A local-first permission firewall and approval layer for AI agent tool calls.
ToolPermit is a local-first permission policy, one-time approval, and redacted audit layer for Model Context Protocol (MCP) tool calls. Put it between a local MCP client and a stdio server to observe calls, enforce explainable allow / ask / deny rules, review exceptional actions, and replay recorded calls against a candidate policy.
Current release: v0.1.1 on PyPI, with a matching GitHub Release.
English is authoritative for project contracts. See README.zh-CN.md for the Chinese feature overview and quickstart.
- Deterministic policy: strict, versioned YAML; first match wins and every result explains why. - Exact one-time approval: an approval is bound to the canonical request, policy, session, and expiry, then consumed atomically. - Redaction before storage: recognized secrets and sensitive keys are irreversibly replaced before SQLite persistence, display, or JSONL export. - Offline replay: compare policies against stored, redacted calls without starting the MCP server or executing a tool. - Local interfaces: every core workflow is available from the CLI; the optional approval UI is restricted to loopback and protected by Host, Origin, CSRF, CSP, and SameSite controls. - Portable core: tested on Ubuntu, macOS, and Windows with Python 3.11, 3.12, and 3.13.
Install the ToolPermit Codex Skill from this GitHub repository with the built-in plugin manager:
For a reproducible installation of this release, replace main with v0.1.1 in the first command.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/sunhao123456sun-svg--toolpermit.html)
Local credential control for AI coding agents.
korovin-aa97/talkthrough-mcpMCP server: turn narrated screen recordings into agent-ready data — local Whisper transcript, scene keyframes, OCR, wall-clock anchoring. Record your screen, talk — your AI agent files the bugs.
MaxFreedomPollard/engRAMAutomatic one-click install. Encrypted, fully offline vector memory for AI agents; takes over built-in agentic memory.
TeodorMCP/universal-connector-mcpUniversal MCP server: connect any OpenAPI/Swagger, GraphQL, gRPC or SOAP API to AI agents. Security-first, local, token-efficient. Any API. One server.
omaekumiko2-create/kruLocal-first MCP password and credential manager for AI agents. Use passwords, API keys, SSH identities, and TOTP without exposing hidden plaintext to the model.
Stupidoodle/swissdevjobs-cliSearch & apply to ~4,700 salary-transparent tech jobs across 7 countries (🇨🇭🇩🇪🇬🇧🇺🇸🇨🇦🇳🇱🇫🇷) from your terminal or AI agent — zero-dependency Python CLI + MCP server + Claude Code plugin
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.