DocsWhat may it doMCP proxy

MCP proxy: governing every tool call an agent makes

An MCP proxy is a process that sits between an MCP client, such as Claude Code, Cursor or Codex, and the MCP servers it calls, so that every message between them passes through it. It looks like a server to the agent and like a client to the server. What it does with that position is what separates one MCP proxy from another.

Three kinds of MCP proxy

KindWhat it doesWhere it runs
Transport bridgeconverts between transports, such as a local stdio server and a remote HTTP onebeside the client
Gatewayputs many servers behind one endpoint, with authentication, rate limits and loggingon a server the team shares
Governing proxydecides every tool call before the server sees iton the machine the agent runs on

Most results for "MCP proxy" are the first kind. A gateway suits servers the team hosts centrally. A governing proxy is for the servers an agent starts on a developer's own laptop, which is where a local stdio server runs.

What the Memnox MCP proxy does

Memnox ships a governing proxy, open source and local. One command points every MCP server on the machine at it, and keeps a backup of each config it changes:

bash
memnox mcp wrap      # repoint every MCP server at the proxy
memnox mcp unwrap    # put them back byte for byte

Claude Code, Cursor and Codex configs are handled by name, and anything with a standard .mcp.json is handled too. Then the proxy sees three things:

MessageWhat the proxy does
initializepasses it through unchanged
tools/listclassifies every tool as read, write, destructive, communication or unknown, and removes any tool you hid, so the agent never learns it exists
tools/calldecides it before it reaches the server: allow forwards it, ask holds it for a person, deny returns an error the agent can act on

Rules name a call as mcp.<server>.<tool>, in the same rule file that governs shell commands and file edits:

toml
version = 1
 
[[policies]]
name = "ask-before-github-writes"
 
[policies.match]
actions = ["mcp.github.create_*", "mcp.github.merge_*"]
 
[policies.decision]
effect = "ask"
reason = "these change something other people see."

A denied call comes back as a protocol error the client already understands, naming the rule, the reason and one alternative where the rule gave one. It carries nothing else, because the text is read by a model, and a refusal that told a model what to do would be an injection point.

A new MCP server starts on probation

When somebody installs a new MCP server, it starts on probation for seven days: its writes and its outward and destructive actions ask first, and its reads do not. memnox mcp trust <server> ends probation early, on the record. A server is judged by what its tools can actually do rather than by a score or an install count.

What an MCP proxy cannot see

Only what goes through it. An MCP server an agent reaches without its config is outside the proxy, and a tool that lies about its name in tools/list is classified by the lie. That is why Memnox also holds the shell, the network, git credentials and the browser, and the runtime reference lists each seam with its limits.

Questions people ask

What is the difference between an MCP proxy and an MCP gateway?

A gateway is usually a shared service that puts many servers behind one endpoint. A proxy can be anything in the path; a governing proxy is one that decides each tool call, and the Memnox one runs on the machine the agent runs on.

Is the Memnox MCP proxy open source?

Yes. It is part of the Apache-2.0 Memnox runtime, and it needs no account and no network.

Does the agent have to support the proxy?

No. memnox mcp wrap rewrites the agent's MCP config so the server it starts is the proxy, which starts the real server. The agent calls its tools as before.

Can I hide a tool from the agent completely?

Yes. A hidden tool is removed from tools/list and denied if it is called anyway, since hiding it alone would leave the call itself open.