ToolPermit is a local-first permission firewall for AI agent tool calls over the Model Context Protocol. It is meant to sit between a local MCP client and a local MCP stdio server, where it can observe calls, apply deterministic policy, request one-time approvals, redact sensitive values, and keep an audit trail in SQLite. The project is useful for teams experimenting with agent tools but worried about a model calling destructive or sensitive actions without review.
The core idea is policy before execution. ToolPermit uses a versioned YAML policy format where the first matching rule wins and every decision is explainable as allow, ask, or deny. If a call needs an exception, ToolPermit can issue an approval request that is tied to the canonical request, the policy, the session, and an expiry. Approved exceptions are consumed atomically, which helps prevent a broad approval from being reused for a different tool call.
Auditing is local by design. ToolPermit redacts recognized secrets and sensitive keys before storing calls in SQLite or showing them in CLI, UI, or JSONL export workflows. Stored redacted calls can be replayed against a candidate policy without launching the MCP server or executing the original action. That replay loop is useful when teams want to tighten rules after observing real agent behavior.
The current release supports a single local user, MCP over stdio, YAML policy version 1, SQLite audit schema version 1, CLI approvals, and an optional loopback-only web UI. The UI includes host checks, origin checks, CSRF protection, CSP, and SameSite controls. The README is also clear about non-goals: ToolPermit is not an operating-system sandbox, it cannot undo actions that already executed, it does not authenticate remote users, and it cannot inspect tool calls that bypass the proxy.
ToolPermit is best for local agent workflows where developers want a transparent approval layer before sensitive MCP tools. Examples include file writes, shell commands, network access, secrets handling, or internal admin actions. It is Apache-2.0 licensed and published as a Python package for Python 3.11 through 3.13. The tool itself is free; users bring their own MCP servers, AI clients, and runtime environment.
For an OpenTools page, ToolPermit is best understood as a safety layer for local MCP workflows. It does not make a dangerous tool safe by itself, but it gives developers a consistent place to define policy, pause for approval, redact records, and test stricter rules before giving an agent broader access.