ValGuard + MCP: LLM path and tool gates

Route MCP host model calls through ValGuard. Tool side effects still need explicit gates — see the MCP security guide.

Last verified:

Model Context Protocol hosts call models and tools. ValGuard covers LLM completions on the OpenAI-compatible path. MCP tool calls that trigger side effects need explicit gates — ValGuard does not sit inside every MCP server automatically.

When you need this

An MCP host lets a model invoke refund_customer. The LLM proposes arguments; a tool runs. Validate the model JSON on the ValGuard path, then enforce tool policy in your host or a dedicated tool gate. See MCP security.

Setup (LLM path)

  1. Point the MCP host's OpenAI-compatible client at https://api.valguard.ai/v1.
  2. Set X-VG-Agent per workflow.
  3. Shadow, then enforce on model output before tool selection.

Setup (tool path)

  1. Review server permissions and scopes.
  2. Run deterministic checks on tool arguments before execution (P-tool-gate in the guide).
  3. Log rule IDs alongside MCP trace IDs.

Code (LLM)

import os
from openai import OpenAI

client = OpenAI(
    base_url="https://api.valguard.ai/v1",
    api_key=os.environ["VG_API_KEY"],
    default_headers={"X-VG-Agent": "mcp-host-planner"},
)

completion = client.chat.completions.create(
    model="openai/gpt-4o-mini",
    messages=[{"role": "user", "content": "Plan tool calls for ticket 991"}],
)

Honest limits

  • MCP transport security (TLS, auth) is your deployment.
  • ValGuard is not an MCP registry or permission broker.
  • Tools invoked without an LLM step are out of scope unless you add a gate.

Related

Next step

Read MCP security, then quickstart.