
Derbent
io.github.tunahanaliozturkv1.0.0更新於 Oct 2, 2026
Gate for coding agents' MCP and built-in tool calls: rules, approvals and hash-chained receipts
概覽
Derbent 是本地閘道,對編碼代理的每次工具呼叫(MCP 或內建工具)進行規則判定、核准與記錄。
- 功能
- Derbent 位於編碼代理與其工具之間,用一套規則依代理、工具與參數對每次呼叫做出允許、拒絕或詢問的判定。它把每次呼叫記錄為雜湊鏈式收據,可用 derbent verify 檢查是否被編輯、搬移或刪除,並在終端介面中等待你核准規則要求詢問的呼叫。它還提供依儲存庫共享的筆記與代理間任務交接、針對下游工具定義變更的固定(pins),以及阻止代理陷入迴圈的預算。
- 適用情境
- 如果你使用 Claude Code、Codex、GitHub Copilot CLI 或 Antigravity CLI 等編碼代理,並希望以單一政策與稽核紀錄涵蓋它們的 MCP 與內建工具呼叫,就值得加入。適合希望 git push、rm -rf 等風險命令先等待你核准,或需要防竄改代理操作紀錄的場合。
- 執行需求
- 需要 Windows、macOS 或 Linux 的本地二進位檔,可從發行版、Homebrew、Scoop 安裝,或以 Go 1.27 以上自行建置。不需要常駐程式、網路監聽、帳號或 API 金鑰;SQLite 檔案是唯一的共享狀態。安裝時執行 derbent init 為各 CLI 加入 MCP 項目與工具呼叫前掛鉤,規則存放在使用者設定目錄的 config.toml 中。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Derbent,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Derbent
One guarded pass for all your coding agents.
Every tool call that reaches Derbent, MCP or a CLI's built-in tools, is decided by one policy and written to a tamper-evident log, and the calls you care about wait for you.
Derbent guards against mistakes and prompt injection, and keeps an audit trail. It is not a sandbox: an agent that can already run shell commands as you can get around it (see Limits).
In Turkish history, a derbent was a guarded post on a mountain pass: its keepers decided who went through and kept a record of everyone who did. Derbent does the same for your coding agents' tool calls.
Claude Code, Codex, GitHub Copilot CLI and Antigravity CLI connect to Derbent as one MCP server, and your other MCP servers sit behind it. Each CLI's pre-tool hook sends its built-in tools, such as the shell and file edits, through the same gate. Every call is decided by your rules and written down.
Support for Codex and Antigravity CLI is experimental (configured from their docs, not yet checked in a real session).
It is one binary for Windows, macOS and Linux. There is no daemon and no network listener: a SQLite file is the only shared state (ADR 0001).
What you get
- Rules that allow, deny or ask, by agent, tool and argument. The first match wins. The same rules apply to MCP tools and to built-in tools such as the shell, in all four CLIs, and a repository can add project rules that only make them stricter.
- Approvals. A call your rules ask about waits until you press
ain the terminal UI, or is denied after 50 seconds by default. - Receipts. Every call gets a hash-chained receipt, and
derbent verifynames the first receipt where the chain breaks after one was edited, moved, inserted or removed. Keep the head hash it prints to catch the newest ones being deleted too.
Also:
- Shared memory and handoffs. Agents keep notes per repository and can leave tasks for each other.
- Pins hold back a downstream server's tool when its definition changes.
- Budgets stop an agent stuck in a loop.
Install
Download the binary for your system and SHA256SUMS from the
latest release, check the hash, and put it
on your PATH as derbent (derbent.exe on Windows):
Or build it with Go 1.27 or later:
Homebrew (brew install tunahanaliozturk/tap/derbent) and Scoop install it too; see
Install and set up.
Every release can be rebuilt byte for byte from its tag. Install and set up has the other systems, how to check a release, and each CLI's entries by hand.
Quick start
derbent init shows every change and asks once before it makes any. It copies each file it changes
first and never replaces an entry you already have. With --dry-run it only shows the changes. Two of
them, from a real run with the paths shortened:
It also adds the derbent gate hook to each CLI's settings; Install and set up shows
every entry. Start your agents as usual. Their calls now appear in the UI, and calls the rules ask about
wait there for you. Built-in tools says what each CLI's hook covers.
To put your other MCP servers behind the gate, so each agent needs only the one derbent entry, see
Downstream servers.
How a call is decided
Rules live in config.toml in your user config directory (%AppData%\derbent\ on Windows,
~/.config/derbent/ on Linux, ~/Library/Application Support/derbent/ on macOS). A downstream MCP
server's tools are named <server>__<tool>, and a CLI's built-in tools native__<tool>:
To see how a call would be decided before it happens:
It prints each rule and why it matches or not, down to the first match, then the project's rules,
budgets, pin and grant, and ends with verdict: ask (rule:3) for this call under the rules above. Rules covers globs, the three presets (watch,
balanced, strict), project rules, budgets and rule suggestions.
Receipts
A receipt keeps the arguments after masking secrets, and only the size and hash of what a tool returned (ADR 0004). Someone who can write the database could still rewrite the whole chain or delete the newest receipts, so keep the head hash somewhere else if you want to be able to tell later. Receipts and verify covers exports that can be checked without the database.
Commands
Overhead
Measured on GitHub's hosted runners on 2026-10-01 (Linux on an Intel Xeon Platinum 8370C, Windows on an AMD EPYC 9V74, 4 vCPUs each), median of ten runs at p50, from docs/benchmark-results:
The gate adds 499.5 µs to an MCP call on Linux and 616.0 µs on Windows, for the extra stdio hop, the rule decision, the project rules check and the receipt written to SQLite. A hook call costs about 2.1 ms more than starting the binary on Linux and 24 ms more on Windows, where most of its cost is the process start. The numbers come from one run on shared runners, and runs differ by more than one run's intervals: the day before, the same code on the same Windows CPU model put the gate 459.5 µs over a direct MCP call, against 616.0 µs here. The results page has p99, calls per second and the caveats.
Limits
The whole list, with the reasons, is under Known limits and risks. The ones to know first:
- Only calls that pass through the gate are seen. Tools a CLI never shows its hook, such as Codex's hosted web search, are outside it.
- The CLIs marked experimental at the top have entries and hook adapters that follow each CLI's documentation and have not been checked in a real session. Claude Code and Copilot CLI (1.0.88, on 2026-10-02) have.
- Argument globs match strings, not meaning:
git push*does not matchcd repo && git push. - Approvals guard against mistakes and prompt injection inside MCP. They do not stop an agent that can
already run shell commands as you: it can run
derbent approveitself. - A receipt export shows its last run unchanged only against a head you kept, and never that nothing was left out of it.
- A suggestion refuses the shells, launchers and operators it knows, but a text rule can be fooled and
those lists cannot be complete, and an
allowfor a command prefix lets any options through. - A handoff's address is a label, not an identity: any agent that can call
handoff_takecan claim every open handoff addressed to*. - Approvals depend on you watching. Unattended,
askmeans denied after the timeout. - Pins trust the first definition they see, including a new tool that an update adds to a pinned server, so name the tools you allow for a server whose updates you do not review.
- A budget can be passed by the calls in flight at the same moment.
- CI runs the tests on Windows and Linux and only builds on macOS.
For teams
A team audit trail, with receipts synced off each machine and an export for a SIEM, is an idea, not a plan. If you would use it, say so in this discussion.
Docs
- Install and set up: every system, checking a release, each CLI by hand
- Rules: rules, presets,
explain, project rules, budgets, suggestions - Approvals and the UI: keys, grants, answering from a shell
- Built-in tools: the hook, tool names per CLI, what each CLI covers
- Downstream servers and tool pins
- Receipts and verify: what a receipt holds, exports,
verify --file - Memory and handoffs
- Demo: a transcript of two real Claude Code sessions sharing one gate
- Design, the contract for the build, and the decisions behind it
Changes are listed in the changelog. To build, test or send a change, see CONTRIBUTING.md. To report a vulnerability, see SECURITY.md.
Licence
Apache 2.0. See LICENSE.
來源:README.md,提交 1103432
工具
0版本歷史
1- v1.0.0最新Oct 2, 2026

