Add your servers
Bring local and remote MCP servers into one configuration.
Local-first · Open source MCP proxy
Connect your AI clients to one local proxy. Choose the servers each agent can reach, review tool changes, and run workflows with visibility and control.
Free · MIT licensed · macOS, Windows & Linux

One setup. Deliberate access.
Bring local and remote MCP servers into one configuration.
Use the TPA scanner, ask your agent to review quarantined tools, or inspect them yourself.
Use profiles and scoped tokens to set each agent’s boundaries.
Point your AI clients at MCPProxy and start using your tools.
More than a connection
Configuration, access, security, visibility and automation—together, between your agents and your MCP servers.
Manage your servers once. Connect the AI clients you use and discover tools as you need them.
Explore connect & discover ↗Organize servers into profiles and issue scoped, revocable credentials for individual agents.
Explore profiles & agent tokens ↗Combine quarantine, tool-change review, offline scanning, sensitive-data detection, and schema checks.
Explore tool security ↗Use OS keyring-backed secrets and optional Docker isolation for local stdio servers.
Explore secrets & isolation ↗Inspect routed tool activity and manage your servers through the Web UI, CLI, or macOS menu bar.
Explore activity & interfaces ↗Check required tools, orchestrate calls in JavaScript or TypeScript, and operate the proxy from your terminal.
Explore cli & automation ↗Your workflow. Your interface.
Manage servers and inspect activity in the embedded browser interface.
See what ran ↗A quick look at your servers, with management close at hand while you work.
Keep an eye on your setup ↗Inspect, check and automate from the terminal. Build repeatable tool workflows.
Make it repeatable ↗Get MCPProxy
Run the DMG and follow the setup wizard.
Built-in auto-updater included.
Recommended: signed installer.
Install with the setup wizard.
Recommended: signed apt/dnf repositories with package-manager updates.
Set up apt / dnf ↗Other packages available in release notes.Inside MCPProxy
Actual local UI captures · September 11, 2026. Charts include demonstration traffic, not adoption metrics. Open either theme at full size.
Call counts, response sizes and activity charts from a running local proxy.
Read the intent behind a request and inspect its recorded outcome.
macOS menu bar
Open MCPProxy from the menu bar to see recent calls, their intents, connected clients and the last 24 hours of activity.
Server controls, profiles and the full Web UI are right there when you need them.
Actual tray menu—not the main app window. Recorded local activity includes demonstration calls.
Profiles and scanner examples below use an isolated development build with synthetic servers.
Before your first call
No. Use the TPA scanner to check tool definitions, ask your AI agent to review quarantined tools and findings, or inspect them yourself. Agent-assisted review is not the same as granting approval: configured quarantine and approval controls still apply.
The proxy runs on your machine. Your upstream servers and AI clients may still contact remote services; local-first does not make the whole workflow offline. The built-in tool scanner can run without network access.
MCPProxy provides a shared MCP endpoint. Follow the connection guide for your client’s supported transport and authentication. You manage upstream servers in MCPProxy rather than repeating that setup for each client.
Profiles select groups of servers. Agent tokens restrict access through scoped, revocable credentials. Pinning a token to a profile keeps a session from switching beyond that restriction.
No. Quarantine, definition-change review, scanning, sensitive-data detection and schema checks add useful controls, but cannot guarantee safety. Tool implementation changes may not change their definitions, and scanner findings still need judgment.
Neither is required. Docker isolation is optional for supported stdio servers. JavaScript and TypeScript orchestration is separately opt-in.
Yes. MCPProxy is MIT licensed. You can inspect the source, run it yourself, and contribute on GitHub.
Make your tools work for you