. writ_check(sponsor_id, agent_id, verb, target, purpose) — before the write.
  2. ALLOW → you get a 90-second authToken bound to that exact write.
  3. writ_verify_token(auth_token, verb, target, purpose) — immediately before executing, to prove the authorization still matches what you're doing.
  4. DENY → do not proceed. STEP_UP → a human sponsor approves (via writ_grant or the dashboard), then check again.

Tools

ToolWhoWhat
writ_checkagentDecision + 90s purpose-bound token
writ_verify_tokenagentPoint-of-action token verification
writ_grantsponsorApprove a STEP_UP (one-time grant)
writ_revoke / writ_reinstatesponsorKill switch on/off for a principal
writ_receiptsagentAudit trail of decisions
writ_policyagentTenant verb policy
writ_sandboxanyoneFree 90-second demo grant, no key needed

Try it with no key: writ_sandbox → writ_check with verb="demo_write".

Source

Public repo: withwrit/pywrit (mcp/ directory). License: MIT.

来源:mcp/README.md,提交 500c8c4

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.3最新Oct 2, 2026