MCP policy proxy: spend caps, approvals for destructive tools, kill switch, dry-run, audit log.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
60 seconds to a safe first run. Your agent already has an MCP config. Put agentguard in front of it, run the agent once in dry-run, and read what it would have done:
agentguard is an MCP policy proxy for agents that touch production. It sits between the agent and its MCP servers, sees every tool call, and enforces one YAML file:
spend_usd across every provider, from tool arguments (stripe_create_charge.amount), tool results (cost_usd), and — with the SDK's guarded fetch — LLM token usage from OpenAI, Anthropic and Gemini responses. The call that would exceed the cap gets CAP_EXCEEDED with the remaining budget.approval.tools: [crm_delete_*] makes the agent get APPROVAL_REQUIRED + an id; a human runs agentguard approve <id> (or clicks the button in Slack) and the agent's identical retry goes through once.agentguard kill (a file), AGENTGUARD_KILL=1 (env), or POST /kill (HTTP): every run halts instantly with KILLED until agentguard resume.agk_… key with its own allowlist, denylist and caps. Only the key's hash lives in the policy.agentguard diff shows what would have changed.(tool, normalized args) 3× in the last 30 calls, or an A→B→A→B cycle, returns LOOP_DETECTED. Timestamps, ids, whitespace and key order are ignored.tool_calls, writes, deletes, emails, spend_usd and custom counters, per run and per day.prev_hash and hash; agentguard verify proves no entry was edited, removed from the middle, or reordered (see Limits for what a local chain cannot prove on its own).No LLM calls. No phone-home. No account. MIT.
Two install paths, one policy engine: the MCP proxy (npx @agentwares/agentguard, stdio + Streamable HTTP, multiple upstreams) and the SDK/middleware (@agentwares/agentguard-sdk) for OpenAI Agents SDK, LangChain or plain-function tools that never go through MCP.
init writes agentguard.yaml next to your config, backs the config up (*.agentguard-backup), and replaces its servers with one entry:
Tools keep their names (prefixed <upstream>__ only on collision). Your MCP client sees one server; agentguard connects to all of them and holds their credentials.
Spawned with no arguments at all — what an install from the MCP registry does — agentguard serves the same stdio proxy and reads AGENTGUARD_CONFIG or ./agentguard.yaml. In a terminal it prints the help instead.
Prefer HTTP (several agents, scoped keys, Slack approve buttons)? agentguard proxy --http --port 8788 and point clients at http://127.0.0.1:8788/mcp with an X-Run-Id header per run and Authorization: Bearer agk_… per agent.
agentguard init generates this file with every knob explained inline. The short form:
Classification order: classify.* patterns → MCP annotations.readOnlyHint / destructiveHint → verb heuristics (get/list/search… read, create/update/delete/send/execute… write, pay/charge/refund… + stripe_*/x402_* spend). agentguard tools prints every tool with its class and why.
Every block is an in-band tool result with isError: true and a JSON body the model can act on:
Codes: KILLED, APPROVAL_REQUIRED (retryable once approved), APPROVAL_DENIED, LOOP_DETECTED, CAP_EXCEEDED, TOOL_DENIED, UNKNOWN_TOOL, UPSTREAM_ERROR. Successful and faked results carry _meta.agentguard = { class, verb, mode, outcome, dryRun, seq, run_id }.
Run identity: X-Run-Id header (HTTP) → _meta.runId on the call → session → one id per proxy process. Per-run caps and the loop window are per run; per-day caps are per policy (and per agent).
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/agentguard-4)<a href="https://allmcps.com/mcp/agentguard-4"><img src="https://allmcps.com/api/badge/agentguard-4?style=directory" alt="Agentguard on AllMCPs" /></a>