What is the Iris MCP server?
Stop shipping agents on vibes. Score every agent output for quality, safety, and cost.
How to install Iris
Copy-paste configuration for popular MCP clients.
IRIS_API_KEYsecretAPI key for HTTP authentication. Required to bind the HTTP transport or the dashboard beyond loopback (0.0.0.0, a LAN address, a container): without it the server refuses to start
IRIS_API_KEY_FILEPath to a file whose trimmed contents are the API key (the secret-file pattern Docker and Kubernetes mount). Set this or IRIS_API_KEY, not both; further keys and rotation are security.apiKeys in config.json
IRIS_ALLOW_UNAUTHENTICATEDSet to 1 to run a non-loopback bind with NO API key on purpose (lifts the startup refusal; the network is then your boundary)
IRIS_DB_PATHSQLite database path
IRIS_SQLITE_DRIVERWhich SQLite driver holds the database: native (better-sqlite3, the default) or node (Node's built-in node:sqlite, Node 22.13+). Unset: native, falling back to node when the native module cannot load
IRIS_LOG_LEVELLog level: debug, info, warn, error
IRIS_HOMEDirectory for the database, custom rules and preferences (default ~/.iris)
IRIS_ANTHROPIC_API_KEYsecretEnables evaluate_with_llm_judge and verify_citations with an Anthropic model. Optional: the deterministic rules never need a key
IRIS_OPENAI_API_KEYsecretEnables evaluate_with_llm_judge and verify_citations with an OpenAI model. Optional: the deterministic rules never need a key
IRIS_LLM_JUDGE_MAX_COST_USD_PER_EVALHard cap on the worst-case cost of one judge or citation call (default 0.25)
IRIS_CITATION_ALLOW_FETCHLet verify_citations fetch URLs (off by default)
IRIS_DASHBOARDStart the dashboard alongside the server (same as --dashboard)
IRIS_DASHBOARD_PORTDashboard port (default 6920); IRIS_PORT is the MCP HTTP transport port (default 3000)
IRIS_PORTMCP HTTP transport port (default 3000); only used with --transport http
IRIS_OTEL_ENDPOINTOTLP/HTTP collector URL; when set, every stored trace is also exported as OpenTelemetry spans (best-effort, asynchronous)
IRIS_CITATION_DOMAINSComma-separated domain allowlist for verify_citations fetches (only consulted when IRIS_CITATION_ALLOW_FETCH is on)
IRIS_TRANSPORTTransport: stdio (default) or http; same as --transport
IRIS_HOSTBind host for the HTTP transport (default 127.0.0.1); only used with --transport http
IRIS_ALLOWED_ORIGINSComma-separated Origin allowlist for the HTTP transport and dashboard CORS (default http://localhost:*)
IRIS_DASHBOARD_HOSTBind host for the dashboard (default 127.0.0.1); same as --dashboard-host
IRIS_OTEL_HEADERSComma-separated key=value headers sent with every OTLP export (for example an auth token for your collector)
IRIS_OTEL_SERVICE_NAMEservice.name resource attribute on exported spans (default iris-eval)
IRIS_OTEL_TIMEOUT_MSTimeout in milliseconds for each OTLP export request
IRIS_WEBHOOK_URLThe receiver of the webhook that fires on a moment (docs/webhooks.md); merged over notify.webhook in config.json
IRIS_WEBHOOK_SECRETsecretThe signing key of that webhook (any string, or whsec_ + base64); the iris format refuses to run without one
Related MCP servers

MemoryGuard
Local-first governed MCP memory backend for coding agents.
Threads tools for AI — generate viral posts, download videos, export profiles
View repository →
Automated web QA via Chrome DevTools MCP — a11y, security, visual, env diff, CI; Aegis redaction.

io.github.ironflowsh/mcp
Read-only Hyperliquid data for AI agents: fills, candles, funding, liquidations, wallet analytics.

io.github.irrenwill/secret-safe-env
Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI)
