Warden is featured on Product Hunt

Vote for us

How to securely run an MCP server

An MCP server is a local process with your permissions unless you put a sandbox in front of it. These pages answer that problem directly. Warden is one open-source way to enforce the resulting policy. It is not assumed in the question.

Guides

Start here if you have an MCP server and want to know what it can touch.

Comparisons

Isolation options side by side, including Docker and hand-written OS sandboxes.

  • Warden vs Docker for MCP servers

    Docker and Warden solve different problems. When a container is enough, when a deny-by-default policy is the point, and how Warden uses Docker as a fallback.

  • Ways to isolate an MCP server

    Unsandboxed processes, separate OS users, containers, hand-written OS sandboxes, and a policy runtime. What each option actually stops.

Use cases

Local servers, untrusted packages, and filesystem isolation.