Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Tool governance

permissions:
default: deny
tools:
github.read:
allow: true
github.write:
allow: true
production.deploy:
allow: false
network:
egress: deny
allowHosts:
- mcp.example.com
secrets:
- GITHUB_TOKEN
  • allow: false wins over allow: true within one object; several permissions objects combine as an intersection.
  • resources restricts an allowed action to specific targets. If the target cannot be determined, the call is denied.
  • Permissions grant, policies restrict. Without a permissions object every action of the exposed tools is allowed by permissions; awp lint warns about this.

Normative text: Tool governance: permissions.