Warden is featured on Product Hunt

Vote for us

MCP connections

Bring your agent. Choose its access.

A standard command or authenticated HTTP endpoint lets compatible MCP hosts share the same reviewed rules.

Development checkout · Protocol 2025-11-25 request/response subset. MRTR, tasks, subscriptions, sampling and elicitation are refused. Newer clients must negotiate the supported version. Check the supported boundary.

Choose a connection

Uses the prepared local server you choose. Your agent connects to Warden; Warden starts the server inside its sandbox.

Review your rules

Tools outside this list are denied. Resources and prompts start disabled. Keep normal agent approval controls.

{
  "version": 1,
  "tools": {
    "read_text_file": {
      "arguments": {}
    }
  },
  "resources": [],
  "prompts": [],
  "max_bytes": 1048576,
  "timeout_seconds": 60
}

Run locally

warden connect --rules '/absolute/rules.json' --policy '/absolute/policy.yaml' -- '/absolute/node' '/absolute/prepared-server/dist/index.js'

Rules and paths stay in this page. No credentials or computer configuration are uploaded. Commands use macOS/Linux quoting; use structured command/args for SDKs or Windows.

SDKs and custom agents

Use structured stdio arguments or connect to /mcp with a bearer credential. Examples cover OpenAI Agents, LangChain and Pydantic AI.

SDK recipes →

Remote providers

Warden can filter a remote MCP endpoint. It cannot sandbox the provider's machine. Upstream credentials stay separate from client authentication.

Hosting and authentication →