Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. MCP Bastion
MCP Bastion logo
Health: ActiveRecent health check succeeded.Last checked 9/22/2026, 3:32:42 PM

MCP Bastion

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository6 GitHub StarsTotal stargazers on GitHub for the source repository (6 stars).Visit Website

Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "mcp-bastion": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-bastion"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

πŸ›‘οΈ mcp-bastion

A reliability & security proxy for the Model Context Protocol (MCP).

Self-healing connections, runtime tool-security, and a compliance-mapped audit trail for your MCP servers.

npm version npm downloads MCP Registry Measured coverage mcp-bastion MCP server – quality and maintenance score on Glama CI License Node TypeScript PRs welcome


mcp-bastion: an MCP server crashes mid-session and the agent recovers it automatically

mcp-bastion sits between your MCP client (Claude Code, Cursor, Cline, Windsurf, Zed, Claude Desktop, or any MCP-compliant agent) and your MCP servers. It is client-agnostic β€” it works with any compliant client through configuration alone, with zero client-specific code β€” and non-invasive: your servers run unchanged, and removing Bastion is a one-line config revert.

πŸ“¦ Package: mcp-bastion on npm Β· πŸ—‚οΈ Official MCP Registry: io.github.Gowthaman90/mcp-bastion

πŸ”’ Security, measured: on the open, vendor-neutral mcp-defense-bench, Bastion covers 63% of the MCP attack surface (15.0/24 vectors; 11 enforced) at zero false positives β€” the broadest of the proxies measured.

πŸ“– Launch story: Medium Β· dev.to

πŸ‘€ Created & maintained by Gowthaman Arumugam β€” Independent Researcher. Companion benchmark: mcp-defense-bench.

Contents

  • Why
  • How it works
  • Features
  • Quick start
  • Demo
  • Control tools
  • Configuration
  • Transports
  • Runtime security
  • Audit & compliance
  • Client setup
  • Architecture
  • Development
  • Roadmap
  • Contributing
  • Security
  • License

Why

When an MCP server disconnects mid-session, the agent only sees a generic "No such tool available" error β€” indistinguishable from a tool that never existed β€” and it cannot reconnect; only a human can. Long agent sessions silently lose capabilities and fail in confusing ways.

Bastion closes that gap. It health-checks every server, auto-reconnects with backoff, and β€” crucially β€” exposes control tools so the agent itself can inspect connection health and recover a dropped server without human intervention.

Bastion now spans three layers: reliability (v0.1), runtime security (v0.2 β€” tool pinning / rug-pull & poisoning detection), and audit & compliance (v0.3 β€” pluggable sinks mapped to NIST AI RMF / OWASP LLM Top 10). See the roadmap.

How it works

Today your client connects directly to each server. With Bastion, your client connects to Bastion, which connects to those same servers on your behalf β€” so it sits in the tool-call path and can add reliability (and, later, security) transparently.

Code
Before:   Client ─▢ server A / server B / server C

After:    Client ─▢ mcp-bastion ─▢ server A
                                  ─▢ server B
                                  ─▢ server C

Bastion is a standard MCP server to your client and a standard MCP client to each upstream. Because it speaks the protocol faithfully, it works with every compliant client automatically β€” the only per-client difference is where you put a few lines of config.

Features

  • πŸ”Œ Client-agnostic β€” one binary, config-only integration; no per-client plugins.
  • ♻️ Self-healing β€” health checks + capped exponential-backoff auto-reconnect for stdio servers.
  • 🧭 Agent-recoverable β€” bastion__status and bastion__reconnect let the agent detect and fix drops itself, instead of hitting an opaque "no such tool" wall.
  • 🧩 Transparent aggregation β€” merges many servers into one, with per-server tool namespacing to prevent collisions and tool-shadowing.
  • πŸ’¬ Legible failures β€” a dropped server yields an actionable message, not a crash.
  • πŸ›‘οΈ Runtime security (new in v0.2) β€” pins each tool's definition and blocks "rug pulls" (a server changing a tool after approval); heuristically inspects descriptions for poisoning; detects cross-server shadowing. See Runtime security.
  • πŸ“ Audit & compliance (new in v0.3, opt-in) β€” structured, integrity-hash-chained audit events to pluggable sinks (console / file / webhook), mapped to NIST AI RMF & OWASP LLM Top 10. See Audit & compliance.
  • πŸͺΆ Non-invasive & reversible β€” your servers run unchanged; uninstall is a config revert.
  • 🧱 Enterprise-grade codebase β€” strict TypeScript, layered architecture, ESLint + Prettier, and unit + end-to-end tests.

Quick start

Bastion is published on npm as mcp-bastion β€” the npx command below fetches it automatically, so there's nothing to install first.

1. Add Bastion to your client, pointing it at a config file:

jsonc
// your client's mcpServers config
{
  "mcpServers": {
    "bastion": {
      "command": "npx",
      "args": ["-y", "mcp-bastion", "--config", "bastion.config.json"],
    },
  },
}

2. List your real servers in bastion.config.json (moved verbatim from the client):

JSON Config
{
  "servers": {
    "github": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-github"] },
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path/to/dir"],
    },
  },
  "reconnect": { "auto": true },
  "healthCheck": { "enabled": true },
}

3. Restart your client. Your tools now appear namespaced (e.g. github__create_issue) alongside Bastion's control tools. See bastion.config.example.json for the full set of options.

πŸ”’ Security is on by default. Out of the box, Bastion runs the balanced enforcement profile: it blocks high-confidence attacks (rug-pulls, argument/command injection, cross-server exfiltration) and warns on heuristic ones (description/response poisoning), while redacting leaked secrets from tool results. Set security.enforcementProfile to observe (warn-only) or strict (block-all), or tune any individual control β€” see Runtime security.

Demo

See the whole thing in action β€” a server crashing mid-session and healing itself:

Terminal
npm run demo

It boots Bastion in front of a server that crashes on command, shows the agent getting an actionable "reconnect" message instead of a cryptic error, and then the connection auto-recovering with no human involved. To record it as a GIF: asciinema rec demo.cast -c "npm run demo" && agg demo.cast assets/demo.gif.

Control tools

Bastion injects control tools so the agent can manage connections and review security itself, using only standard MCP calls:

ToolPurpose
bastion__statusHealth of every proxied server: connected / disconnected / reconnecting / failed, tool counts, last error.
bastion__reconnectReconnect a named server (argument: { "server": "<name>" }) without human intervention.
bastion__securityPer-tool security report: pin status (approved vs changed), poisoning findings, and shadowing.
bastion__complianceAudit summary of recent activity mapped to NIST AI RMF / OWASP LLM Top 10 (requires audit.enabled).

Re-approval is operator-only. Clearing a rug-pull block is a security authority, so it is not an agent-callable tool β€” a prompt-injected agent must not be able to re-approve the very tool it was blocked from. A changed tool stays blocked until an operator clears it out-of-band; bastion__approve is not advertised and a client call to it is refused.

Configuration

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • MCP Audit logoMCP Audit

    Transparent audit proxy for MCP servers: logs every tool call, flags poisoning and rug pulls.

    πŸ”’ Security1 views
    Compare vs MCP Audit β†’
  • Ida Pro MCP logoIda Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • MCP Slim Guard logoMCP Slim Guard

    Schema compression (83%+ savings) + security proxy for MCP servers β€” SSRF, injection, rate limit

    πŸ”’ Security1 views
    Compare vs MCP Slim Guard β†’
  • Aiseo Audit logoAiseo Audit

    Audit web pages for AI search readiness (ChatGPT, Claude, Perplexity, Gemini).

    πŸ”’ Security1 views
    Compare vs Aiseo Audit β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
6
Stargazers on the source repository.
Last commit
1mo ago
Most recent push to the default branch.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Bastion

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "mcp-bastion": { "command": "npx", "args": ["-y","mcp-bastion"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Bastion AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/mcp-bastion?style=directory)](https://allmcps.com/mcp/mcp-bastion)
HTML Embed
<a href="https://allmcps.com/mcp/mcp-bastion"><img src="https://allmcps.com/api/badge/mcp-bastion?style=directory" alt="MCP Bastion on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedAug 3, 2026
4/4 checks healthy over the last 46d
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars6
GitHub Star CountTotal stargazers on GitHub representing community popularity (6 stars).
Last commit1mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 3, 2026
40Quality signal: Fair Β· 40/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity4/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 2d ago via OSV.dev Β· mcp-bastion (npm)

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to MCP Bastion β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients