Browse
→ Infrastructure
→ MCP Bastion
MCP Bastion
Local zero-trust checkpoint for stdio MCP tool traffic. The Rust gateway reads newline-delimited JSON-RPC, extracts method, tool name, and arguments, enforces allow, deny, redact, size, depth, and rate policies before forwarding, fails closed when it cannot confidently authorize a request, and writes one-line audit events for forwarded and blocked calls. Public GitHub repository created September 22, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | none |
| Endpoint | mcp-bastion local stdio relay |
| Install | git clone https://github.com/Matthew0822/MCPBastion.git && cd MCPBastion && cargo build --release |
Use Cases
| 01 | Put a local policy enforcement point between an MCP client and a sensitive stdio MCP server |
| 02 | Deny dangerous tool names, redact arguments, cap request size or depth, and audit every decision |
| 03 | Experiment with fail-closed MCP security controls without adding a cloud dependency |
Tags
security zero-trust gateway policy redaction audit rust stdio
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>