CAIN-42 · Secure tools & MCP servers
MCPGate
The gate in front of your tools: an agent touches a tool only when CAIN says yes.
Last reviewed 2026-10-01
Live Core platform · infrastructure
What it is
Model Context Protocol gateway with hosted MCP tools.
Where it fits
Part of Secure tools & MCP servers: Check, pin and gate the tools your agents can reach. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Open it
https://mcpgate.online - Documentation
https://cainstudio.online/docs/mcp - API endpoint
https://cainstudio.online/mcp
Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Tools, MCP, protocols & adapters: 684 tested invariants — How agents reach tools, APIs and each other, safely.
- Supply chain, registry & lifecycle: 246 tested invariants — Where agents, models and tools come from, and how they change.
Related
- CAIN Skills — A catalog of the skills your agents may use, each one reviewed and governed.
- Chat — Chat with the MCPGate tools from your browser.
- DriftGuard — Pins your MCP tool definitions and alerts you if one is silently changed.
- Flowgate — Checks an agent pipeline for loops and bad ordering before it runs.
- MCP Protocol Explorer — Browse and call MCP tools interactively to see how they behave.
- MCP Security Scanner — Scans MCP tools for hidden instructions, leaked keys and dangerous parameters.
- MCPiverse — Turns any API description into a signed MCP server your agents can use.
- MeshRouter — Routes each agent request to the right service, with rate limits and circuit breakers.
- ToolWarden — Runs MCP tools in a sandbox with size limits and injection screening.
Full documentation
The complete reference, also at /docs/mcp.
Protecting an MCP server#
MCP is where an agent actually reaches the world, so it is the highest-value thing to put a decision in front of.
The shape of it#
Instead of your client talking to your MCP server directly, it talks to MCPGate, which decides and then forwards:
MCP client -> MCPGate (decides, enforces) -> your MCP server -> tool runs
One command#
cain protect mcp ./my-server
> cain is the operator CLI that ships with self-hosted MCPGate; it is not installable on its own yet (CLI reference). With only the SDK, use cainstudio or plain curl (see the quickstart).
That inspects the target and prints what to change. It does not rewrite your MCP client configuration -- reconfiguring a developer's environment unprompted is the kind of surprise that loses trust, so the change is shown and applied only with --apply.
It reports what it found: whether the target exists, whether it is a local directory or a remote URL, and how many tools appear to be declared. The tool count is derived by reading source files, not by executing the server -- a security tool that runs an unknown MCP server to enumerate its tools would be a remarkable thing.
Then prove the path#
cain test --mcp
This is the check that matters, because "I pointed my client at the gateway" and "calls are actually being decided" are different claims. Note that the client-side suite reports MCP path enforcement as SKIP when it cannot observe it directly -- a skip is not a pass, and it withholds the conformance claim.
Declaring servers#
mcp:
servers:
- ./my-server
- https://tools.internal/mcp
cain test checks these are declared. With none listed, the MCP suite skips rather than passing vacuously.
What is protected, and what is not#
Protected: the decision to allow a tool call, made before the call reaches your server, recorded as evidence.
Not protected by this alone: anything that talks to your MCP server without going through the gateway. If the server is still reachable directly, a client that skips the gateway skips the decision. Bind it to localhost, or put it on a network only the gateway can reach. cain doctor cannot see this for you, and does not claim to.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem