mcp-airlock
local MCP serverInstallation
Terminal
claude mcp add mcp-airlock -e AIRLOCK_JWT_SECRET=... -e AIRLOCK_SECRET=... -- uvx mcp-airlock
Run in your project folder. Add --scope user to use it everywhere.
Claude Desktop, Cursor & other clients
Add to claude_desktop_config.json or .cursor/mcp.json.
{
"mcpServers": {
"mcp-airlock": {
"command": "uvx",
"args": [
"mcp-airlock"
],
"env": {
"AIRLOCK_JWT_SECRET": "...",
"AIRLOCK_SECRET": "..."
}
}
}
}Fill in the environment variables with your own credentials.
Summary
Governance proxy for MCP servers: allowlist, forced dry run, human confirmation, blast radius, audit
Questions
mcp-airlock is a local MCP server distributed as the pypi package mcp-airlock.
Run: claude mcp add mcp-airlock -e AIRLOCK_JWT_SECRET=... -e AIRLOCK_SECRET=... -- uvx mcp-airlock
Run: codex mcp add mcp-airlock --env AIRLOCK_JWT_SECRET=... --env AIRLOCK_SECRET=... -- uvx mcp-airlock