Skip to content

feat(policy): an MCP access preset, or a validator message that says what to write when access presets are rejected on protocol: mcp #4293

Description

@anthonychung

Version. OpenShell 0.1.2. Observed 2026-09-29.

Observed. On an endpoint declared protocol: mcp, access: read-only fails policy validation. The form that works is an explicit tools/call params.name allowlist plus the handshake methods. The validator message says the preset is rejected but not what to write instead.

Why it matters. read-only is the first thing anyone writes for an MCP endpoint, and the natural reading of "rejected" is "MCP does not support access control", not "write the explicit list". We only found the working form by reading l7_validate.rs.

Ask. Either of:

  1. An MCP access preset that means handshake + tools/list only (the MCP equivalent of read-only), or
  2. A validator message that names the required explicit form, e.g. "access presets do not apply to protocol: mcp; declare tools/call params.name entries plus initialize, notifications/initialized, tools/list".

Activity

  1. shiju-nv commented on Oct 7, 2026

    @shiju-nv
    Collaborator

    OpenShell already supports MCP access control through explicit method and tool rules. The v0.1.2 documentation includes the initialization methods and a tool allowlist.

    There is also mcp.allow_all_known_mcp_methods: true, but without explicit allow rules it permits tool execution too.

    For that behavior, remove access and use these fields on the MCP endpoint, retaining its host and port:

    protocol: mcp
    enforcement: enforce
    rules:
      - allow:
          method: initialize
      - allow:
          method: notifications/initialized
      - allow:
          method: tools/list

    This allows initialization and tool discovery without allowing tools/call. To permit selected tools, add method: tools/call rules with tool or params.name matchers.

    The v0.1.2 validator already points to rules/deny_rules and the allow-all option. Could you share the exact error and command you saw? That would help identify whether another validation path loses this guidance.

  2. shiju-nv commented on Oct 7, 2026

    @shiju-nv
    Collaborator

    For MCP and generic JSON-RPC, access presets like access: read-only are currently unsupported. Both reading and writing can happen through the same RPC method, so policies use explicit method rules and, for MCP, tool-name rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions