Add Arbitus - Security proxy for MCP servers#122
Open
nfvelten wants to merge 1 commit intoPuliczek:mainfrom
Open
Add Arbitus - Security proxy for MCP servers#122nfvelten wants to merge 1 commit intoPuliczek:mainfrom
nfvelten wants to merge 1 commit intoPuliczek:mainfrom
Conversation
Arbitus is a security proxy that sits between AI agents and MCP servers. It enforces per-agent policies before any tool call reaches the upstream. Key features: - Per-agent auth (API key, JWT/OIDC, mTLS) - Rate limiting (sliding window, per-tool, per-IP) - Payload filtering (encoding-aware: Base64, URL, Unicode) - Human-in-the-Loop (HITL) approval workflow - Shadow mode for dry-run operations - OPA/Rego policy engine - Schema validation against inputSchema - Audit logging (SQLite, webhook, OpenLineage, CloudEvents) - Circuit breaker for upstream failures - Both HTTP+SSE and stdio transports - Written in Rust, sub-millisecond overhead
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added Arbitus - Security proxy for MCP servers
Description
Arbitus is a security proxy that sits between AI agents (Cursor, Claude, Windsurf, etc.) and MCP servers. It enforces per-agent policies before any tool call reaches the upstream server.
Key Features
Checklist
Repository Stats