Local-first · Open source MCP proxy

Give your agents tools.
Keep control.

Connect your AI clients to one local proxy. Choose the servers each agent can reach, review tool changes, and run workflows with visibility and control.

Free · MIT licensed · macOS, Windows & Linux

MCPProxy macOS dashboard showing client connections, upstream servers and tools awaiting quarantine review
Real MCPProxy macOS interface · repository screenshot

One setup. Deliberate access.

From scattered servers
to a setup you can manage.

01

Add your servers

Bring local and remote MCP servers into one configuration.

02

Choose how to review

Use the TPA scanner, ask your agent to review quarantined tools, or inspect them yourself.

03

Scope agent access

Use profiles and scoped tokens to set each agent’s boundaries.

04

Connect your clients

Point your AI clients at MCPProxy and start using your tools.

More than a connection

The tools you need.
The controls you were missing.

Configuration, access, security, visibility and automation—together, between your agents and your MCP servers.

01 / Connect & discover

One place for your MCP setup.

Manage your servers once. Connect the AI clients you use and discover tools as you need them.

Explore connect & discover ↗
02 / Profiles & agent tokens

Give each agent a defined boundary.

Organize servers into profiles and issue scoped, revocable credentials for individual agents.

Explore profiles & agent tokens ↗
03 / Tool security

Check your tools. Choose how you review.

Combine quarantine, tool-change review, offline scanning, sensitive-data detection, and schema checks.

Explore tool security ↗
04 / Secrets & isolation

Be deliberate about secrets and host access.

Use OS keyring-backed secrets and optional Docker isolation for local stdio servers.

Explore secrets & isolation ↗
05 / Activity & interfaces

See what ran. Find what needs attention.

Inspect routed tool activity and manage your servers through the Web UI, CLI, or macOS menu bar.

Explore activity & interfaces ↗
06 / CLI & automation

Turn tool calls into repeatable workflows.

Check required tools, orchestrate calls in JavaScript or TypeScript, and operate the proxy from your terminal.

Explore cli & automation ↗

Your workflow. Your interface.

One proxy. Three ways in.

Web UI

Manage servers and inspect activity in the embedded browser interface.

See what ran ↗

Powerful CLI

Inspect, check and automate from the terminal. Build repeatable tool workflows.

Make it repeatable ↗

Get MCPProxy

Your next tool call starts here.

Next: connect your AI client →   ·   Release notes

Inside MCPProxy

Real screens. A setup you can see.

Actual local UI captures · September 11, 2026. Charts include demonstration traffic, not adoption metrics. Open either theme at full size.

macOS menu bar

A quick look.
Without switching windows.

Open MCPProxy from the menu bar to see recent calls, their intents, connected clients and the last 24 hours of activity.

Server controls, profiles and the full Web UI are right there when you need them.

Actual tray menu—not the main app window. Recorded local activity includes demonstration calls.

MCPProxy macOS tray menu showing a 24-hour histogram, recent calls with intents, client activity and server controls

Profiles and scanner examples below use an isolated development build with synthetic servers.

Before your first call

A little clarity goes a long way.

Do I have to review every tool manually?

No. Use the TPA scanner to check tool definitions, ask your AI agent to review quarantined tools and findings, or inspect them yourself. Agent-assisted review is not the same as granting approval: configured quarantine and approval controls still apply.

What does local-first mean?

The proxy runs on your machine. Your upstream servers and AI clients may still contact remote services; local-first does not make the whole workflow offline. The built-in tool scanner can run without network access.

Can I use my existing AI clients?

MCPProxy provides a shared MCP endpoint. Follow the connection guide for your client’s supported transport and authentication. You manage upstream servers in MCPProxy rather than repeating that setup for each client.

How are profiles different from agent tokens?

Profiles select groups of servers. Agent tokens restrict access through scoped, revocable credentials. Pinning a token to a profile keeps a session from switching beyond that restriction.

Does MCPProxy make every tool safe?

No. Quarantine, definition-change review, scanning, sensitive-data detection and schema checks add useful controls, but cannot guarantee safety. Tool implementation changes may not change their definitions, and scanner findings still need judgment.

Do I need Docker? Is code execution required?

Neither is required. Docker isolation is optional for supported stdio servers. JavaScript and TypeScript orchestration is separately opt-in.

Is it free and open source?

Yes. MCPProxy is MIT licensed. You can inspect the source, run it yourself, and contribute on GitHub.

Make your tools work for you

Give your agents tools.
Keep control.