All playbooks

Authorize an MCP tool before it runs

Restrict MCP servers and tools in an agent passport, check a denied call, and wire the allow decision to tool execution.

Install my guardrail

Setup path

Claude Code setup
npx @aporthq/aport-agent-guardrails claude-code
npx @aporthq/aport-agent-guardrails mode claude-code --enforcement=warn
  1. Install the Claude Code hook in warn mode or use the custom integration guide for another MCP client.
  2. Set the passport's allowed MCP server and tool list; use an isolated server for the denied-call test.
  3. Confirm a denied delete_account call and an allowed read_account call, then enforce the decision before invoking the tool.

Check a denied action

Request tool delete_account on an allowed MCP server with only read_account in the tool allowlist.

Expected policy result: deny. The integration must execute the tool only on allow. Warn mode records or displays the denial but may continue, so use an isolated test tool with no side effects.

Expected policy result, illustrative
{
  "policy_id": "mcp.tool.execute.v1",
  "allow": false,
  "reason": "oap.tool_not_allowed"
}
MCP Tool Execution Policy

Setup path

Prepare Enforcement setup

Restrict MCP servers and tools in an agent passport, check a denied call, and wire the allow decision to tool execution.

Recommended

Let my agent prepare Enforcement.

Tell the agent which framework you use: Claude Code, Cursor, Goose, Codex, Gemini CLI, OpenClaw, LangChain, or CrewAI.

agent instruction
install APort runtime guardrails for my agent framework — https://aport.io/skill

Copy this into the agent that already has access to your repo or runtime environment. Require a diff before enforcement or secrets are enabled.