writ

io.github.withwritv0.1.3更新於 Oct 2, 2026

Commit-time policy checks for AI agent writes (ALLOW/DENY/STEP_UP) with a tamper-evident audit log.

概覽

AI 產生的概覽

讓助理在執行重要寫入前請求提交時政策判定(ALLOW、DENY 或 STEP_UP),並留下防竄改的稽核紀錄。

功能
Writ 是一道閘門,供相容於 MCP 的助理在執行重要寫入前呼叫。助理以 writ_check 傳入發起方、代理、動作、目標與用途,取得 ALLOW、DENY 或 STEP_UP;回傳 ALLOW 時會附上一個 90 秒、綁定該次寫入的權杖,執行前再以 writ_verify_token 複核。發起方工具可核准 STEP_UP、撤銷或恢復某個主體,助理端工具則可讀取回執與租戶動作政策。writ_sandbox 提供免金鑰的免費示範授權。
適用情境
適合助理執行需要在動作發生點取得授權、而不只是在安裝時授權的寫入操作,且希望每次嘗試都有判定紀錄的情況。也適合需要在敏感操作加入人工核准步驟,並保留允許或拒絕稽核軌跡的團隊。
執行需求
以 stdio 在本機執行 PyPI 套件 writ-mcp 提供的 writ-mcp 指令,需要 Python 3.9+(可用 uvx 安裝)。必須在環境變數 WRIT_API_KEY 提供 Writ API 金鑰;發起方工具另需 WRIT_SPONSOR_TOKEN。WRIT_BASE_URL 可覆寫預設 API 位址,因此需要能連線至 Writ API 的網路。
安裝前請注意
WRIT_API_KEY 與 WRIT_SPONSOR_TOKEN 是以環境變數傳入的機密,不應外洩。判定與回執會傳送至第三方服務 Writ API,因此動作、目標與用途等寫入中繼資料會離開本機。發起方工具可授予、撤銷或恢復主體權限,改變誰能執行操作;收到 DENY 時不得繼續寫入,STEP_UP 需人工核准後再重試。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 writ,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

writ-mcp

The Writ gate as an MCP server. Give any MCP-compatible agent point-of-action control: the agent calls Writ before a consequential write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an audit receipt.

Install

bash
pip install writ-mcp

Requires Python 3.9+. Installs the writ-mcp command (stdio transport).

Configure

bash
export WRIT_API_KEY="writ_..."        # required; get one free: POST /v1/keys with an emailexport WRIT_SPONSOR_TOKEN="..."       # only for sponsor tools (grant, revoke, reinstate)# export WRIT_BASE_URL="..."          # default: https://api.withwrit.com

Add to your agent

Claude Code:

bash
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp

Claude Desktop (claude_desktop_config.json):

json
{  "mcpServers": {    "writ": {      "command": "writ-mcp",      "env": { "WRIT_API_KEY": "writ_..." }    }  }}

Any MCP client (generic stdio config):

json
{  "command": "writ-mcp",  "env": {    "WRIT_API_KEY": "writ_...",    "WRIT_SPONSOR_TOKEN": "writ_sp_..."  }}

Hermes (NousResearch/hermes-agent) catalog entry — once published, this package is installable from the optional-mcps catalog:

bash
hermes mcp install writ

The check-before-write loop

The tool descriptions teach the agent this flow, but the short version:

  1. writ_check(sponsor_id, agent_id, verb, target, purpose) — before the write.
  2. ALLOW → you get a 90-second authToken bound to that exact write.
  3. writ_verify_token(auth_token, verb, target, purpose) — immediately before executing, to prove the authorization still matches what you're doing.
  4. DENY → do not proceed. STEP_UP → a human sponsor approves (via writ_grant or the dashboard), then check again.

Tools

ToolWhoWhat
writ_checkagentDecision + 90s purpose-bound token
writ_verify_tokenagentPoint-of-action token verification
writ_grantsponsorApprove a STEP_UP (one-time grant)
writ_revoke / writ_reinstatesponsorKill switch on/off for a principal
writ_receiptsagentAudit trail of decisions
writ_policyagentTenant verb policy
writ_sandboxanyoneFree 90-second demo grant, no key needed

Try it with no key: writ_sandbox → writ_check with verb="demo_write".

Source

Public repo: withwrit/pywrit (mcp/ directory). License: MIT.

來源:mcp/README.md,提交 500c8c4

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.3最新Oct 2, 2026