Guarded
БесплатноНе проверенAuthorization middleware requiring human approval via Telegram for sensitive AI agent tool calls.
Описание
Authorization middleware requiring human approval via Telegram for sensitive AI agent tool calls.
README
Authorization-first MCP server framework with Telegram-based human-in-the-loop approval for AI agent actions.
Why
LLM agents can call tools. Some tools are dangerous — sending emails, modifying data, transferring money. Guarded MCP sits between the agent and the tools, requiring explicit human approval for sensitive actions via Telegram.
Architecture
AI Agent (Claude, GPT, etc.)
│
▼
┌─────────────────────────────────┐
│ MCP Protocol (HTTP transport) │
└──────────────┬──────────────────┘
▼
┌─────────────────────────────────┐
│ GuardedMCPServer │
│ ┌───────────────────────────┐ │
│ │ ApprovalMiddleware │ │
│ │ ┌─────────────────────┐ │ │
│ │ │ PolicyEngine │ │ │ ← auto-approve reads, trust, allowlists
│ │ └─────────────────────┘ │ │
│ │ ┌─────────────────────┐ │ │
│ │ │ ApprovalEngine │ │ │ ← Telegram: approve / reject / trust 30min
│ │ └─────────────────────┘ │ │
│ └───────────────────────────┘ │
│ ┌───────────────────────────┐ │
│ │ Integrations (pluggable) │ │ ← Gmail, Calendar, etc.
│ └───────────────────────────┘ │
└─────────────────────────────────┘
Features
- Approval middleware — intercepts gated tool calls, sends a Telegram message with an inline keyboard (Approve / Reject / Trust 30min)
- Policy engine — auto-approve read-only tools, domain allowlists, per-tool configuration
- Trust elevation — "Trust 30min" grants temporary auto-approval for repeated calls to the same tool
- Hash verification — each request's parameters are SHA-256 hashed; the hash is verified before execution to prevent tampering
- Anti-manipulation — approval messages show raw parameters only, never agent-supplied descriptions
- Pluggable integrations — simple ABC for adding new tool providers
Quick Start
Prerequisites
- Python 3.12+
- uv package manager
- A Telegram bot token (via @BotFather)
- Your Telegram chat ID and user ID
Setup
Run the interactive setup wizard:
git clone https://github.com/fernandosmither/guarded-mcp.git
cd guarded-mcp
uv sync
uv run python -m src.setup
The wizard walks you through:
- Generating an encryption key for credential storage
- Configuring your Telegram bot (token, chat ID, allowed users)
- Setting approval policy defaults
- Optionally linking Google accounts via OAuth2
Or configure manually: cp config.toml.example config.toml and edit.
Run
uv run python main.py
The server starts on http://127.0.0.1:3100 with stateless HTTP transport.
Configuration
[server]
| Key | Default | Description |
|---|---|---|
host |
127.0.0.1 |
Bind address |
port |
3100 |
Listen port |
approval_timeout_seconds |
300 |
Seconds before an unanswered approval expires |
[telegram]
| Key | Default | Description |
|---|---|---|
bot_token_env |
APPROVAL_BOT_TOKEN |
Environment variable containing the bot token |
chat_id |
0 |
Telegram chat ID to send approvals to |
allowed_user_ids |
[] |
User IDs allowed to approve/reject |
[policy]
| Key | Default | Description |
|---|---|---|
auto_approve_reads |
true |
Read-only tools skip approval |
trust_elevation_minutes |
30 |
Duration of "Trust 30min" button |
[integrations.<name>.tools.<tool>]
| Key | Default | Description |
|---|---|---|
requires_approval |
true |
Whether this tool needs human approval |
auto_approve_domains |
[] |
Email domains that bypass approval |
Writing an Integration
from src.integrations.base import Integration, ToolDef
class MyIntegration(Integration):
name = "my_service"
def tools(self) -> list[ToolDef]:
return [
ToolDef(
name="read_data",
description="Read some data",
input_schema={
"type": "object",
"properties": {
"query": {"type": "string", "description": "Search query"}
},
"required": ["query"],
},
read_only=True, # auto-approved if policy allows
requires_approval=False,
),
ToolDef(
name="write_data",
description="Write data (needs approval)",
input_schema={
"type": "object",
"properties": {
"content": {"type": "string", "description": "Content to write"}
},
"required": ["content"],
},
read_only=False,
requires_approval=True,
),
]
async def execute(self, tool_name: str, arguments: dict):
if tool_name == "read_data":
return {"result": f"data for {arguments['query']}"}
elif tool_name == "write_data":
return {"written": arguments["content"]}
Register it in main.py:
server.register_integration(MyIntegration())
Development
uv sync --extra dev
uv run pytest -v
uv run ruff check src/ tests/
Setup for AI Agents
If you're an AI agent setting up guarded-mcp on behalf of a user, follow these steps:
Prerequisites
- Python 3.12+ and uv installed
- A Telegram bot token (user must create via @BotFather)
- User's Telegram chat ID and user ID (from @userinfobot)
Step-by-step
Clone and install:
git clone https://github.com/fernandosmither/guarded-mcp.git cd guarded-mcp uv syncGenerate encryption key:
python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"Ask the user to add the output to their shell profile:
export GUARDED_MCP_SECRET="<generated-key>"Set the Telegram bot token:
export APPROVAL_BOT_TOKEN="<token-from-botfather>"Write config.toml:
[server] host = "127.0.0.1" port = 3100 approval_timeout_seconds = 300 [telegram] bot_token_env = "APPROVAL_BOT_TOKEN" chat_id = <user-chat-id> allowed_user_ids = [<user-id>] [policy] auto_approve_reads = true trust_elevation_minutes = 30 [google] client_secret_path = "credentials/client_secret.json" credentials_dir = "credentials" secret_env = "GUARDED_MCP_SECRET" accounts = []Link Google accounts (requires user interaction): The user must complete OAuth consent in a browser. Run:
uv run python -m src.auth_cli add workThen update
config.tomlto include the alias:accounts = ["work"]Start the server:
uv run python main.py
Connecting to the MCP server
The server runs on http://127.0.0.1:3100 with stateless HTTP transport. Configure your MCP client to connect to this URL.
Tool naming convention
All tools follow the pattern {integration}__{tool_name}. Each tool that accesses Google services takes an account parameter specifying which linked account to use (e.g., "work", "personal").
Read-only tools (searches, reads, listings) are auto-approved. Write tools (send, create, modify, delete) require Telegram approval unless overridden in config.
License
MIT
Установка Guarded
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/fernandosmither/guarded-mcpFAQ
Guarded MCP бесплатный?
Да, Guarded MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Guarded?
Нет, Guarded работает без API-ключей и переменных окружения.
Guarded — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Guarded в Claude Desktop, Claude Code или Cursor?
Открой Guarded на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
Gmail
Read, send and search emails from Claude
автор: GoogleSlack
Send, search and summarize Slack messages
автор: SlackRunbear
No-code MCP client for team chat platforms, such as Slack, Microsoft Teams, and Discord.
Discord Server
A community discord server dedicated to MCP by [Frank Fiegel](https://github.com/punkpeye)
Compare Guarded with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории communication
