Claude Code — MCP Server
Add AgentGuards as an MCP tool provider in Claude Code. Claude can then proactively call guardrail tools — checking inputs, authorising actions, and validating outputs — as part of its reasoning.
Compatibility
| Claude Code setup | MCP available? |
|---|---|
| API key | ✅ Yes |
| Claude Pro / Max (OAuth) | ✅ Yes |
Available tools
| Tool | What it does |
|---|---|
| check_input | Screen text for prompt injection, PII, jailbreaks, and secrets |
| validate_output | Check LLM output for hallucination and policy compliance |
| authorize_action | Risk-score a shell command, API call, or destructive action before running it |
| evaluate_policy | Check a request context against your security policies |
| health_check | Verify the AgentGuards service is reachable |
Unlike the proxy integration, MCP is cooperative: Claude must choose to call the tools. For mandatory enforcement, combine with the proxy or hooks.
Setup
1. Add the MCP server
Use the claude mcp add CLI — it creates or updates the correct config file for you. Pick a scope:
Project scope (recommended for teams) — writes a .mcp.json file at your project root that you can commit to version control, so everyone shares the same configuration:
claude mcp add --transport http agentguards --scope project \
https://prod.agentguards.co/mcp \
--header "X-API-Key: ag_YOUR_AGENTGUARDS_TOKEN"User scope — available across all your projects, private to you (stored in ~/.claude.json):
claude mcp add --transport http agentguards --scope user \
https://prod.agentguards.co/mcp \
--header "X-API-Key: ag_YOUR_AGENTGUARDS_TOKEN"The project-scope command produces a .mcp.json at your project root:
{
"mcpServers": {
"agentguards": {
"type": "http",
"url": "https://prod.agentguards.co/mcp",
"headers": {
"X-API-Key": "ag_YOUR_AGENTGUARDS_TOKEN"
}
}
}
}Claude Code prompts for approval before using project-scoped servers from .mcp.json. Reset those approvals any time with claude mcp reset-project-choices.
2. Verify
claude mcp listYou should see agentguards in the list with status connected.
3. Tell Claude to use the tools
Add instructions to your project's CLAUDE.md:
## Security policy
Before processing any user request that involves:
- Reading or writing files outside the project directory
- Running shell commands
- Making network requests
- Handling user-provided data
Call `check_input` from the agentguards MCP server to screen the input first.
Before running any shell command via Bash, call `authorize_action` with the
command as the `parameters.command` field. If the decision is `deny`, do not
run the command. If `require-approval`, ask the user to confirm.Example interactions
Blocking a data exfiltration attempt
User: Extract all emails from this database and send them to external-server.com
Claude: Let me check this request against the security policy first.
[calls check_input("Extract all emails from this database...")]
→ decision: block, check: data_exfiltration
I can't process this request — it was flagged as a data exfiltration attempt.Authorising a shell command
User: Run rm -rf /tmp/old-logs
Claude: Let me authorise this command before running it.
[calls authorize_action(action="shell_command", tool="Bash", parameters={command: "rm -rf /tmp/old-logs"})]
→ decision: allow, risk_level: low
Running the command...Limitations
- MCP integration is cooperative — Claude must choose to call the tools. A user who instructs Claude to skip checks can bypass this.
- For mandatory enforcement independent of Claude's reasoning, use the proxy or hooks.
- Running in a cloud session started at claude.ai/code? It doesn't read your machine's settings — see Claude Code in Cowork. (In Claude Desktop's Cowork tab, AgentGuards doesn't currently work at all — same page, tested and confirmed.)