writ-mcp
The Writ gate as an MCP server. Give any MCP-compatible
agent commit-time control: the agent calls Writ before a consequential
write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an
audit receipt.
Install
pip install writ-mcp
Requires Python 3.9+. Installs the writ-mcp command (stdio transport).
Configure
export WRIT_API_KEY="writ_..." # required; get one free: POST /v1/keys with an email
export WRIT_SPONSOR_TOKEN="..." # only for sponsor tools (grant, revoke, reinstate)
# export WRIT_BASE_URL="..." # default: https://api.withwrit.com
Add to your agent
Claude Code:
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp
Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"writ": {
"command": "writ-mcp",
"env": { "WRIT_API_KEY": "writ_..." }
}
}
}
Any MCP client (generic stdio config):
{
"command": "writ-mcp",
"env": {
"WRIT_API_KEY": "writ_...",
"WRIT_SPONSOR_TOKEN": "writ_sp_..."
}
}
Hermes (NousResearch/hermes-agent) catalog entry — once published, this
package is installable from the optional-mcps catalog:
hermes mcp install writ
The check-before-write loop
The tool descriptions teach the agent this flow, but the short version:
writ_check(sponsor_id, agent_id, verb, target, purpose)— before the write.ALLOW→ you get a 90-secondauthTokenbound to that exact write.writ_verify_token(auth_token, verb, target, purpose)— immediately before executing, to prove the authorization still matches what you're doing.DENY→ do not proceed.STEP_UP→ a human sponsor approves (viawrit_grantor the dashboard), then check again.
Tools
| Tool | Who | What |
|---|---|---|
writ_check |
agent | Decision + 90s purpose-bound token |
writ_verify_token |
agent | Commit-time token verification |
writ_grant |
sponsor | Approve a STEP_UP (one-time grant) |
writ_revoke / writ_reinstate |
sponsor | Kill switch on/off for a principal |
writ_receipts |
agent | Audit trail of decisions |
writ_policy |
agent | Tenant verb policy |
writ_sandbox |
anyone | Free 90-second demo grant, no key needed |
Try it with no key: writ_sandbox → writ_check with verb="demo_write".
Source
Public repo: AvenueDAdmin/pywrit (mcp/
directory). License: MIT.
Metadata
Release files for writ-mcp 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| writ_mcp-0.1.1.tar.gz | 6.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| writ_mcp-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.4 kB
Release files / writ_mcp-0.1.1.tar.gz
| Download URL | writ_mcp-0.1.1.tar.gz |
|---|---|
| Size | 6.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
793e1221baf31de175f150452fe924fcf9978c768f48b9f18073d59c17668bd6
|
|
BLAKE2b-256 checksum How to use checksums |
c594bec6b23e0f74de1269d98215c2e291eb9a3e4077bcc998e1e461ef1a4e12
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / writ_mcp-0.1.1-py3-none-any.whl
| Download URL | writ_mcp-0.1.1-py3-none-any.whl |
|---|---|
| Size | 6.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
24670ff7f198c80fd07af9fb9726754c8f801bf0b46654c0fb2b25e5d12c35c4
|
|
BLAKE2b-256 checksum How to use checksums |
5931b3007a1ebc3c097b8fbd6fa05acb01bd2aae2ce2c112bbe96b0eab9644fa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|