Warden is featured on Product Hunt
Vote for usHow to securely run an MCP server
An MCP server is a local process with your permissions unless you put a sandbox in front of it. These pages answer that problem directly. Warden is one open-source way to enforce the resulting policy. It is not assumed in the question.
Guides
Start here if you have an MCP server and want to know what it can touch.
- How to protect API keys from MCP servers
MCP servers inherit your shell environment unless you filter it. How to pass one token without exposing the rest, and which setups still leak keys.
- How to sandbox an MCP server
How to put a local MCP server in an OS sandbox, what the policy must grant, and what to do when the sandbox cannot start.
- How to securely run an MCP server
An MCP server is a local process with your permissions. Here is the attack surface, what to constrain, and how a sandbox policy limits the damage.
- MCP security best practices
Practical rules for running local MCP servers, from what the protocol does not protect to how to grant files, hosts, and secrets.
- What permissions should an MCP server have?
How to decide filesystem, network, and environment permissions for a local MCP server without handing it your user account.
Comparisons
Isolation options side by side, including Docker and hand-written OS sandboxes.
- Warden vs Docker for MCP servers
Docker and Warden solve different problems. When a container is enough, when a deny-by-default policy is the point, and how Warden uses Docker as a fallback.
- Ways to isolate an MCP server
Unsandboxed processes, separate OS users, containers, hand-written OS sandboxes, and a policy runtime. What each option actually stops.
Use cases
Local servers, untrusted packages, and filesystem isolation.
- How to run an untrusted MCP server
A practical way to try an MCP server you did not write, without giving it your SSH keys, your .env files, or a general network.
- How to run local MCP servers securely
Local stdio MCP servers are the common case. How to keep the client setup you already have and stop the server from inheriting your account.
- How to stop an MCP server from reading your filesystem
Why an MCP filesystem server can see your home directory, and how bind mounts and grants limit it to one folder.