Back to Directory/Developer Tools

io.github.declaw-ai/mcp-server

Secure Firecracker microVM sandboxes for AI agents: network policy, PII & injection guardrails.

Developer ToolsTypeScriptv0.1.2

Declaw MCP Server

MCP server for Declaw — secure sandbox execution for AI agents with network policies, PII scanning, prompt injection defense, and audit logging.

Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool.

Quick Start

Claude Desktop / Cursor / Windsurf

Add to your MCP config:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key"
      }
    }
  }
}

Claude Code

claude mcp add declaw -- npx -y @declaw/mcp-server

Set DECLAW_API_KEY in your environment.

Tools

ToolDescription
create_sandboxCreate a secure sandbox with configurable security policies
run_commandExecute a shell command inside a sandbox
read_fileRead a file from a sandbox
write_fileWrite a file to a sandbox
list_filesList directory contents in a sandbox
kill_sandboxDestroy a sandbox
list_sandboxesList all active sandboxes

Security Presets

When creating a sandbox, choose a security preset:

  • none — No guardrails. Full internet access.
  • standard (default) — PII scanning + audit logging. Full internet access.
  • strict — PII scanning + prompt injection defense + audit logging + network deny-all.

You can also pass allowed_domains to restrict outbound traffic to specific domains:

create_sandbox with template="python", security_preset="strict", allowed_domains=["pypi.org", "github.com"]

Why Declaw?

DeclawOther Sandbox Providers
Sandbox executionYesYes
Non-bypassable network controlsYes??
PII scanningYesNo
Injection defenseYesNo
Full audit trailYesBasic
SnapshotsYesVaries
Multiple templates8 built-inVaries
Interactive stdioYesVaries

Environment Variables

VariableRequiredDescription
DECLAW_API_KEYYesYour Declaw API key
DECLAW_DOMAINNoCustom API domain (for on-prem deployments)

On-Prem

For self-hosted Declaw deployments, set the domain:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key",
        "DECLAW_DOMAIN": "declaw.internal.company.com"
      }
    }
  }
}

License

Apache-2.0

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @declaw/mcp-server

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-declaw-ai-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@declaw/mcp-server"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@declaw/mcp-servernpm

Compatible MCP Clients

io.github.declaw-ai/mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More