Prepare the server locally
Run this once before adding it to Claude Code.
npm install -g @alramalho/mcp-guardAdd it to Claude Code
Paste the maintainer's config below, then edit any placeholder values.
{
"port": 6427,
"servers": {
"supabase_production": {
"url": "https://mcp.supabase.com/mcp?project_ref=xxx&read_only=true",
"block": [
"DELETE",
"UPDATE",
"DROP",
"TRUNCATE",
"ALTER",
"INSERT"
],
"blockMessage": "Destructive SQL operations are not allowed in production"
}
}
}See the mcp-guard README for full setup instructions.
Make your agent remember this setup
mcp-guard's config, env vars, and the gotchas you hit — recalled in every future Claude Code, Cursor, and Codex session.
npx conare@latestFree · one command · indexes the sessions already on disk. Set up in the browser instead →
What it does
- Intercepts and proxies MCP server traffic via HTTP
- Blocks specific tool calls based on case-insensitive keyword patterns
- Supports custom error messages when requests are blocked
- Handles OAuth-protected upstream servers automatically
- Provides a debug mode to monitor tool calls and block decisions in real-time
Try it
Original README from alramalho/mcp-guard
mcp-guard
A simple HTTP proxy that gates MCP servers with block rules.
No SDKs. No dashboards. Just a JSON config and a toggle command.
Client (Claude, Cursor, etc.)
↕ http
mcp-guard (localhost proxy)
↕ http
Upstream MCP server (supabase, postgres, etc.)
Quick Start
1. Install
npm install -g @alramalho/mcp-guard
Or from source:
git clone https://github.com/alramalho/mcp-guard
cd mcp-guard
pnpm install && pnpm build && npm link --force
2. Create `.mcp-guard.json`
In your project root (or ~/.mcp-guard.json globally). Config is auto-discovered by walking up from cwd.
{
"port": 6427,
"servers": {
"supabase_production": {
"url": "https://mcp.supabase.com/mcp?project_ref=xxx&read_only=true",
"block": ["DELETE", "UPDATE", "DROP", "TRUNCATE", "ALTER", "INSERT"],
"blockMessage": "Destructive SQL operations are not allowed in production"
}
}
}
3. Update your `mcp.json`
Replace the direct upstream URL with the mcp-guard proxy:
{
"mcpServers": {
"supabase_production": {
"type": "http",
"url": "http://localhost:6427/supabase_production"
}
}
}
4. Toggle on/off
$ mcp-guard
MCP Guard on → http://localhost:6427
$ mcp-guard
MCP Guard off
Debug mode
Run in foreground to see all tool calls and block decisions live:
$ mcp-guard -d
Config
.mcp-guard.json (auto-discovered from cwd up, or ~/.mcp-guard.json, or --config ):
| Field | Type | Default | Description |
|---|---|---|---|
port |
number |
6427 |
Port for the local HTTP proxy |
servers |
object |
— | Map of gate name → server config |
Each server:
| Field | Type | Description |
|---|---|---|
url |
string |
Upstream MCP server URL |
enabled |
boolean |
Set to false to passthrough without blocking |
token |
string |
Static Bearer token for upstream auth (optional) |
block |
string[] |
Patterns to block (case-insensitive substring match) |
blockMessage |
string |
Error message returned when blocked |
Authentication
mcp-guard handles OAuth-protected upstream servers (e.g. Supabase) automatically. On first connection, if the upstream requires auth, mcp-guard will open your browser for OAuth authorization. Tokens are cached in ~/.mcp-guard/auth/ and refreshed automatically.
Alternatively, you can provide a static token in the config:
{
"servers": {
"my_server": {
"url": "https://example.com/mcp",
"token": "your-access-token"
}
}
}
How It Works
mcp-guardstarts a local HTTP server- When a client connects to
http://localhost:PORT/<gate_name>, it connects to the upstream MCP server - It discovers all upstream tools and re-exposes them
- On each tool call, all argument values are checked against block patterns
- If any pattern matches → error returned, call never reaches upstream
- If no match → call is forwarded to upstream as-is
License
MIT