OpenToolslogo
ToolsExpertsNewsletterSubmit a Tool
AdvertiseLearn AI
  1. home
  2. tools
  3. toolpermit
ToolPermit screenshot

ToolPermit

DeveloperApplicationPricing unavailable

ToolPermit - Local Approval Firewall for MCP Tools

Listing updated Oct 3, 2026

Get This Tool
Claim Tool

What is ToolPermit?

ToolPermit is a local-first permission firewall for AI agent tool calls over the Model Context Protocol. It is meant to sit between a local MCP client and a local MCP stdio server, where it can observe calls, apply deterministic policy, request one-time approvals, redact sensitive values, and keep an audit trail in SQLite. The project is useful for teams experimenting with agent tools but worried about a model calling destructive or sensitive actions without review. The core idea is policy before execution. ToolPermit uses a versioned YAML policy format where the first matching rule wins and every decision is explainable as allow, ask, or deny. If a call needs an exception, ToolPermit can issue an approval request that is tied to the canonical request, the policy, the session, and an expiry. Approved exceptions are consumed atomically, which helps prevent a broad approval from being reused for a different tool call. Auditing is local by design. ToolPermit redacts recognized secrets and sensitive keys before storing calls in SQLite or showing them in CLI, UI, or JSONL export workflows. Stored redacted calls can be replayed against a candidate policy without launching the MCP server or executing the original action. That replay loop is useful when teams want to tighten rules after observing real agent behavior. The current release supports a single local user, MCP over stdio, YAML policy version 1, SQLite audit schema version 1, CLI approvals, and an optional loopback-only web UI. The UI includes host checks, origin checks, CSRF protection, CSP, and SameSite controls. The README is also clear about non-goals: ToolPermit is not an operating-system sandbox, it cannot undo actions that already executed, it does not authenticate remote users, and it cannot inspect tool calls that bypass the proxy. ToolPermit is best for local agent workflows where developers want a transparent approval layer before sensitive MCP tools. Examples include file writes, shell commands, network access, secrets handling, or internal admin actions. It is Apache-2.0 licensed and published as a Python package for Python 3.11 through 3.13. The tool itself is free; users bring their own MCP servers, AI clients, and runtime environment. For an OpenTools page, ToolPermit is best understood as a safety layer for local MCP workflows. It does not make a dangerous tool safe by itself, but it gives developers a consistent place to define policy, pause for approval, redact records, and test stricter rules before giving an agent broader access.

ToolPermit's Top Features

Key capabilities that make ToolPermit stand out.

Local proxy between MCP clients and stdio servers

Deterministic YAML policies with allow, ask, and deny decisions

One-time approvals bound to request, policy, session, and expiry

Sensitive-value redaction before storage and display

SQLite audit trail for local runs

Offline replay of redacted calls against candidate policies

CLI workflows plus optional loopback-only approval UI

Security controls such as origin checks, CSRF, CSP, and SameSite settings

Use Cases

Who benefits most from this tool.

Agent developers

Add explainable permission checks before local MCP tools can perform risky actions.

Security-minded teams

Audit and replay tool calls while redacting secrets before local storage.

MCP experimenters

Test approval policies around stdio MCP servers without building a custom proxy.

Explore Top AI Use Cases

Tags

mcpai-agentssecuritypermissionsapproval-workflowlocal-firstaudit-logspythondeveloper-toolsopen-source

ToolPermit's Pricing

Open source

Pricing unavailable

  • Apache-2.0 license
  • Python package
  • CLI approvals
  • + 2 more features
Get started

User Reviews

Share your thoughts

If you've used this product, share your thoughts with other builders

Recent reviews

Frequently Asked Questions

What is ToolPermit?
ToolPermit is a local-first permission, approval, and audit layer for MCP tool calls between a local client and stdio server.
Does ToolPermit sandbox the operating system?
No. The README explicitly says it is not an OS sandbox and cannot undo actions that already executed.
How does ToolPermit store audit data?
It stores redacted call records locally in SQLite and can export or replay them against candidate policies.
Which Python versions does ToolPermit support?
The reviewed repository summary lists Python 3.11 through 3.13 support for the current release.

Footer

Company name

The right AI tool is out there. We'll help you find it.

LinkedInX

Knowledge Hub

  • News
  • Resources
  • Newsletter
  • Blog
  • AI Tool Reviews
  • YouTube Summary
  • YouTube Transcript Generator

Industry Hub

  • AI Companies
  • AI Tools
  • AI Models
  • MCP Servers
  • Muse Connectors
  • AI Tool Categories
  • Top AI Use Cases

For Builders

  • Submit a Tool
  • Experts & Agencies
  • Advertise
  • Compare Tools
  • Favourites

Legal

  • Privacy Policy
  • Terms of Service

© 2026 OpenTools - All rights reserved.