Answers
How do I allow or deny MCP tool calls by policy?
Put the MCP server behind a proxy that holds its credential and decides each tools/call against a rule. Immiscible’s MCP proxy lists only the tools a rule covers, refuses or asks about the rest, and records every call as a digest.
Put the tool server behind a proxy that holds its credential and decides each tools/call against a rule, so the agent has no direct way to the tool. Immiscible’s MCP proxy does that: a tool no rule covers is left out of tools/list and refused if called anyway, a tool mapped as a payment or an email is judged as one, and every call is recorded as SHA-256 digests in a signed ledger.
#How do I set it up?
- Register the upstream (owners and admins, once per workspace) with its URL, its credential and the tools to allow. The credential is sealed and never returned. See register the upstream.
- Write the rule. A proxied call is a
tool.callwhose target is the upstream’s host; a tool map gives tools their meaning:
{
"delete_repo": { "type": "repo.delete" },
"send_email": { "type": "email.send", "targetPath": "to" },
"create_payment": { "type": "payment", "amountPath": "amount", "amountUnit": "minor", "currency": "GBP", "merchantPath": "merchant" }
}- Point the agent at the proxy instead of the tool, and remove its direct connection:
claude mcp add --transport http github https://immiscible.fly.dev/mcp/proxy/mcu_6c1d0e \
--header "Authorization: Bearer $IMMISCIBLE_AGENT_KEY"The same address goes in .cursor/mcp.json or any MCP client’s config. The full walk-through is the MCP proxy.
#What happens when a call needs approval?
The proxy answers with an approval link and the agent waits; calling again with the same arguments returns the same answer and does not ask twice. Once a person approves, the call is forwarded once, never twice. See what the agent sees on approval.
#Is this an MCP gateway with an audit log?
Yes, for the decision and the record. Each proxied call is one record with digests of the arguments and result (never the credential, argument values or tool output), in a hash-chained ledger anyone can verify offline, exportable to a SIEM as OCSF or OpenTelemetry. It is not a tool catalogue or a hosting platform for MCP servers: it fronts servers you already run or use.
#What if a tool server changes its tools?
New or changed tools are hidden until an owner accepts the new manifest, so a server cannot add a tool the rule never saw. Tool descriptions still come from the upstream and reach the model unchanged, so allow only upstreams you trust to describe their own tools.
#What does it not do?
- It governs the tools behind it. A tool the agent can still reach with its own credential is not governed.
- It does not run local (stdio) MCP servers; it fronts remote servers over HTTPS. For Claude Code’s local tools, use the hook.
- Private, loopback and internal addresses are refused as upstreams, as written and as resolved.