MCP policy proxy · Apache-2.0

Govern what your AI assistants can reach and do.

Aggrete is an MCP proxy that sits between AI assistants and your connectors. It checks each tool call against a YAML policy and per-user memory, and refuses the request that would leak a secret, cross an information barrier, over-share health data, complete a forbidden combination, or write out after reading untrusted content, before the upstream is ever contacted.

Python 3.10+ MCP stdio + HTTP License Apache-2.0 Deterministic no model in path No endpoint agent mapped to OWASP · CoSAI · AIUC-1
$ pip install aggrete
aggrete — ask first, then enforced
# ask first — check the plan, nothing is fetched
>check: joiners + budget + on-calldeny
   COC-HR-004 · would join personnel + budget + rotation
# the same requests, run for real
>Q3 headcount planallow
>Backfill-only rolesallow
>Recent joiners · 10 peoplealert
>On-call gapsdeny
   refused at pre-call — upstream never contacted
# audit.jsonl ← one JSON line per decision
Get started in 30 seconds
pip
pip install aggrete
then aggrete --demo to watch it refuse
uvx · zero install
uvx aggrete --demo
runs the demo without installing anything
docker
docker run --rm ghcr.io/aggrete/aggrete --demo
self-contained, no config needed
New in 0.10 and 0.11 Everything that has shipped →
hold, don't refuse

A person signs off

A rule can say approve instead of deny. The call pauses before anything is fetched, the clause owner gets the ping, and the retry works for a few hours with their name on every audit line.

Why it matters
no second hop

Runs inside your gateway

Native in agentgateway over its ExtMCP hook, two interceptors for Docker's MCP gateway, a plugin for IBM ContextForge, and an OpenID AuthZEN endpoint for anything else. Same rules, memory and audit.

How adapters work
proof, not claims

A test you can rerun

One command runs sixteen checks against the real components and maps them onto OWASP, CoSAI and AIUC-1. A second mode scores any gateway from the outside, including ones that are not Aggrete.

See the report
At a glance

Everything it does, in plain words, with what engineers call it in grey. Hover any line for a sentence more.

What it decides

Says no before anything is fetchedpre-call enforcement
Remembers what each person already looked upper-user accumulator
Stops a poisoned page from steering the assistantinjection shield · governed writes
Lets a person sign off instead of a flat nohuman approvals
Hides tools people should never useselective tool exposure
Blacks out IDs, card numbers and passwordsoutput redaction

Who is asking

Knows who is asking, using your company loginOAuth 2.1 identity
The assistant never holds your system passwordsno token passthrough

Proof and records

A logbook nobody can quietly edithash-chained audit
A test you, or your auditor, can rerunconformance suite
Dashboards, health checks, security feedsmetrics · OTLP · OCSF

Writing the rules

Your rules live in one readable filepolicy is one YAML file
Catches mistakes before they go liveaggrete-lint
Your AI assistant already knows how to set it upagent skill

Where it runs

On a laptop or for the whole companystdio & streamable HTTP
Remembers across restarts and serversMemoryStore / RedisStore
Installs the way your platform team expectsHelm chart + Docker
Works inside the gateway you already runExtMCP · Docker · ContextForge
Answers any system that asks "is this allowed?"AuthZEN · ASGI hook
Keeps up with the protocolMCP 2026-07-28
Proof

Don't take our word for it. Run it.

Every security tool says it blocks these. Aggrete ships the test. Sixteen checks drive the real engine and map onto the lists buyers ask about, and a black-box mode scores any MCP gateway from the outside.

$pip install aggrete && aggrete conformance
OWASP MCP Top 10

7 pass · 2 partial

of 10 controls, 0 failing

OWASP Top 10 for Agentic Applications

6 pass · 2 partial

of 10 controls, 0 failing

CoSAI MCP Security v2.0

13 pass · 1 partial

of 14 controls, 0 failing

AIUC-1

16 pass · 2 partial

of 18 controls, 0 failing

black-box scenario, same connectorsaggretenothing
Combination: budget + personnel + rota about the same peoplepassfail
Exfiltration: no write after reading untrusted contentpassfail
Arguments: the same tool allowed or refused by what it is askedpassfail
Redaction: an SSN in a result never reaches the clientpassfail
Inbound secrets: a credential in arguments never reaches the upstreampassfail
Tool poisoning: a tool with hidden instructions is not usablepassfail
Walls: a tool this person may never call is hidden or refusedpassfail

Two real runs over MCP. The right-hand column is the same fixture connector with no policy layer in front of it. Full report, every control, and how to point it at your own gateway →