@usetorii/gateway
v0.1.20
Published
The secure gateway for AI tools. Sits between AI assistants (Claude, Cursor) and MCP servers, providing static analysis, threat modelling, policy enforcement, consent, and audit.
Readme
Torii Gateway
The runtime side of Torii. A small Node.js process that:
- speaks MCP to your AI client (Claude Desktop, Cursor, your own app),
- proxies tool calls to the real MCP servers you've registered,
- enforces policies (block, ask-me-first),
- streams audit + threat findings to the Torii backend, and
- runs the local pieces of the consent flow.
It pairs with a TORII_API_KEY you generate in the dashboard.
Install
Pick one. Same binary, different package.
1. npx (no install)
// claude_desktop_config.json
{
"mcpServers": {
"torii": {
"command": "npx",
"args": ["-y", "@usetorii/gateway"],
"env": { "TORII_API_KEY": "tok_..." }
}
}
}2. Native binary
# macOS / Linux (Homebrew)
brew install scumfrog/tap/torii
# Linux / macOS (curl)
curl -fsSL https://usetorii.dev/install.sh | shThen in claude_desktop_config.json:
{
"mcpServers": {
"torii": {
"command": "torii",
"env": { "TORII_API_KEY": "tok_..." }
}
}
}3. Docker
docker pull ghcr.io/scumfrog/torii-gateway:latest{
"mcpServers": {
"torii": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "TORII_API_KEY",
"ghcr.io/scumfrog/torii-gateway:latest"
],
"env": { "TORII_API_KEY": "tok_..." }
}
}
}Configuration
Without a TORII_API_KEY, the gateway looks for a local YAML config at:
$TORII_CONFIGif set, else~/.torii/config.yaml
See the config schema for the full shape.
When TORII_API_KEY is set, the gateway pulls its config from
https://api.usetorii.dev/v1/me/servers/config so you can manage everything
from the dashboard.
Local development
pnpm install
pnpm run build
node dist/index.jsHow distribution works
- Tag a release:
git tag v0.x.y && git push --tags. .github/workflows/release.ymlruns and:- publishes
@usetorii/gatewayto npm (needsNPM_TOKENsecret), - builds native binaries for macOS/Linux × x64/arm64 with
bun build --compile, - uploads them to a GitHub Release with SHA-256 checksums,
- builds and pushes a multi-arch Docker image to
ghcr.io/scumfrog/torii-gateway, - bumps the
homebrew-tapformula (needsHOMEBREW_TAP_TOKENsecret).
- publishes
To bootstrap the secrets:
# in this repo
gh secret set NPM_TOKEN -b "<from https://www.npmjs.com/settings/tokens>"
gh secret set HOMEBREW_TAP_TOKEN -b "<a PAT with 'repo' scope on scumfrog/homebrew-tap>"GITHUB_TOKEN is auto-injected by Actions for the GHCR push.
License
MIT. See LICENSE.
Part of Torii
Torii is split across standalone repos — this repo is the source of truth for the gateway runtime; edit here, not in any monorepo copy.
| Component | Repo | Deploys to |
|---|---|---|
| API + workers | Torii-api | Railway · api.usetorii.dev |
| Dashboard + landing | Torii-front | Vercel · usetorii.dev |
| Gateway runtime | Torii-gateway | npm / Homebrew / GHCR / install.sh |
