{"_id":"@axiorank/mcp-gateway","_rev":"4-f84a220cbce2450bfc2d662afb6c2731","name":"@axiorank/mcp-gateway","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@axiorank/mcp-gateway","version":"0.1.0","keywords":["axiorank","mcp","model-context-protocol","gateway","firewall","ai","agent","security"],"license":"MIT","_id":"@axiorank/mcp-gateway@0.1.0","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"bin":{"axiorank-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"c80c87f04beef8e4396ae5be0d3d3e377cd37069","tarball":"https://registry.npmjs.org/@axiorank/mcp-gateway/-/mcp-gateway-0.1.0.tgz","fileCount":3,"integrity":"sha512-A+IkWnhuk2EJmAGWPf0rNjZE7/UVz762sEognjSXaBsgeowDcM1jqicy9ekdQnoi4w8nWXFyTw3JpmmHW5jRvw==","signatures":[{"sig":"MEUCIF9rGxHUWC1vYFU9BxnnQLHQ9vbmZ/i1Uqw5I/qH+s/1AiEAnQZLc1iMzl+6rKsuxUsA7KPDdxnIw7jrWa3g0Dm78Yk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":10508},"type":"module","engines":{"node":">=20"},"gitHead":"d8fd756fb0b43d3cdc50f3633773446159227bb0","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"_npmVersion":"10.9.8","description":"Transparent MCP gateway — route an MCP server's tool calls through AxioRank for inspection, redaction, and policy enforcement. Governance by changing one URL.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vite":"^8.0.16","vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.0_1780916765071_0.5686073863314756","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@axiorank/mcp-gateway","version":"0.1.1","keywords":["axiorank","mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-security","gateway","firewall","guardrails","ai","agent","security","llm"],"author":{"name":"AxioRank"},"license":"MIT","_id":"@axiorank/mcp-gateway@0.1.1","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"homepage":"https://axiorank.com","bugs":{"url":"https://github.com/frostyhand/AxioRank/issues"},"bin":{"axiorank-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"a2a783dbb5f0a2926cefa41aa5d62b3b491c4489","tarball":"https://registry.npmjs.org/@axiorank/mcp-gateway/-/mcp-gateway-0.1.1.tgz","fileCount":4,"integrity":"sha512-MKV8E7WwC91eRbpZ44pPeEjrSC7L5hO/XQZ/ywPD14bdvraredlhvfJSAXH+WXklVnAj1eo1dRhP5VRYKWVzGA==","signatures":[{"sig":"MEYCIQDKwxjJPcGzifOU3fuTBqlKpnNCYLOSFuClsZI5N11EmAIhAI8/oH3I5wEsgrez/57Wpmpj7P2AoT2PaLhmWEUHnCRY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11936},"type":"module","engines":{"node":">=20"},"gitHead":"fc5d998ecc47ba7f49294de24a198bed52b6e6e9","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"repository":{"url":"git+https://github.com/frostyhand/AxioRank.git","type":"git","directory":"packages/mcp-gateway"},"_npmVersion":"10.9.8","description":"Transparent MCP gateway — route an MCP server's tool calls through AxioRank for inspection, redaction, and policy enforcement. Governance by changing one URL.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vite":"^8.0.16","vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.1_1780924665935_0.09817052573457041","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@axiorank/mcp-gateway","version":"0.1.2","keywords":["axiorank","mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-security","gateway","zero-trust","firewall","guardrails","ai","agent","security","llm"],"author":{"name":"AxioRank"},"license":"MIT","_id":"@axiorank/mcp-gateway@0.1.2","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"homepage":"https://axiorank.com","bugs":{"url":"https://github.com/frostyhand/AxioRank/issues"},"bin":{"axiorank-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"883c293b5a6629bfcf648a4556b459ca52773458","tarball":"https://registry.npmjs.org/@axiorank/mcp-gateway/-/mcp-gateway-0.1.2.tgz","fileCount":4,"integrity":"sha512-Fotgv664tOqvuv/d4wr2GRIBsCb3aIoF3huZvmRSdivxbZOjv7OAMrPBCSsaK2bAJHVZK8uwJG/Vw/GTGfQBVQ==","signatures":[{"sig":"MEQCIGpjvl0sMtoEZxKEXqhaIqj2oOXqwSnz+gmoCWsAl/tnAiAv3HbFW4Cas/STmdQH0PieHoxZFtiaRAHHtwIwvgcuIg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15280},"type":"module","engines":{"node":">=20"},"gitHead":"79ea365ad7219c193179af47ca6a0031d02fc03f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"repository":{"url":"git+https://github.com/frostyhand/AxioRank.git","type":"git","directory":"packages/mcp-gateway"},"_npmVersion":"10.9.8","description":"Transparent MCP gateway: route an MCP server's tool calls through AxioRank for inspection, redaction, and policy enforcement. Zero-Trust governance by changing one URL.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vite":"^8.0.16","vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.2_1781122155353_0.283934751504789","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@axiorank/mcp-gateway","version":"0.1.3","description":"Transparent MCP gateway: route an MCP server's tool calls through AxioRank for inspection, redaction, and policy enforcement. Zero-Trust governance by changing one URL.","license":"MIT","homepage":"https://axiorank.com","bugs":{"url":"https://axiorank.com/support"},"author":{"name":"AxioRank"},"type":"module","bin":{"axiorank-mcp-gateway":"dist/cli.js"},"keywords":["axiorank","mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-security","gateway","zero-trust","firewall","guardrails","ai","agent","security","llm"],"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","test":"vitest run"},"publishConfig":{"access":"public"},"engines":{"node":">=20"},"devDependencies":{"@types/node":"^22.10.2","tsup":"^8.3.5","typescript":"^6.0.3","vite":"^8.0.16","vitest":"^4.1.8"},"_id":"@axiorank/mcp-gateway@0.1.3","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-mj/WEdxPbo5dWiio26YkJg+XEFvFS3dQ0P7OmKimpLJDty1GclyITh65PcxNGijsuMVgzJwEkC3JyKsrSEcS8g==","shasum":"f09f03a986564deddd3469741bde0da3fc607c41","tarball":"https://registry.npmjs.org/@axiorank/mcp-gateway/-/mcp-gateway-0.1.3.tgz","fileCount":4,"unpackedSize":16015,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC8aFoSelcMvF2BmjTklTDFS94YfZz6UEaX/Ni4IyPtkwIhAPddrj7Dep9bhhA3+YQmW4eARzGT9LWApyDuW5H1eLM4"}]},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"directories":{},"maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-gateway_0.1.3_1785415302343_0.13475487440854028"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-08T11:06:04.904Z","modified":"2026-07-30T12:41:42.638Z","0.1.0":"2026-06-08T11:06:05.230Z","0.1.1":"2026-06-08T13:17:46.112Z","0.1.2":"2026-06-10T20:09:15.511Z","0.1.3":"2026-07-30T12:41:42.462Z"},"bugs":{"url":"https://axiorank.com/support"},"author":{"name":"AxioRank"},"license":"MIT","homepage":"https://axiorank.com","keywords":["axiorank","mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-security","gateway","zero-trust","firewall","guardrails","ai","agent","security","llm"],"description":"Transparent MCP gateway: route an MCP server's tool calls through AxioRank for inspection, redaction, and policy enforcement. Zero-Trust governance by changing one URL.","maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"readme":"# @axiorank/mcp-gateway\n\nDrop [AxioRank](https://axiorank.com) between an MCP client and a **local stdio**\nMCP server. Every `tools/call` is inspected by AxioRank's content-risk + policy\nengine before it reaches the upstream (catching leaked secrets, destructive\ncommands, and prompt injection) and written to a redacted, immutable audit log.\nZero-Trust governance by changing one config block, with **no changes to your\nagent's code**.\n\n> For **remote** (Streamable HTTP) MCP servers, you don't need this package:\n> point your client's HTTP transport at the gateway URL AxioRank generates when\n> you register the server. This shim is for servers your client launches locally.\n\n## Setup\n\n1. In the AxioRank dashboard, go to **Outbound → MCP Gateway → Add MCP Server**,\n   choose **Local (stdio shim)**, pick the governing agent, and copy the slug.\n2. Wrap your existing MCP server command with the shim in your client config\n   (`claude_desktop_config.json`, Cursor `mcp.json`, …):\n\n```jsonc\n{\n  \"mcpServers\": {\n    \"github\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\", \"@axiorank/mcp-gateway\",\n        \"--\",\n        \"npx\", \"-y\", \"@modelcontextprotocol/server-github\"\n      ],\n      \"env\": {\n        \"AXIORANK_KEY\": \"axr_live_xxxxxxxxxxxxxxxx\",\n        \"AXIORANK_SERVER\": \"github-mcp\",\n        \"GITHUB_PERSONAL_ACCESS_TOKEN\": \"ghp_...\"\n      }\n    }\n  }\n}\n```\n\nEverything after `--` is your upstream server command, launched and managed by\nthe shim. Its own env (e.g. `GITHUB_PERSONAL_ACCESS_TOKEN`) is passed through.\n\n## Docker\n\nRun the shim as a containerized sidecar. To be clear about the trust boundary:\nthe AxioRank enforcement plane itself is hosted, and the container only runs\nthe local shim that wraps your stdio MCP server. As on the host, everything\nafter `--` is the upstream server command:\n\n```bash\ndocker build -t axiorank/mcp-gateway packages/mcp-gateway\n\ndocker run -i --rm \\\n  -e AXIORANK_KEY=axr_live_xxxxxxxxxxxxxxxx \\\n  -e AXIORANK_SERVER=github-mcp \\\n  -e GITHUB_PERSONAL_ACCESS_TOKEN=ghp_... \\\n  axiorank/mcp-gateway \\\n  -- npx -y @modelcontextprotocol/server-github\n```\n\n`-i` keeps stdin open: the MCP client speaks JSON-RPC to the container over\nstdio exactly as it would to the bare shim. The image ships Node, so\n`npx`-launched upstreams work out of the box; for an upstream that needs\nanother runtime (Python, for example), build a derived image `FROM` this one\nand install it there.\n\n## Environment\n\n| Variable | Required | Default | Description |\n| --- | --- | --- | --- |\n| `AXIORANK_KEY` | ✅ | - | The governing agent's API key. |\n| `AXIORANK_SERVER` | ✅ | - | The registered server slug (policy/audit attribution). |\n| `AXIORANK_BASE_URL` | | `https://app.axiorank.com` | AxioRank base URL. |\n| `AXIORANK_FAIL` | | `open` | `open` = forward if AxioRank is unreachable; `closed` = block. |\n\n## How it works\n\nThe shim spawns your MCP server as a child process and sits in the middle of the\ntwo newline-delimited JSON-RPC streams. It forwards everything transparently\n(`initialize`, `notifications/*`, `tools/list`, `ping`, …) and diverts only\n`tools/call`: each is sent to AxioRank for a verdict. A denied call (under\n*enforce* posture) is answered with an `isError` result the model can read; it\nnever reaches the upstream. Calls are processed in order, so responses stay\ncorrectly correlated.\n\nOnly the (server-side redacted) call arguments ever leave your machine.\n","readmeFilename":"README.md"}