Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. 🧬 Biology & Bioinformatics
  3. MCP Airlock
M
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

MCP Airlock

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time — check back soon.
View Repository

Governance proxy for MCP servers: allowlist, forced dry run, human confirmation, blast radius, audit

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON ▾
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself — its README, its docs, or a verified owner. We haven’t found those for mcp-airlock, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing Alternatives🧬 More in Biology & Bioinformatics

Documentation Overview

mcp-airlock

Русская версия

M8ven Score

mcp-airlock is a proxy you put between an AI agent and an MCP server when the server can do things you don't want an agent doing on its own. It speaks the 2026-07-28 revision of the protocol (the stateless one: no session, no initialize, one POST per request) and adds the parts the protocol leaves to you: who is allowed to call what, dry runs by default, a human in the loop for dangerous calls, an audit trail and tracing.

It is deliberately small. There is no UI, no policy language beyond flat YAML, no MCP SDK of its own. The whole proxy is one Starlette app plus a few helper modules.

How a call goes through

The agent sends a normal tools/call to the proxy instead of the server. The proxy:

  1. Works out who is calling. That comes from a JWT (Authorization: Bearer) or, if you run it behind a gateway that already did the authentication, from an X-Airlock-Principal header. It is never taken from the request body. No principal, no call.
  2. Looks the tool up in the policy. Tools that are not listed are refused. Listed tools have a risk tier per environment, so the same delete_service can be free in dev and gated in prod.
  3. Depending on the tier:
    • L0 (read) goes straight through.
    • L1 (suggest) always goes through with dry_run: true, whatever the agent asked for.
    • L2 (confirm) goes through with dry_run: true first, and the result comes back to the agent as input_required with a description of what would happen and a signed requestState. When a person says yes, the agent repeats the call with that state and the proxy executes it for real, once. Repeating it again is refused.
    • L3 (auto) goes through as sent.
  4. Checks the blast radius: how many objects one call touches (the length of a list argument you name in the policy) and how many a principal has touched in the last hour or day.
  5. Forwards the call, cuts the response down to the output cap if it is too big, and marks anything in it that smells like a prompt injection. Marking only; it does not change what the agent gets to see.
  6. Writes two audit records, one before the upstream call and one after, whatever happened.

Refusals come back as tool results with isError: true, not as protocol errors, so the model sees why and can do something else. Every result carries the verdict and the rule that produced it in _meta.

Running it

The released version, no clone needed:

Code
uvx mcp-airlock --policy policy.yaml --upstream http://127.0.0.1:8080/mcp --env prod

The same as a container. The image listens on 0.0.0.0:9000, runs as a non-root user and writes audit.jsonl into /data:

Terminal
docker run --rm -p 9000:9000 -v $PWD/policy.yaml:/data/policy.yaml \
  ghcr.io/shalimov04/mcp-airlock:0.2 --policy policy.yaml --upstream http://host.docker.internal:8080/mcp --env prod

From a checkout:

Code
uv sync
uv run pytest
uv run python demo.py

The demo starts a fake upstream with a handful of tools on port 9001 and the proxy on 9000, walks through the interesting cases (refused tool, forced dry run, confirmation, replay, blast radius, output cap, injection marking) and leaves the audit log and spans in examples/.

The short version, recorded against that same fake upstream. An agent tries to delete a production service, gets a dry run and a confirmation prompt instead, the confirmation works exactly once, and a poisoned read result comes back flagged:

demo: refused tool, forced dry run, one-shot confirmation, injection flagged

docs/make_demo_gif.py re-records it (uv run --with pillow python docs/make_demo_gif.py).

docs/clients.md shows how to point Claude Code and Cursor at the proxy and what the agent sees when a call is refused or held for confirmation.

Against a real server:

Code
uv run mcp-airlock --policy policy.example.yaml --env prod \
    --upstream http://127.0.0.1:9001/mcp --audit audit.jsonl

There are ready-made policies for the GitHub, Grafana and Kubernetes MCP servers in examples/policies/. They were written against the servers' source at a pinned commit, so check them against your actual server before trusting them:

Code
uv run airlock-policy lint examples/policies/github.yaml
uv run airlock-policy diff examples/policies/github.yaml --upstream http://127.0.0.1:8080/mcp --env prod

diff tells you which tools the server has that the policy doesn't mention, which policy entries the server no longer has, and which L1/L2 tools have no dry_run argument.

Configuration

Everything is environment variables. None are required for a single-process setup.

VariableWhat it does
AIRLOCK_ENVEnvironment name, picks the tier column in the policy. --env does the same.
AIRLOCK_JWT_SECRETVerify bearer tokens with HS256. sub becomes the principal, groups the groups.
AIRLOCK_JWKS_URL, AIRLOCK_JWT_ISSUER, AIRLOCK_JWT_AUDIENCEVerify bearer tokens against an OIDC provider (RS256/ES256). Takes precedence over the shared secret. Set the audience; without it any token from that provider is accepted.
AIRLOCK_GROUPS_CLAIMClaim to read groups from. Default groups.
AIRLOCK_TRUST_PRINCIPAL_HEADERSet to 1 to accept X-Airlock-Principal and X-Airlock-Groups. Off by default. Only turn it on behind a gateway that sets those headers itself and strips them from clients.
AIRLOCK_SECRETKey for signing confirmation tokens. Random per process if unset, which means a restart forgets pending confirmations. Set it if you run more than one replica.
AIRLOCK_STORE_DSNPostgres DSN for the shared state: used confirmation keys, approvals, blast-radius counters. Without it the state lives in process memory.
AIRLOCK_AUDIT_DSNPostgres DSN for the audit log, in addition to the JSONL file.
AIRLOCK_APPROVAL_WEBHOOKSlack-style incoming webhook, or a Telegram bot<token>/sendMessage URL. Confirmation prompts are posted there with an approve link.
AIRLOCK_TELEGRAM_CHATChat id for the Telegram case.
AIRLOCK_PUBLIC_URLBase URL for approve links. Default http://127.0.0.1:9000.
AIRLOCK_UPSTREAM_AUTHValue of the Authorization header sent to the upstream. This is the proxy's own credential; the caller's identity travels in _meta instead.

The policy file

yaml
version: 1
environment: prod
output:       { max_chars: 16000, chars_per_token: 4 }
blast_radius: { max_per_call: 50, max_per_principal: 500, window_s: 3600 }
tools:
  get_service:
    tiers: { dev: L0, staging: L0, prod: L0 }
    output: { max_chars: 5000 }
  set_replicas:
    description: scale services up/down (reversible)
    tiers: { dev: L3, staging: L1, prod: L2 }
    principals:
      "group:oncall": { prod: L3 }      # on-call people skip the confirmation in prod
    count_arg: names                     # objects per call = len(arguments.names)
    blast_radius: { max_per_call: 3, max_per_principal: 5, window_s: 3600 }
  delete_service:
    description: permanently delete a service (irreversible)
    tiers: { dev: L2, prod: L2 }         # nothing for staging, so it is refused there

A tier is resolved in this order: an entry for the exact principal, then the first matching group in the order the token lists them, then tiers[environment]. The description is what the person approving the call gets to read, so write it for them.

Rule ids you will see in _meta and the audit log: allowlist.deny, tier.unassigned, tier.L0.read, tier.L1.dry_run, tier.L2.confirm, tier.L2.confirmed, tier.L2.dry_run, tier.L3.auto, blast_radius.per_call, blast_radius.per_principal, dry_run.unsupported, catalog.unavailable, principal.missing, protocol.<code>, mrtr.pending, mrtr.declined, mrtr.replay, mrtr.expired, mrtr.mismatch, mrtr.bad_signature, mrtr.approved_oob, mrtr.upstream_input_required, internal.error.

Confirmations in detail

The confirmation token (requestState) is an HMAC-signed blob carrying the principal, the tool, a hash of the arguments, the environment, the upstream URL, a random idempotency key and an expiry (10 minutes). Nothing is stored when it is issued. When it comes back the proxy checks the signature, checks that all of those still match the call in front of it, re-runs the policy, burns the key, then charges the blast-radius counter. Burning is an atomic insert in the store, so two replicas cannot both execute the same confirmation. A decline burns the key too.

Before the prompt is issued the proxy asks the upstream for tools/list and looks at the tool's schema. If the tool declares dry_run, the dry run is forwarded and its output is included in the prompt. If it doesn't (most servers today), nothing is forwarded and the person is asked to confirm without a preview. L1 on such a tool is refused, since there is no safe way to run it. If the upstream cannot be asked at all, the call is refused with catalog.unavailable rather than guessed at. The tools/list answer is cached for as long as the upstream's ttlMs says, per principal; with ttlMs: 0 it is fetched on every gated call. If the tool mirrors dry_run into an Mcp-Param-* header, the proxy rewrites that header along with the body.

Read the full README →View source on GitHub →

Related MCP Servers

View all in Biology & Bioinformatics View all alternatives
  • P
    Prism

    Local-first repo intelligence for agents: DNA, health, blast radius, and Dispatch jobs.

    🧬 Biology & Bioinformatics2 views
    Compare vs Prism →
  • S
    Sourcebook

    Live codebase intelligence for AI agents: conventions, blast radius, import graphs, git insights.

    🧬 Biology & Bioinformatics0 views
    Compare vs Sourcebook →
  • D
    Dep Oracle

    Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis.

    🧬 Biology & Bioinformatics1 views
    Compare vs Dep Oracle →
  • C
    Causely

    Causal reasoning for reliability: root cause, blast radius, and service health for agents.

    🧬 Biology & Bioinformatics0 views
    Compare vs Causely →

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Airlock

We don't have a confirmed install command for mcp-airlock yet, so we don't publish a generated one — a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/Shalimov04/mcp-airlock) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Airlock AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/mcp-airlock?style=directory)](https://allmcps.com/mcp/mcp-airlock)
HTML Embed
<a href="https://allmcps.com/mcp/mcp-airlock"><img src="https://allmcps.com/api/badge/mcp-airlock?style=directory" alt="MCP Airlock on AllMCPs" /></a>

Technical Specs & Signals

Category🧬Biology & Bioinformatics
More technical detailsExpand ▾
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
28Quality signal: Emerging · 28/100How this signal is calculated ▾
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools12/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

★ Featured
A

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in 🧬 Biology & Bioinformatics →Alternatives to MCP Airlock →Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients