Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Explore

  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Tags index
  • Submit a server
  • Pricing

Learn

  • Guides hub
  • What is MCP?
  • Install guide
  • Troubleshooting
  • Security
  • Blog
  • Blog RSS

Tools

  • All tools
  • Config generator
  • Config validator
  • MCP playground
  • OpenAPI β†’ MCP
  • Badge generator

For agents

  • API docs
  • Trust & traffic
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
  • Remote MCP β†— (opens in a new tab)

Company

  • About
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on Buildlist
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Mcp Bastion
M
Health: ActiveRecent health check succeeded.Last checked 8/11/2026, 12:01:10 AM

Mcp Bastion

Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository6 GitHub StarsTotal stargazers on GitHub for the source repository (6 stars).

Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Install Config Generator

Choose your client
claude_desktop_config.json
{
  "mcpServers": {
    "mcp-bastion": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-bastion",
        "--config",
        "bastion.config.json"
      ]
    }
  }
}

πŸ’‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

πŸ›‘οΈ mcp-bastion

A reliability & security proxy for the Model Context Protocol (MCP).

Self-healing connections, runtime tool-security, and a compliance-mapped audit trail for your MCP servers.

npm version npm downloads MCP Registry Measured coverage CI License Node TypeScript PRs welcome


mcp-bastion: an MCP server crashes mid-session and the agent recovers it automatically

mcp-bastion sits between your MCP client (Claude Code, Cursor, Cline, Windsurf, Zed, Claude Desktop, or any MCP-compliant agent) and your MCP servers. It is client-agnostic β€” it works with any compliant client through configuration alone, with zero client-specific code β€” and non-invasive: your servers run unchanged, and removing Bastion is a one-line config revert.

πŸ“¦ Package: mcp-bastion on npm Β· πŸ—‚οΈ Official MCP Registry: io.github.Gowthaman90/mcp-bastion

πŸ”’ Security, measured: on the open, vendor-neutral mcp-defense-bench, Bastion covers 63% of the MCP attack surface (15.0/24 vectors; 11 enforced) at zero false positives β€” the broadest of the proxies measured.

πŸ“– Launch story: Medium Β· dev.to

πŸ‘€ Created & maintained by Gowthaman Arumugam β€” Independent Researcher. Companion benchmark: mcp-defense-bench.

Contents

  • Why
  • How it works
  • Features
  • Quick start
  • Demo
  • Control tools
  • Configuration
  • Transports
  • Runtime security
  • Audit & compliance
  • Client setup
  • Architecture
  • Development
  • Roadmap
  • Contributing
  • Security
  • License

Why

When an MCP server disconnects mid-session, the agent only sees a generic "No such tool available" error β€” indistinguishable from a tool that never existed β€” and it cannot reconnect; only a human can. Long agent sessions silently lose capabilities and fail in confusing ways.

Bastion closes that gap. It health-checks every server, auto-reconnects with backoff, and β€” crucially β€” exposes control tools so the agent itself can inspect connection health and recover a dropped server without human intervention.

Bastion now spans three layers: reliability (v0.1), runtime security (v0.2 β€” tool pinning / rug-pull & poisoning detection), and audit & compliance (v0.3 β€” pluggable sinks mapped to NIST AI RMF / OWASP LLM Top 10). See the roadmap.

How it works

Today your client connects directly to each server. With Bastion, your client connects to Bastion, which connects to those same servers on your behalf β€” so it sits in the tool-call path and can add reliability (and, later, security) transparently.

Code
Before:   Client ─▢ server A / server B / server C

After:    Client ─▢ mcp-bastion ─▢ server A
                                  ─▢ server B
                                  ─▢ server C

Bastion is a standard MCP server to your client and a standard MCP client to each upstream. Because it speaks the protocol faithfully, it works with every compliant client automatically β€” the only per-client difference is where you put a few lines of config.

Features

  • πŸ”Œ Client-agnostic β€” one binary, config-only integration; no per-client plugins.
  • ♻️ Self-healing β€” health checks + capped exponential-backoff auto-reconnect for stdio servers.
  • 🧭 Agent-recoverable β€” bastion__status and bastion__reconnect let the agent detect and fix drops itself, instead of hitting an opaque "no such tool" wall.
  • 🧩 Transparent aggregation β€” merges many servers into one, with per-server tool namespacing to prevent collisions and tool-shadowing.
  • πŸ’¬ Legible failures β€” a dropped server yields an actionable message, not a crash.
  • πŸ›‘οΈ Runtime security (new in v0.2) β€” pins each tool's definition and blocks "rug pulls" (a server changing a tool after approval); heuristically inspects descriptions for poisoning; detects cross-server shadowing. See Runtime security.
  • πŸ“ Audit & compliance (new in v0.3, opt-in) β€” structured, integrity-hash-chained audit events to pluggable sinks (console / file / webhook), mapped to NIST AI RMF & OWASP LLM Top 10. See Audit & compliance.
  • πŸͺΆ Non-invasive & reversible β€” your servers run unchanged; uninstall is a config revert.
  • 🧱 Enterprise-grade codebase β€” strict TypeScript, layered architecture, ESLint + Prettier, and unit + end-to-end tests.

Quick start

Bastion is published on npm as mcp-bastion β€” the npx command below fetches it automatically, so there's nothing to install first.

1. Add Bastion to your client, pointing it at a config file:

jsonc
// your client's mcpServers config
{
  "mcpServers": {
    "bastion": {
      "command": "npx",
      "args": ["-y", "mcp-bastion", "--config", "bastion.config.json"],
    },
  },
}

2. List your real servers in bastion.config.json (moved verbatim from the client):

JSON Config
{
  "servers": {
    "github": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"] },
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path/to/dir"],
    },
  },
  "reconnect": { "auto": true },
  "healthCheck": { "enabled": true },
}

3. Restart your client. Your tools now appear namespaced (e.g. github__create_issue) alongside Bastion's control tools. See bastion.config.example.json for the full set of options.

πŸ”’ Security is on by default. Out of the box, Bastion runs the balanced enforcement profile: it blocks high-confidence attacks (rug-pulls, argument/command injection, cross-server exfiltration) and warns on heuristic ones (description/response poisoning), while redacting leaked secrets from tool results. Set security.enforcementProfile to observe (warn-only) or strict (block-all), or tune any individual control β€” see Runtime security.

Demo

See the whole thing in action β€” a server crashing mid-session and healing itself:

Terminal
npm run demo

It boots Bastion in front of a server that crashes on command, shows the agent getting an actionable "reconnect" message instead of a cryptic error, and then the connection auto-recovering with no human involved. To record it as a GIF: asciinema rec demo.cast -c "npm run demo" && agg demo.cast assets/demo.gif.

Control tools

Bastion injects control tools so the agent can manage connections and review security itself, using only standard MCP calls:

ToolPurpose
bastion__statusHealth of every proxied server: connected / disconnected / reconnecting / failed, tool counts, last error.
bastion__reconnectReconnect a named server (argument: { "server": "<name>" }) without human intervention.
bastion__securityPer-tool security report: pin status (approved vs changed), poisoning findings, and shadowing.
bastion__complianceAudit summary of recent activity mapped to NIST AI RMF / OWASP LLM Top 10 (requires audit.enabled).

Re-approval is operator-only. Clearing a rug-pull block is a security authority, so it is not an agent-callable tool β€” a prompt-injected agent must not be able to re-approve the very tool it was blocked from. A changed tool stays blocked until an operator clears it out-of-band; bastion__approve is not advertised and a client call to it is refused.

Configuration

KeyTypeDefaultDescription
serversmapβ€”Upstream servers to proxy (required, at least one).
servers.<name>.commandstringβ€”Executable to launch (e.g. npx, node).
servers.<name>.argsstring[][]Arguments to command.
servers.<name>.envmapβ€”Env overrides merged over the process env.
servers.<name>.cwdstringβ€”Working directory for the spawned process.
reconnect.autobooleantrueAuto-reconnect after an unexpected disconnect.
reconnect.maxRetriesnumber10Max attempts before giving up (-1 = unlimited).
reconnect.initialBackoffMsnumber500Initial backoff, doubled each attempt.
reconnect.maxBackoffMsnumber30000Backoff ceiling.
healthCheck.enabledbooleantrueEnable periodic liveness probing.
healthCheck.intervalMsnumber30000Interval between probes.
healthCheck.timeoutMsnumber5000Per-probe timeout.
namespace.strategyprefix | passthroughprefixHow upstream tool names are exposed.
namespace.separatorstring__Separator used by the prefix strategy.
security.pinToolsbooleantruePin tool definitions and detect later changes.
security.onRugPullblock | warnblockAction when a pinned tool's definition changed.
security.inspectDescriptionsbooleantrueRun poisoning heuristics on tool descriptions.
security.onPoisoningblock | warnwarnAction on a high-severity poisoning finding.
audit.enabledbooleanfalseRecord an audit event for every tool call.
audit.includeArgsnone|redacted|fullnoneHow tool arguments are recorded.
audit.tamperEvidentbooleanfalseHash-chain events so tampering is detectable.
audit.sinksarrayconsoleDestinations: console, file, webhook, otlp.
servers.<name>.transportstdio | httpstdioLocal subprocess or remote endpoint.
servers.<name>.urlstringβ€”Remote MCP URL (required for http).
servers.<name>.headersmapβ€”Headers for http upstreams (e.g. Authorization).
listen.modestdio | httpstdioServe Bastion over stdio or Streamable HTTP.
listen.host / listen.portstring / number127.0.0.1 / 3000Bind address for http mode.

Transports

Bastion speaks two transports on both faces:

  • stdio (default) β€” the client spawns Bastion, and Bastion spawns local servers.
  • Streamable HTTP β€” connect to remote MCP servers (servers.<name> with transport: "http", a url, and optional auth headers), and/or serve Bastion over HTTP to multiple/remote clients (listen.mode: "http", or --http <port>).

HTTP upstreams configured without an authentication header are flagged (authenticated: false) in bastion__status and warned at connect time.

Runtime security

New in v0.2. Bastion adds a security layer in the tool-call path (an interceptor pipeline), enabled by default:

  • Rug-pull detection (tool pinning). Each tool's definition is pinned on first use. If a server later changes that definition, the tool is blocked (onRugPull: "block") until an operator reviews it and re-approves it out-of-band (operator-only β€” not an agent-callable tool). This catches a server that looks benign at install time and turns malicious afterward.
  • Poisoning inspection. Tool names and descriptions are scanned for manipulation heuristics (instruction override, secret access, data exfiltration, covert instructions, embedded directives, hidden/zero-width characters). Because heuristics can false-positive, the default is warn (logged and reported, not blocked); set onPoisoning: "block" to enforce.
  • Shadowing. When two servers expose a tool with the same name, it's surfaced in the report.

Review everything with the bastion__security tool. These checks apply to local stdio servers today; authentication checks for remote servers arrive with HTTP transport support.

Audit & compliance

New in v0.3, opt-in. Enable audit to record a structured, versioned event for every tool call β€” including calls blocked by the security layer:

jsonc
"audit": {
  "enabled": true,
  "includeArgs": "redacted",     // none | redacted | full
  "tamperEvident": true,          // integrity hash-chain (detects naive edits; unkeyed, not signed)
  "sinks": [
    { "type": "file", "path": "./bastion-audit.jsonl" },
    { "type": "webhook", "url": "https://collector.example/v1/audit" }
  ]
}
  • Pluggable sinks. console (stderr JSONL), file (JSONL append), webhook (batched POST), and otlp (native OpenTelemetry logs export β€” point it at an OTel Collector to fan out to any SIEM/cloud backend). The sink interface makes new destinations additive.
  • Compliance mapping. Each event is mapped to NIST AI RMF functions and OWASP LLM Top 10 categories; bastion__compliance returns an aggregate report of recent activity.
  • Integrity hash chain. With tamperEvident, events are linked by a SHA-256 hash chain, and the exported verifyChain helper detects naive or partial edits within an intact log. The chain is unkeyed: a party who can rewrite the log file can recompute a consistent chain, and truncating the most-recent events links cleanly β€” so treat this as corruption-detection, not cryptographic tamper-proofing. For stronger guarantees, ship events to an append-only external sink (webhook / OTLP β†’ a WORM store or SIEM). Keyed/signed attestation is on the roadmap.
  • Redaction (best-effort). Arguments are omitted by default; includeArgs: "redacted" keeps structure while masking values under known credential key-names and common secret patterns. It is a heuristic, not a guarantee β€” a secret under an unrecognized key can still be recorded, so prefer none for high-sensitivity deployments.

Standards alignment

Every security check maps to recognized frameworks β€” the NIST AI Risk Management Framework (a U.S. federal standard), the OWASP Top 10 for LLM (2025) and Agentic (2026) Applications, and STRIDE. The full per-check mapping (with reference links to the MCP-security literature the checks are drawn from) is in docs/CHECKS-MAPPING.md.

Coverage is measured independently β€” bastion is scored against a 22-vector attack surface by the vendor-neutral mcp-defense-bench benchmark, with a public leaderboard and framework mapping.

Client setup

The steps are identical for every client β€” only the config file location differs:

ClientWhere to add the bastion entry
Claude Codeproject .mcp.json (or claude mcp add)
Cursor~/.cursor/mcp.json or project .cursor/mcp.json
Claude Desktopclaude_desktop_config.json
Clinecline_mcp_settings.json
Windsurf~/.codeium/windsurf/mcp_config.json

Gradual adoption: you don't have to route every server through Bastion β€” put only your flaky or untrusted servers behind it and leave the rest connected directly.

Architecture

Bastion is organized into clear layers with a one-directional dependency flow, so each concern is independently testable and easy to evolve:

Code
src/
β”œβ”€β”€ cli.ts              # thin CLI entrypoint (parse β†’ wire β†’ serve)
β”œβ”€β”€ index.ts            # public library API
β”œβ”€β”€ errors.ts           # error hierarchy (BastionError, …)
β”œβ”€β”€ config/             # schema (Zod) + loader
β”œβ”€β”€ core/               # domain: upstream connection lifecycle, aggregation & routing
β”œβ”€β”€ proxy/              # client-facing MCP server + control tools
β”œβ”€β”€ observability/      # logging (audit sinks in v0.3)
└── internal/           # small cross-cutting utilities

Design details β€” including the client-agnostic rationale, the interceptor pipeline, and the audit-sink strategy β€” live in the project's design docs.

Development

Terminal
npm install
npm run check      # format:check + lint + typecheck + test (the full gate)
npm test           # unit + end-to-end (in-memory transport) tests
npm run build      # bundle to dist/ (CLI + library)
npm run dev -- --config bastion.config.json
ScriptDoes
buildBundle CLI + library with tsup.
devRun the CLI from source with tsx.
typechecktsc --noEmit (strict).
lint / lint:fixESLint (flat config).
format / format:checkPrettier.
test / test:watchVitest.
checkEverything above, as one gate.

Roadmap

VersionThemeHighlights
v0.1 βœ…ReliabilityAggregating proxy, auto-reconnect, bastion__status / __reconnect.
v0.2 βœ…Runtime securityTool-definition pinning (rug-pull detection), poisoning inspection, shadowing detection.
v0.3 βœ…Audit & compliancePluggable audit sinks (console / file / webhook), NIST AI RMF / OWASP LLM Top 10 mapping.

Both stdio and Streamable HTTP transports are supported (see Transports).

Contributing

Contributions are very welcome β€” this project is built to be community-owned. Please read CONTRIBUTING.md for the dev setup, project layout, and PR workflow, and our Code of Conduct.

In short: open an issue for non-trivial changes, keep PRs focused with tests, and make sure npm run check passes (CI runs it on Node 18/20/22). Good first areas: additional client setup recipes, more upstream test fixtures, and Streamable HTTP transport support.

Security

mcp-bastion is security-adjacent software, so we hold it to a high bar. Please report vulnerabilities privately β€” do not open a public issue. See SECURITY.md for the disclosure process.

License

Apache-2.0 Β© Gowthaman Arumugam and mcp-bastion contributors

Related MCP Servers

View all in Security View all alternatives
  • D
    Delego

    Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.

    πŸ”’ Security1 views
    Compare vs Delego β†’
  • M
    Mcp Server

    Runtime authority for AI agents: credential mediation, spend cap, approval gates, audit log.

    πŸ”’ Security0 views
    Compare vs Mcp Server β†’
  • A
    Audit

    AI website growth audits: SEO, performance, AI readiness (GEO), conversion, a11y, security.

    πŸ”’ Security0 views
    Compare vs Audit β†’
  • A
    Audit

    Publisher revenue audit: ads.txt and ad-stack checks, Sulvo onboarding, and Boost ad-block recovery

    πŸ”’ Security0 views
    Compare vs Audit β†’

Frequently Asked Questions about Mcp Bastion

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "mcp-bastion": { "command": "npx", "args": ["-y", "mcp-bastion"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMcp Bastion AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/mcp-bastion?style=directory)](https://allmcps.com/mcp/mcp-bastion)
HTML Embed
<a href="https://allmcps.com/mcp/mcp-bastion"><img src="https://allmcps.com/api/badge/mcp-bastion?style=directory" alt="Mcp Bastion on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars6
GitHub Star CountTotal stargazers on GitHub representing community popularity (6 stars).
Last commit7d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 3, 2026
npm downloads1,841/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
47Quality signal: Fair Β· 47/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity9/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Free dofollow backlink: after claiming, verify your product site and place a dofollow AllMCPs badge β€” we recheck it stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Mcp Bastion β†’Install in Claude DesktopInstall in CursorInstall in VS Code