Integrations
MCP Integration
Model Context Protocol tool call and server governance.
MCP Integration
Overview
AgentTrust provides mcp_tool_guard and MCPServerGuard for Model Context Protocol servers and tool invocations. Validates tool inputs/outputs at the MCP boundary.
Tier: Developer+
Why It Matters
MCP tools expose agents to external capabilities. Tool trust checks at the MCP layer prevent unauthorized or risky tool executions.
Prerequisites
pip install agentrust-py
# Developer+ API key for MCP adapterStep-by-Step Guide
from mcp.server.fastmcp import FastMCP
from agentrust_sdk import mcp_tool_guard, MCPServerGuard
# ── Option A: guard individual tool functions ──────────────────────────
@mcp_tool_guard(agent_id="mcp-tools", base_url="http://127.0.0.1:8765")
async def my_tool_handler(request):
return await execute_tool(request)
# ── Option B: guard every tool registered on a server ──────────────────
mcp = FastMCP("payments-server")
@mcp.tool()
async def process_payment(amount: float, account: str) -> dict:
...
# The server instance is the FIRST positional argument.
guard = MCPServerGuard(mcp, agent_id="payments-mcp", base_url="http://127.0.0.1:8765")
# process_payment is now governed — every call is validated.MCPServerGuard patches the already-registered tool handlers, so construct it after
all @mcp.tool() registrations. Both entry points default base_url to
http://localhost:8000 and do not read AGENTRUST_GATEWAY_URL.
Examples
See agentrust_sdk/agentrust_sdk/adapters/mcp.py.
Best Practices
- Guard at server level for comprehensive coverage
- Include tool name and arguments in validation metadata
- Use tool trust policy rules for allowlist/denylist
Common Mistakes
- Catching
TierGateError— the guard raises plainRuntimeErrorat construction - Constructing
MCPServerGuard(agent_id=...)without the server —serveris the first positional argument - Constructing the guard before the tools are registered
Troubleshooting
| Issue | Fix |
|---|---|
| Tool trust check fails | Review tool allowlist in policy pack |
RuntimeError: [AgentTrust] MCP adapter requires Developer tier… | Upgrade to Developer tier (this is not a TierGateError) |