Warden is featured on Product Hunt

Vote for us

Boundary & evidence

Know what your connection protects.

Protection follows the managed process and the routed connection. Warden does not cover unrelated shell tools, direct connections, or a remote provider’s machine.

Warden mode capabilities and limitations
ModeBoundaryControlsLimitations
warden connect / serve (local)Managed process and routed MCP connectionDigest-pinned sandbox plus tool/argument/resource/prompt rules2025-11-25 bounded subset; unsupported capabilities are refused. Native platform and host coverage still need review.
warden serve (remote)Routed MCP trafficSeparate authentication, credentials and client sessions; filtered discovery/callsProvider process is not sandboxed. No automatic upstream OAuth, MRTR, tasks or subscriptions.
warden runLocal managed processOS sandbox; explicit file, egress and environment grantsBackend required. Runtime mounts and scratch directories are additional to data grants. Allowed API actions still require provider-side privileges.
Client / gateway wrapConfiguration changeLaunches local stdio servers through warden runWrapping is not an MCP workflow test. Remote entries cannot gain process isolation through a config edit.
warden proxyMessages routed through custom TCP listenerTool-name / content filtering and upstream environment allowlistingLocal proxy upstreams are not OS-sandboxed by proxy itself. The downstream listener is not a standard Streamable HTTP endpoint.
warden traceObservation of one workloadCaptures accesses for a candidate policyRuns unsandboxed. Use trusted code, disposable test data and fake credentials. Observation does not prove safety.

Evidence has levels

  1. Metadata reviewed: an upstream and version are identified.
  2. Fixture checked: policy parsing and config transformations pass deterministic checks.
  3. Backend exercised: an actual sandbox allows and blocks representative operations.
  4. Workflow verified: a pinned server and client complete the real task and denial checks on the advertised platform.

Local setup checks

Applying a wrapper probes the selected sandbox using an inert Warden process before writing. It never starts the target server for that readiness check. Failure leaves the configuration unchanged.

After restart, verify one allowed task and one denied task. A configured wrapper remains marked “workflow unverified” in the CLI inventory until evidence exists.

Read the verification guide →

Native Linux/macOS egress filtering covers HTTP/HTTPS through the enforced proxy. Raw database TCP needs separate transport work. The development gateway supports a bounded 2025-11-25 subset; newer protocol-era support and complete remote assurance remain release work. Auditing coverage depends on the backend; a policy fixture is not fresh end-to-end evidence.