@tryagent/mcp-proxy
v0.0.1
Published
MCP proxy that fronts upstream MCP servers with TryAgent human-in-the-loop governance — no code changes, one config file.
Downloads
14
Maintainers
Readme
@tryagent/mcp-proxy
Human-in-the-loop governance for any MCP-speaking agent — no code changes, one config file. The proxy is an MCP server that fronts your upstream MCP servers and re-exports every tool; mapped tools escalate to TryAgent before they execute.
// tryagent-mcp.json
{
"upstreams": [
{ "name": "stripe", "command": "npx -y @stripe/mcp" }
],
"policies": {
"stripe:create_refund": "payments.refund"
},
"default": "passthrough"
}Point your MCP client at the proxy instead of the upstreams:
{
"mcpServers": {
"governed": {
"command": "npx",
"args": ["-y", "@tryagent/mcp-proxy", "--config", "tryagent-mcp.json"],
"env": { "TRYAGENT_API_KEY": "ain_live_…" }
}
}
}Behavior
- Tools are re-exported as
<upstream>__<tool>(MCP tool names disallow:); the config'spolicieskeys keep the readableupstream:toolform. Governed tools get a[TryAgent: requires approval under "<policy>"]note appended to their description so the model knows. - On a governed
tools/callthe proxy creates a TryAgent escalation (the tool args become structured evidence — rubric conditions likeargs.amount > 100evaluate against them) and honors the platform's mode ladder: arequiredrubric blocks until a human decides;reviewed/sampled/autonomouscome back system-decided immediately, so the call passes through while the decision is logged. - Unknown policy keys and agentIds auto-register on first escalate — no dashboard prework.
- Fail closed: a denial returns an MCP error result and the upstream is
never called; if the TryAgent API is unreachable, mapped tools error
instead of executing. Set
"default": "block"for allowlist-style deployments where unmapped tools are refused too.
Config reference
| Field | Meaning |
| --- | --- |
| upstreams[].name | Namespace prefix ([A-Za-z0-9_-], no __) |
| upstreams[].command | Command to spawn; inline args OK, or use args |
| upstreams[].env | Extra env for the upstream process |
| policies | "upstream:tool" → TryAgent policy key |
| default | passthrough (default) or block |
| apiKey / baseUrl | Override TRYAGENT_API_KEY / API base |
| waitIntervalMs / waitTimeoutMs | Decision polling knobs |
Requires Node.js >= 20.17.
