PluginBench
MCP Server
Active
Apache-2.0

TAP MCP Server

tech.human/tap

Credential isolation and approval gating for AI agents with policy enforcement and human oversight.

What is the TAP MCP server?

The TAP (Tool Authorization Protocol) MCP server provides credential isolation, approval gating, and connector routing for AI agents. It keeps secrets out of agent contexts using placeholder credentials, enforces access policies, and enables optional human approval workflows. TAP can be self-hosted or used via a managed service with hardware-enclave credential protection.

TAP solves the problem of safely giving AI agents access to external tools and APIs without exposing credentials directly in agent contexts. It acts as a proxy that substitutes placeholder credentials, validates requests against policies, routes to appropriate connectors, and optionally gates requests through human approval (via Telegram or Matrix bots). Use it when you need fine-grained control over what APIs your agents can call and want audit trails and approval workflows.

How to install TAP

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • X-TAP-Key
    required
    secret

    TAP agent API key (create one at tap.human.tech)

~/.cursor/mcp.json
{
  "mcpServers": {
    "tap": {
      "url": "https://mcp.tap.human.tech/mcp"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Credential substitution — Replace real credentials with placeholders in agent requests, validating credential position and format
  • Policy enforcement — Evaluate and enforce approval policies on incoming requests
  • Connector routing — Route requests to appropriate backend connectors based on request shape and configuration
  • Approval bots — Telegram and Matrix bots for optional human approval of gated requests
  • Request auditing — Log and audit request routing, connector behavior, and approval flows

Use cases

  • Gate AI agent access to sensitive APIs with human approval workflows
  • Isolate credentials from agent contexts using placeholder substitution
  • Audit and debug all requests routed through agents to external services
  • Enforce fine-grained access policies on agent tool usage
  • Route agent requests to multiple backend connectors with consistent credential handling

TAP MCP server FAQ

What is the TAP MCP server?

TAP is a credential isolation and approval-gating proxy for AI agents. It substitutes real credentials with placeholders, enforces policies, routes requests to connectors, and optionally requires human approval via Telegram or Matrix bots.

Is TAP free?

TAP is open-source under Apache-2.0 and free to self-host. A managed hosted version is also available at tap.human.tech, starting free with credentials stored in a hardware enclave.

How do I install TAP in Cursor or Claude?

TAP is available as a remote MCP server at https://mcp.tap.human.tech/mcp. Add it to your MCP configuration with the remote (streamable-http) connection method.

What authentication is required?

TAP manages credentials for your backend connectors and APIs. You configure credentials in TAP, and it substitutes placeholders in agent requests. For the hosted version, credentials are stored in a hardware enclave.

Can I self-host TAP?

Yes, TAP is fully open-source and can be self-hosted. However, self-hosting requires you to manage security of credentials, signing keys, host hardening, and policy-engine operation. The hosted version is recommended for teams without deep security expertise.

What approval workflows does TAP support?

TAP includes approval bots for Telegram and Matrix that can gate requests requiring human sign-off before they reach backend connectors.

README (reference)

Source of truth, from the repository.

Tool Authorization Protocol (TAP)

Credential isolation, approval gating, and connector routing for AI agents.

This repository contains the code that is most useful for:

  • auditing request routing and connector behavior
  • debugging failed requests
  • understanding approval flows
  • improving connector-side request shaping
  • contributing fixes to the core TAP experience

[!WARNING] Self-hosting means you own the security of your credentials and signing keys. TAP keeps secrets out of your agents, but running it yourself puts the host hardening, key isolation, and correct policy-engine operation on you. It's a path for teams that are well versed in security. For everyone else the hosted version is strongly recommended: credentials sit in a hardware enclave we can't read into, with no ops to run. Start free at tap.human.tech.

Start Here

  • crates/tap-proxy/src/routing.rs — how TAP resolves connector target shapes
  • crates/tap-proxy/src/placeholder.rs — credential substitution and position validation
  • crates/tap-proxy/src/policy.rs — approval policy enforcement
  • docs/ — full documentation including self-hosting guide

Included

  • core proxy and storage crates
  • Telegram and Matrix approval bots
  • remote MCP server (tap-mcp)
  • CLI
  • docs (self-hosting, API reference, credential setup)

Not Included

  • enclave deployment glue (CCE policy generation, release-policy automation, ARM templates, env config)
  • production workflows and secret bootstrapping
  • managed hosting operations glue
  • the hosted dashboard UI source (a placeholder is shipped so the proxy compiles)

The enclave key-management source is included (key_provider_enclave.rs, kms_azure.rs, skr.rs) — it's the custody model documented at docs.tap.human.tech/security, and each hosted release's enclave measurement is published in measurements/. Hosted deployment and operational infrastructure are maintained separately from this repository.

Security

See SECURITY.md to report a vulnerability.

License

Apache-2.0: free to use, read, modify, and self-host. This repo is the open-source TAP runtime (tap-core, tap-proxy, tap-bot, tap-cli, tap-mcp). The hosted dashboard and managed-service deployment glue are proprietary and live in a separate private repo.

Contributing

See CONTRIBUTING.md.

Testing

# Needs Postgres (default postgres://tap:tap@localhost:5434/tap, override with
# POSTGRES_DATABASE_URL). Isolated suites parallelize; env-mutating unit tests stay serial.
cargo test -p tap-core
cargo test -p tap-proxy --test integration --test e2e
cargo test -p tap-proxy -p tap-bot -p tap-cli --lib --bins -- --test-threads=1

Related MCP servers

Print & mail PDF/HTML/Markdown/text/DOCX/images to US addresses; pay per call in x402 USDC on Base.

1
View repository →

Issue tracker and wiki for teams and their agents: find, file and update issues, write pages.

TEtech.kasabeh/baton logo

Convert coding-agent sessions between Claude Code, OpenCode, Codex, and 6+ others—keep context and continue mid-task.

23
Rust
Apache-2.0
View repository →

European-first forecasts, fundamental screening, and historical market cap.

MCP server exposing Mélodium program validation and reference lookup

View repository →

Search transcripts and summaries of your meetings, calls, and recordings in Memo AI