Govern MCP tool calls with one policy

@scopebond/mcp is a proxy that sits between an MCP client and its servers. Every tools/call is checked against your policy before it reaches the upstream server; an out-of-policy call is denied and each decision is signed into a receipt. Windowed rules — a rate limit, a spend cap, a sequence — count prior calls in the session, so "at most N per window" actually binds. It is the same policy you use for Claude Code, Cursor and GitHub.

1. Proxy an MCP server

Point your MCP client at the Scopebond proxy instead of the upstream server; the proxy forwards allowed calls and denies the rest.

npx @scopebond/mcp@latest --policy .scopebond/policy.json --upstream <server-command>

2. Windowed rules bind across calls

The proxy keeps a session history of authorized calls and passes it to the verdict engine, so rate_limit, spend_limit and sequence clauses trigger — not just single-action allowlists.

What this does not do

The proxy governs calls that route through it; a client that talks to the upstream server directly is not covered. It decides on typed actions and does not inspect payload contents with DLP.

Alternatives

FAQ

Does it work with any MCP server?

It proxies an upstream MCP server and decides each tools/call; the client sees a normal MCP server.

Can I enforce a rate or spend limit across calls?

Yes. The proxy keeps a session history so windowed clauses (rate_limit, spend_limit, sequence) count prior authorized calls.

Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/mcp/test).