Skip to main content
Connect a JavaScript or TypeScript MCP server to inventory its tools and apply Rules before tool execution. This is a tools-only subject: it has no agent response loop to instrument. Python MCP servers are not supported by this path.

Connect

From the server repository:
Alternatively, choose Connect → MCP in the app and save its generated credentials. Apply the generated setup prompt with your coding agent. It declares the server’s tools and guards the actual dispatcher, where every protected call passes before reaching its handler. A manual integration uses the TypeScript SDK: declare tools only, and guard the dispatcher. Do not invent prompts, a model client or response-delivery events for an MCP server. Return policy errors to the MCP client as a normal isError: true tool result, rather than crashing the server or sending a protocol error.

Verify

Start the server normally and call a guarded tool through your MCP client:
The MCP evidence contract requires registration, inventory, heartbeat and a tool call. It does not require a turn or before-response delivery evidence. Inspect Actions in Context & actions and the call’s decision/outcome in Traces. Write a Rule, start in Observe, and test representative inputs. An enforced blocking match must prevent the handler from executing. A server registered in the catalogue is not protected unless the caller actually goes through the guard.