Trust policy before
tool execution.
MCP Hub provides a server-backed trust-policy control plane, append-only security evidence, bounded guarded execution, and a stateless MCP ingress live-verified against the isolated proof tool.
Preview the verdict model.
Simulated examples of ALLOW, FLAG, and BLOCK outcomes. No live request is evaluated on this public page.
Legitimate agent
Identity verified · Scope compliant · Normal behavior
Unknown agent
No registration · Attempted tool enumeration
Known agent — anomaly
Identity ok · Call rate 40× baseline spike
Prompt injection attempt
Jailbreak pattern detected in tool argument
How the verified enforcement boundary works
This flow is live-verified through the deployed Base44 endpoint for the bounded `probe.increment` proof tool. External-provider execution and production certification remain separate gates.
Request enters the MCP boundary
The implemented ingress authenticates a bearer credential, derives client identity server-side, validates MCP routing metadata, and exposes only bounded registered tools.
Server policy decides
The latest versioned policy evaluates the requested tool and arguments and returns ALLOW, FLAG, or BLOCK with reason codes.
Execution is conditional
Only ALLOW reaches the bounded mutation callback. FLAG requires review and BLOCK stops execution. Every decision can produce immutable evidence.
What we evaluate on every call
Six layers of evaluation fire in parallel on every inbound agent request — under 5ms, no rule writing.
Agent Identity Verification
Each agent registers a cryptographic identity. Every request is verified against that identity before any tool is exposed.
Behavioral Anomaly Detection
Hub tracks call patterns, tool enumeration, and frequency spikes. Deviations from baseline trigger automatic review.
Prompt Injection Scanning
Incoming tool arguments are scanned for injection patterns, jailbreak payloads, and policy-violating instructions.
Least-Privilege Scoping
Each agent is granted only the tools it declared it needs. Scope creep is blocked before execution.
Real-Time Threat Logging
All evaluation decisions — pass or block — are written to an immutable audit log with full request context.
Risk Scoring Dashboard
Per-agent risk scores surface trending anomalies, repeat offenders, and tool abuse patterns in one view.
Know which agents to trust.
Before they act.
Stop hoping your agents behave. Connect them through MCP Hub and get a real-time verdict on every request — legitimate, suspicious, or malicious.
- No credit card required
- Set up in minutes
- MCP-compliant