TAP MCP Server
tech.human/tap
Credential isolation and approval gating for AI agents with policy enforcement and human oversight.
What is the TAP MCP server?
The TAP (Tool Authorization Protocol) MCP server provides credential isolation, approval gating, and connector routing for AI agents. It keeps secrets out of agent contexts using placeholder credentials, enforces access policies, and enables optional human approval workflows. TAP can be self-hosted or used via a managed service with hardware-enclave credential protection.
TAP solves the problem of safely giving AI agents access to external tools and APIs without exposing credentials directly in agent contexts. It acts as a proxy that substitutes placeholder credentials, validates requests against policies, routes to appropriate connectors, and optionally gates requests through human approval (via Telegram or Matrix bots). Use it when you need fine-grained control over what APIs your agents can call and want audit trails and approval workflows.
How to install TAP
Copy-paste configuration for popular MCP clients.
X-TAP-KeyrequiredsecretTAP agent API key (create one at tap.human.tech)
Tools & capabilities
Tools this server exposes to the agent.
Credential substitution— Replace real credentials with placeholders in agent requests, validating credential position and formatPolicy enforcement— Evaluate and enforce approval policies on incoming requestsConnector routing— Route requests to appropriate backend connectors based on request shape and configurationApproval bots— Telegram and Matrix bots for optional human approval of gated requestsRequest auditing— Log and audit request routing, connector behavior, and approval flows
Use cases
- Gate AI agent access to sensitive APIs with human approval workflows
- Isolate credentials from agent contexts using placeholder substitution
- Audit and debug all requests routed through agents to external services
- Enforce fine-grained access policies on agent tool usage
- Route agent requests to multiple backend connectors with consistent credential handling
TAP MCP server FAQ
TAP is a credential isolation and approval-gating proxy for AI agents. It substitutes real credentials with placeholders, enforces policies, routes requests to connectors, and optionally requires human approval via Telegram or Matrix bots.
TAP is open-source under Apache-2.0 and free to self-host. A managed hosted version is also available at tap.human.tech, starting free with credentials stored in a hardware enclave.
TAP is available as a remote MCP server at https://mcp.tap.human.tech/mcp. Add it to your MCP configuration with the remote (streamable-http) connection method.
TAP manages credentials for your backend connectors and APIs. You configure credentials in TAP, and it substitutes placeholders in agent requests. For the hosted version, credentials are stored in a hardware enclave.
Yes, TAP is fully open-source and can be self-hosted. However, self-hosting requires you to manage security of credentials, signing keys, host hardening, and policy-engine operation. The hosted version is recommended for teams without deep security expertise.
TAP includes approval bots for Telegram and Matrix that can gate requests requiring human sign-off before they reach backend connectors.
README (reference)
Source of truth, from the repository.
Tool Authorization Protocol (TAP)
Credential isolation, approval gating, and connector routing for AI agents.
This repository contains the code that is most useful for:
- auditing request routing and connector behavior
- debugging failed requests
- understanding approval flows
- improving connector-side request shaping
- contributing fixes to the core TAP experience
[!WARNING] Self-hosting means you own the security of your credentials and signing keys. TAP keeps secrets out of your agents, but running it yourself puts the host hardening, key isolation, and correct policy-engine operation on you. It's a path for teams that are well versed in security. For everyone else the hosted version is strongly recommended: credentials sit in a hardware enclave we can't read into, with no ops to run. Start free at tap.human.tech.
Start Here
crates/tap-proxy/src/routing.rs— how TAP resolves connector target shapescrates/tap-proxy/src/placeholder.rs— credential substitution and position validationcrates/tap-proxy/src/policy.rs— approval policy enforcementdocs/— full documentation including self-hosting guide
Included
- core proxy and storage crates
- Telegram and Matrix approval bots
- remote MCP server (
tap-mcp) - CLI
- docs (self-hosting, API reference, credential setup)
Not Included
- enclave deployment glue (CCE policy generation, release-policy automation, ARM templates, env config)
- production workflows and secret bootstrapping
- managed hosting operations glue
- the hosted dashboard UI source (a placeholder is shipped so the proxy compiles)
The enclave key-management source is included (key_provider_enclave.rs,
kms_azure.rs, skr.rs) — it's the custody model documented at
docs.tap.human.tech/security, and each
hosted release's enclave measurement is published in measurements/.
Hosted deployment and operational infrastructure are maintained separately from this repository.
Security
See SECURITY.md to report a vulnerability.
License
Apache-2.0: free to use, read, modify, and self-host. This repo is the
open-source TAP runtime (tap-core, tap-proxy, tap-bot, tap-cli, tap-mcp). The
hosted dashboard and managed-service deployment glue are proprietary and live in
a separate private repo.
Contributing
See CONTRIBUTING.md.
Testing
# Needs Postgres (default postgres://tap:tap@localhost:5434/tap, override with
# POSTGRES_DATABASE_URL). Isolated suites parallelize; env-mutating unit tests stay serial.
cargo test -p tap-core
cargo test -p tap-proxy --test integration --test e2e
cargo test -p tap-proxy -p tap-bot -p tap-cli --lib --bins -- --test-threads=1
Related MCP servers

tech.interpretai/PostAgent
Print & mail PDF/HTML/Markdown/text/DOCX/images to US addresses; pay per call in x402 USDC on Base.
Issue tracker and wiki for teams and their agents: find, file and update issues, write pages.

tech.kasabeh/baton
Convert coding-agent sessions between Claude Code, OpenCode, Codex, and 6+ others—keep context and continue mid-task.
European-first forecasts, fundamental screening, and historical market cap.
Search transcripts and summaries of your meetings, calls, and recordings in Memo AI