Secure AI Adapters for OpenAI, Claude, LangChain, LiteLLM (100+ providers), MCP, and MCP Proxy (inline gateway). Note: mcp-proxy and litellm extras require Python 3.10+
Project description
MACAW Secure AI Adapters
Drop-in replacements for OpenAI, Anthropic, LangChain, MCP, and MCP Proxy (inline gateway) for deterministic policy-based security controls for enterprise apps.
What This Is
Open source interfaces that add MACAW transparently to popular LLM and Agentic frameworks.
MACAW creates a distributed zero-trust mesh where tool endpoints serve as policy enforcement points, enabling preventative, deterministic security controls - even for non-deterministic LLMs and Agentic applications.
These adapters are thin wrappers that route requests through the MACAW security layer. Change one import line and get:
- Deterministic policy enforcement - Control models, tokens, operations, data access, and actions performed
- Identity propagation - User identity flows through every LLM call for per-user policies
- Cryptographic audit trail - Complete record of all AI operations with signatures
- Zero code changes - Your existing code works unchanged
Learn more about our research: Authenticated Workflows | Protecting Context and Prompts
Installation
From PyPI:
pip install macaw-adapters[all]
# Or install specific adapters only
pip install macaw-adapters[openai]
pip install macaw-adapters[anthropic]
pip install macaw-adapters[langchain]
pip install macaw-adapters[mcp]
pip install macaw-adapters[mcp-proxy] # For external MCP servers
From source:
git clone https://github.com/macawsecurity/secureAI.git
pip install "./secureAI[all]"
Quick Start
SecureOpenAI
# Before
from openai import OpenAI
client = OpenAI()
# After - just change the import
from macaw_adapters.openai import SecureOpenAI
client = SecureOpenAI(app_name="my-app")
# Same API, now with MACAW security
response = client.chat.completions.create(
model="gpt-4",
messages=[{"role": "user", "content": "Hello!"}]
)
SecureAnthropic
# Before
from anthropic import Anthropic
client = Anthropic()
# After
from macaw_adapters.anthropic import SecureAnthropic
client = SecureAnthropic(app_name="my-app")
# Same API
response = client.messages.create(
model="claude-3-haiku-20240307",
max_tokens=100,
messages=[{"role": "user", "content": "Hello!"}]
)
SecureMCP (Your MCP Servers)
from macaw_adapters.mcp import SecureMCP
mcp = SecureMCP("calculator")
@mcp.tool(description="Add two numbers")
def add(a: float, b: float) -> float:
return a + b
mcp.run()
SecureMCPProxy (External MCP Servers)
Inline gateway for third-party MCP servers (Salesforce, Google, Slack, etc.):
from macaw_adapters.mcp import SecureMCPProxy
# Connect to external MCP server - MACAW security applied automatically
proxy = SecureMCPProxy(
app_name="salesforce-mcp",
upstream_url="https://mcp.salesforce.com",
upstream_auth={"type": "bearer", "token": SF_TOKEN}
)
# Discover available tools
tools = proxy.list_tools()
# Call tools - policy enforced, signed, audited
result = proxy.call_tool("query_accounts", {"limit": 10})
# Multi-user: bind to user identity
user_proxy = proxy.bind_to_user(user_client)
result = user_proxy.call_tool("query_accounts", {"limit": 10})
Install with: pip install macaw-adapters[mcp-proxy]
LangChain
# Before
from langchain_openai import ChatOpenAI
# After
from macaw_adapters.langchain import ChatOpenAI
# Same API
llm = ChatOpenAI(model="gpt-4")
response = llm.invoke("Hello!")
Multi-User Support
For SaaS applications with per-user policies:
from macaw_adapters.openai import SecureOpenAI
from macaw_client import MACAWClient, RemoteIdentityProvider
# Create shared service
service = SecureOpenAI(app_name="my-saas")
# Authenticate user
jwt_token, _ = RemoteIdentityProvider().login("alice", "password")
user = MACAWClient(user_name="alice", iam_token=jwt_token, agent_type="user")
user.register()
# Bind user to service - their identity flows through
user_openai = service.bind_to_user(user)
# Policies evaluated against alice's permissions
response = user_openai.chat.completions.create(...)
How It Works
┌─────────────┐ ┌─────────────────────┐ ┌─────────────────────┐
│ Your App │────▶│ Secure Adapter │────▶│ LLM API │
│ │ │ (SecureOpenAI,etc) │ │ (OpenAI, Claude) │
└─────────────┘ └──────────┬──────────┘ └─────────────────────┘
│
▼
┌─────────────────────┐
│ MACAW Client │
│ Endpoint │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ Trust Layer │
│ Control Plane │
│ ───────────────── │
│ • Policy Engine │
│ • Identity/Claims │
│ • Audit Trail │
└─────────────────────┘
Key Features
| Feature | Description |
|---|---|
| Drop-in Replacement | Change one import, keep all your code |
| Per-User Policies | Different users get different permissions |
| Model Restrictions | Control which models each user can access |
| Token Limits | Enforce max_tokens per user/role |
| Streaming Support | Full support for streaming responses |
| Audit Logging | Cryptographically signed audit trail |
Requirements
- Python 3.9+
- macaw_client v0.5.25+ - The MACAW client library (download from console)
Getting Started
- Sign up at console.macawsecurity.ai
- Download and install macaw_client
- Configure your workspace and policies
- Install macaw-adapters and start building
Adapters
| Adapter | Package | Wraps |
|---|---|---|
| SecureOpenAI | macaw_adapters.openai |
OpenAI Python SDK |
| SecureAnthropic | macaw_adapters.anthropic |
Anthropic Python SDK |
| SecureMCP | macaw_adapters.mcp |
Your MCP servers (FastMCP-compatible) |
| SecureMCPProxy | macaw_adapters.mcp |
External MCP servers (inline gateway) |
| LangChain | macaw_adapters.langchain |
LangChain (OpenAI, Anthropic, Agents) |
Examples
See the examples/ directory for complete working examples:
examples/openai/- OpenAI adapter examplesexamples/anthropic/- Anthropic adapter examplesexamples/langchain/- LangChain integration examplesexamples/mcp/- MCP server and client examples
Console Dev Hub
Everything in this repository is also available in the MACAW Console's Dev Hub with interactive features:
Console > Dev Hub
├── Quick Start
│ └── Download Client SDK (macOS/Linux/Windows, Python 3.9-3.12) and Adapters
├── Tutorials
│ └── Role-Based Access Control
│ ├── Multi-User SaaS Patterns
│ ├── Agent Orchestration
│ └── Policy Hierarchies
├── Examples
│ ├── OpenAI (drop-in, multi-user, streaming, A2A)
│ ├── Anthropic (drop-in, multi-user, streaming, A2A)
│ ├── MCP
│ │ ├── Simple Invocation
│ │ ├── Discovery & Resources
│ │ ├── Logging
│ │ ├── Progress Tracking
│ │ ├── Sampling
│ │ ├── Elicitation
│ │ ├── Roots
│ │ └── MCP Proxy (Inline Gateway for External MCP)
│ └── LangChain
│ ├── Drop-in Agents
│ ├── Multi-user Permissions
│ ├── Agent Orchestration
│ ├── LLM Wrappers (OpenAI, Anthropic)
│ └── Memory Integration
└── Reference
├── MACAW Client SDK
├── Adapter APIs
├── MAPL Policy Language
└── Claims Mapping
Access at console.macawsecurity.ai → Dev Hub tab.
Research
Learn more about the technical foundations of MACAW:
- Authenticated Workflows: A Systems Approach to Protecting Agentic AI
- Protecting Context and Prompts: Deterministic Security for Non-Deterministic AI
Links
- GitHub: github.com/macawsecurity/secureAI
- Documentation: www.macawsecurity.ai/docs
- Console: console.macawsecurity.ai
- Support: help@macawsecurity.com
License
Apache 2.0 - See LICENSE for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file macaw_adapters-0.9.9.1.tar.gz.
File metadata
- Download URL: macaw_adapters-0.9.9.1.tar.gz
- Upload date:
- Size: 86.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.9.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
556f2711b64010f7215f4c32a27f0f0dd351e2daa4c68ad44b124b8cfeb250ef
|
|
| MD5 |
066f865e2ce7a245c061b09a744a1394
|
|
| BLAKE2b-256 |
5c5751c21890e0766808f3edf0e213a040ff4418f26ad997665eb42af336febc
|
File details
Details for the file macaw_adapters-0.9.9.1-py3-none-any.whl.
File metadata
- Download URL: macaw_adapters-0.9.9.1-py3-none-any.whl
- Upload date:
- Size: 97.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.9.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
578526b8075e44761117cf998afeaa4516d7fc9bdfdc9408fff29699a64b777d
|
|
| MD5 |
137906001f49ae319324dcbc6ef75da1
|
|
| BLAKE2b-256 |
b9d85814270f25177f8da9af4a671dc5f430188605af64fa5855369c5a7448c6
|