Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ⚖️ Legal
  3. PolicyForge MCP Server
PolicyForge MCP Server logo
Health: ActiveRecent health check succeeded.Last checked 9/21/2026, 7:46:43 PM

PolicyForge MCP Server

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time — check back soon.
View RepositoryVisit Website

Generate, audit, and maintain legal policies that match what your code actually does.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON ▾

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "mcp-52": {
      "command": "npx",
      "args": [
        "-y",
        "@policyforge/mcp@latest"
      ]
    }
  }
}

💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Tool Schemas (15) Directory Badge Claim listing Alternatives⚖️ More in Legal

Capabilities & Tool Schemas (15) ~407 tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server — may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by PolicyForge MCP Server.

generate_policy

Generate a policy and return its Markdown content + hosted URL. Consumes one policy from your quota.

generate_baa

Generate a HIPAA Business Associate Agreement between a covered entity and a vendor handling PHI. Built from the clauses required by 45 CFR 164.504(e) and validated clause by clause. Pro plan; never publicly hosted. Consumes one policy from your quota.

regenerate_policy

Re-run the AI engine with changed business context — same ID and hosted URL, previous content saved as a version.

update_policy

Hand-edit a policy in place — same ID and hosted URL, so published links keep working.

audit_compliance

Gap analysis: compare what the code does (your scanned manifest) with what a policy discloses.

check_policy_freshness

Drift detection: diff the current codebase scan against the manifest stored at generation time.

Documentation Overview

PolicyForge MCP Server

Generate legal policies — privacy policies, terms of service, cookie policies, refund policies, EULAs, disclaimers, and HIPAA Business Associate Agreements — directly from your AI coding tools (Claude Code, Cursor, Windsurf, Claude Desktop) via the Model Context Protocol.

Ask your agent "generate a GDPR + CCPA privacy policy for this app" and it fills the details from your codebase, calls PolicyForge, and drops the policy straight into your project.

Try it free: compliance audits (audit_compliance), drift checks (check_policy_freshness), and the scan rubric (get_disclosure_checklist) are unlimited and never touch your quota — start with "audit our compliance — does the privacy policy cover everything this code actually does?". And the first time your account connects through MCP it gets 3 bonus policy generations on top of the free 2/month — enough to generate privacy, terms, and cookie policies for a new project in one conversation.

Connect

Pick the row that matches your client. If you're unsure, start with A.

How you sign inBest for
A. Remote + OAuthBrowser sign-in, no key to copyClients that support OAuth (Claude, ChatGPT)
B. Remote + API keyAuthorization headerAny client that can send a header
C. Local (npx)POLICYFORGE_API_KEY env varRunning the server as a local process

All three expose the same tools. A and B need nothing installed.

A. Remote with OAuth (easiest)

No key to copy, no config file to edit. You'll need a PolicyForge account first — https://policyforge.co, free, no card.

1. Add the server. The -s user makes it available in every project rather than only the directory you ran this in:

Terminal
claude mcp add -s user --transport http policyforge https://policyforge.co/api/mcp

Note there is no --header. Omitting it is what makes the client use OAuth.

2. Restart your client. MCP config is read at startup, so a session that was already running won't see the new server.

3. Authenticate. Run /mcp, select policyforge, and press Enter:

Code
policyforge · △ needs authentication

Your browser opens, you sign in and approve, and the client stores the token itself. You should land back at /mcp showing ✔ connected · 15 tools.

To confirm from the other side, a key named MCP · <your client> appears at https://policyforge.co/api-dashboard — that's the grant, and deleting it revokes access.

Other clients differ in step 3: some prompt on first tool use rather than offering an explicit authenticate action.

B. Remote with an API key

For clients that don't do OAuth yet. Create a key at https://policyforge.co/api-dashboard, then:

Terminal
claude mcp add --transport http policyforge https://policyforge.co/api/mcp \
  --header "Authorization: Bearer pf_your_key_here"

For clients with URL-based MCP config (Cursor, Windsurf, and others):

config.json
{
  "mcpServers": {
    "policyforge": {
      "url": "https://policyforge.co/api/mcp",
      "headers": { "Authorization": "Bearer pf_your_key_here" }
    }
  }
}

C. Local (npx)

Prefer a local process? The server runs via npx — nothing to install globally. Uses an API key from the environment, which is what the MCP spec recommends for stdio transports.

Claude Code

Terminal
claude mcp add policyforge \
  --env POLICYFORGE_API_KEY=your_key_here \
  -- npx -y @policyforge/mcp@latest

Cursor / Claude Desktop / Windsurf

Add to your MCP config (.cursor/mcp.json, claude_desktop_config.json, etc.):

config.json
{
  "mcpServers": {
    "policyforge": {
      "command": "npx",
      "args": ["-y", "@policyforge/mcp@latest"],
      "env": {
        "POLICYFORGE_API_KEY": "your_key_here"
      }
    }
  }
}

On Windows, some clients need the command wrapped: set "command": "cmd" and "args": ["/c", "npx", "-y", "@policyforge/mcp@latest"].

See https://policyforge.co/mcp for one-click installs (Cursor/VS Code) and per-client instructions — with your API key pre-filled when signed in.

Troubleshooting

  • 401 — if you connected with OAuth, the authorization was revoked or expired: reconnect and approve again. If you used an API key, it was deleted, disabled, or mistyped (keys start with pf_) — rotate or create one at https://policyforge.co/api-dashboard and restart the client.
  • 402 — generation quota exhausted. Free tier: 2 generations per calendar month, plus a one-time bonus of 3 extra generations on first MCP connect. Only generate_policy/regenerate_policy consume quota — audits and drift checks are free; ask your agent to run get_usage to see what's left.
  • 429 — request rate limit (free tier: 10/minute, 100/day); the response includes retry_after.
  • Server not listed in /mcp — either the session started before you added it (restart the client; config is read at startup), or it was added to a different project scope. claude mcp add -s user … makes it available everywhere.
  • Tools missing — restart the client after config changes; on Windows use the cmd wrapper above.
  • "The redirect URI is not registered for this application" — the client is using a callback URL we haven't seen. Loopback callbacks work on any port (per RFC 8252), so this should be rare; report the exact URI and it can be supported.

More detail: https://policyforge.co/mcp#troubleshooting

Tools

ToolWhat it does
generate_policyGenerate a policy and return its Markdown content + hosted URL. Consumes one policy from your quota.
generate_baaGenerate a HIPAA Business Associate Agreement between a covered entity and a vendor handling PHI. Built from the clauses required by 45 CFR 164.504(e) and validated clause by clause. Pro plan; never publicly hosted. Consumes one policy from your quota.
regenerate_policyRe-run the AI engine with changed business context — same ID and hosted URL, previous content saved as a version.
update_policyHand-edit a policy in place — same ID and hosted URL, so published links keep working.
audit_complianceGap analysis: compare what the code does (your scanned manifest) with what a policy discloses.
check_policy_freshnessDrift detection: diff the current codebase scan against the manifest stored at generation time.
list_policy_versionsVersion history — a snapshot is saved before every update, regeneration, or restore.
restore_policy_versionRoll a policy back to any previous version (itself reversible).
list_policiesList policies on your account (filter by type/status, paginate).
get_policyFetch a single policy by ID, including full content.
delete_policyPermanently delete a policy (its hosted URL stops working).
get_usageCheck your tier and remaining generation quota before generating.
get_disclosure_checklistThe codebase-scan rubric: which SDKs/patterns require disclosure and how findings map to generate_policy fields.
get_integration_guideCopy-paste embed/link instructions for Next.js, React, plain HTML, or WordPress.
list_policy_typesList supported policy types, business types, and jurisdictions.

The codebase-aware workflow

Your agent can read your project — so policies come from what the code actually does, not what you remember it doing:

  1. get_disclosure_checklist → agent scans dependencies, script tags, cookie writes, and outbound hosts against the rubric, and builds a stack manifest of what it found
  2. generate_policy with the detected context + stack_manifest (stored server-side for drift detection)
  3. get_integration_guide → agent wires the hosted policy into your footer
  4. Later, after the stack changes: check_policy_freshness reports the drift, audit_compliance shows the concrete gaps, and regenerate_policy fixes them — same hosted URL, no broken links, previous version restorable

generate_policy inputs

Required: type, business_type, jurisdiction, company_name, contact_email

  • type — privacy_policy · terms_of_service · cookie_policy · refund_policy · eula · disclaimer
  • business_type — e-commerce · saas · healthcare · education · financial · fintech · real-estate · non-profit · consulting · media · mobile_app · other
  • jurisdiction — one or more of gdpr ccpa pipeda lgpd us eu ca uk au br global (comma-separate to combine, e.g. gdpr,ccpa)

Optional context (improves output): website_url, service_description, data_collection[], third_party_integrations[], data_retention, user_accounts, payments, marketing, analytics, cookies, children_data, sells_data, target_audience[], security_measures[], governing_law, physical_address, dpo_email, consent_tracking, hosting_enabled.

generate_baa inputs

A Business Associate Agreement is a contract between two named parties, not a published policy, so it takes its own tool and its own fields. Pro plan.

Required: acknowledge_contract (must be true), baa_direction, company_name, contact_email, both parties' legal names and addresses, baa_effective_date (YYYY-MM-DD), baa_services_description, baa_phi_types[], baa_permitted_uses[], baa_governing_law_state.

  • baa_direction — covered_entity_to_vendor (you are the practice issuing the agreement) or business_associate_to_client (you are the vendor offering it to a healthcare client)
  • baa_phi_types[] — categories of PHI involved. Including "Substance use treatment records (42 CFR Part 2)" adds a Part 2 addendum
  • baa_permitted_uses[] — anything not listed here is not permitted by the agreement (45 CFR 164.504(e)(2)(i))

Read the full README →View source on GitHub →

Related MCP Servers

View all in Legal View all alternatives
  • License Verify MCP logoLicense Verify MCP

    Verify a US contractor's license, surety bond, and insurance from official state data (WA L&I live, CA CSLB beta). Agent-payable pay-per-success, MCP-native.

    ⚖️ Legal3 views
    Compare vs License Verify MCP →
  • Entscheidsuche — Schweizer Gerichtsentscheide logoEntscheidsuche — Schweizer Gerichtsentscheide

    Suche in Schweizer Gerichtsentscheiden aller Instanzen (Bund, Kantone) in DE/FR/IT.

    ⚖️ Legal1 views
    Compare vs Entscheidsuche — Schweizer Gerichtsentscheide →
  • Registeroracle logoRegisteroracle

    RegisterOracle - 10-tool DORA Art.28 register: ICT third-party, contracts, criticality.

    ⚖️ Legal0 views
    Compare vs Registeroracle →
  • Australian Law MCP logoAustralian Law MCP

    Read Australian Commonwealth law as it stood on any date, and verify citations against the register

    ⚖️ Legal1 views
    Compare vs Australian Law MCP →

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks — not a rating.

Last commit
22d ago
Most recent push to the default branch.
Tools exposed
15
Callable tools this server registers over MCP.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about PolicyForge MCP Server

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "policyforge-mcp-server": { "command": "npx", "args": ["-y","@policyforge/mcp@latest"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewPolicyForge MCP Server AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/mcp-52?style=directory)](https://allmcps.com/mcp/mcp-52)
HTML Embed
<a href="https://allmcps.com/mcp/mcp-52"><img src="https://allmcps.com/api/badge/mcp-52?style=directory" alt="PolicyForge MCP Server on AllMCPs" /></a>

Technical Specs & Signals

Category⚖️Legal
More technical detailsExpand ▾
TransportSTDIO
RuntimeNode.js
Last updatedSep 2, 2026
12/12 checks healthy over the last 45d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit22d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 2, 2026
52Quality signal: Good · 52/100How this signal is calculated ▾
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools25/30
Adoption & activity4/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 6d ago via OSV.dev · @policyforge/mcp@latest (npm)

★ FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ⚖️ Legal →Best MCP servers for Legal →Alternatives to PolicyForge MCP Server →Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients