writ-mcp
The Writ gate as an MCP server. Give any MCP-compatible
agent commit-time control: the agent calls Writ before a consequential
write, gets back ALLOW, DENY, or STEP_UP, and every outcome creates an
audit receipt.
Install
pip install writ-mcp
Requires Python 3.9+. Installs the writ-mcp command (stdio transport).
Configure
export WRIT_API_KEY="writ_..." # required; get one free: POST /v1/keys with an email
export WRIT_SPONSOR_TOKEN="..." # only for sponsor tools (grant, revoke, reinstate)
# export WRIT_BASE_URL="..." # default: https://api.withwrit.com
Add to your agent
Claude Code:
claude mcp add writ --env WRIT_API_KEY="$WRIT_API_KEY" -- writ-mcp
Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"writ": {
"command": "writ-mcp",
"env": { "WRIT_API_KEY": "writ_..." }
}
}
}
Any MCP client (generic stdio config):
{
"command": "writ-mcp",
"env": {
"WRIT_API_KEY": "writ_...",
"WRIT_SPONSOR_TOKEN": "writ_sp_..."
}
}
Hermes (NousResearch/hermes-agent) catalog entry — once published, this
package is installable from the optional-mcps catalog:
hermes mcp install writ
The check-before-write loop
The tool descriptions teach the agent this flow, but the short version:
writ_check(sponsor_id, agent_id, verb, target, purpose)— before the write.ALLOW→ you get a 90-secondauthTokenbound to that exact write.writ_verify_token(auth_token, verb, target, purpose)— immediately before executing, to prove the authorization still matches what you're doing.DENY→ do not proceed.STEP_UP→ a human sponsor approves (viawrit_grantor the dashboard), then check again.
Tools
| Tool | Who | What |
|---|---|---|
writ_check |
agent | Decision + 90s purpose-bound token |
writ_verify_token |
agent | Commit-time token verification |
writ_grant |
sponsor | Approve a STEP_UP (one-time grant) |
writ_revoke / writ_reinstate |
sponsor | Kill switch on/off for a principal |
writ_receipts |
agent | Audit trail of decisions |
writ_policy |
agent | Tenant verb policy |
writ_sandbox |
anyone | Free 90-second demo grant, no key needed |
Try it with no key: writ_sandbox → writ_check with verb="demo_write".
Source
Public repo: AvenueDAdmin/pywrit (mcp/
directory). License: MIT.
Metadata
Release files for writ-mcp 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| writ_mcp-0.1.2.tar.gz | 6.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| writ_mcp-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.4 kB
Release files / writ_mcp-0.1.2.tar.gz
| Download URL | writ_mcp-0.1.2.tar.gz |
|---|---|
| Size | 6.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4823c0e2308713639095cbdbc38c32ad65ce00e8bf9bc9743d4e575c8872e7d8
|
|
BLAKE2b-256 checksum How to use checksums |
2fef595d86cd7ffa6c2bbf08fc96ee5907aba464d4405d10018138fb4e2b0f4a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / writ_mcp-0.1.2-py3-none-any.whl
| Download URL | writ_mcp-0.1.2-py3-none-any.whl |
|---|---|
| Size | 6.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d58f4bc126b86c5910b03d65456c121b4f0870e909d4b350560d4ada2ea3e8e4
|
|
BLAKE2b-256 checksum How to use checksums |
695d690caaa7230f81bc610e453b5dffb1afbfdb9c4a3702d47467970b1efbf5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|