writ-mcp
The Writ gate as an MCP server. Give any MCP-compatible
agent commit-time control: the agent calls Writ before a consequential
write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an
audit receipt.
Install
pip install writ-mcp
Requires Python 3.9+. Installs the writ-mcp command (stdio transport).
Configure
export WRIT_API_KEY="writ_..." # required; get one free: POST /v1/keys with an email
export WRIT_SPONSOR_TOKEN="..." # only for sponsor tools (grant, revoke, reinstate)
# export WRIT_BASE_URL="..." # default: https://api.withwrit.com
Add to your agent
Claude Code:
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp
Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"writ": {
"command": "writ-mcp",
"env": { "WRIT_API_KEY": "writ_..." }
}
}
}
Any MCP client (generic stdio config):
{
"command": "writ-mcp",
"env": {
"WRIT_API_KEY": "writ_...",
"WRIT_SPONSOR_TOKEN": "writ_sp_..."
}
}
Hermes (NousResearch/hermes-agent) catalog entry — once published, this
package is installable from the optional-mcps catalog:
hermes mcp install writ
The check-before-write loop
The tool descriptions teach the agent this flow, but the short version:
writ_check(sponsor_id, agent_id, verb, target, purpose)— before the write.ALLOW→ you get a 90-secondauthTokenbound to that exact write.writ_verify_token(auth_token, verb, target, purpose)— immediately before executing, to prove the authorization still matches what you're doing.DENY→ do not proceed.STEP_UP→ a human sponsor approves (viawrit_grantor the dashboard), then check again.
Tools
| Tool | Who | What |
|---|---|---|
writ_check |
agent | Decision + 90s purpose-bound token |
writ_verify_token |
agent | Commit-time token verification |
writ_grant |
sponsor | Approve a STEP_UP (one-time grant) |
writ_revoke / writ_reinstate |
sponsor | Kill switch on/off for a principal |
writ_receipts |
agent | Audit trail of decisions |
writ_policy |
agent | Tenant verb policy |
writ_sandbox |
anyone | Free 90-second demo grant, no key needed |
Try it with no key: writ_sandbox → writ_check with verb="demo_write".
Source
Public repo: AvenueDAdmin/pywrit (mcp/
directory). License: MIT.
Metadata
Release files for writ-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| writ_mcp-0.1.0.tar.gz | 6.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| writ_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.4 kB
Release files / writ_mcp-0.1.0.tar.gz
| Download URL | writ_mcp-0.1.0.tar.gz |
|---|---|
| Size | 6.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4a666bfe157d2a53923d294aafc285c9699b7b9e23d9606d0e47d720fac21009
|
|
BLAKE2b-256 checksum How to use checksums |
26379fc8faa5cb6ef15b31a9f566f52b383522f82d47188c89c9be7818fdc6d5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / writ_mcp-0.1.0-py3-none-any.whl
| Download URL | writ_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0b88d17eae498354364f21b51128690b5aad65f493ce8b0cae1ba9fbadbb03dc
|
|
BLAKE2b-256 checksum How to use checksums |
a005c35174ec0fb6c120d0a98e9e047375d009af8190d3426402801c884ffe9d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|