kosa8 docs

Commands / kosa8 mcp-policy

kosa8 mcp-policy

Govern which MCP servers and tools each team may use

An org signs a policy of scopes — "engineering", "data-science" — each listing the MCP servers it may reach and, within a server, which tools.

A server nobody approved is denied: the approved set is a list, not a denylist of things someone thought to forbid. Tool names take wildcards ("read_*"); server names never do, because one pattern would re-approve everything. Deny beats allow.

The policy is signed with the same key as kosa8 policy and verified against the same pinned signer, so editing it locally breaks it — and a broken policy denies everything rather than falling back to open.

Subcommands