AI agent governance: content scanning, audit logs, policy evaluation, session management.
Connect Bulwark to Claude, Cursor or any other MCP client and it stops being a tab you switch to. AI agent governance: content scanning, audit logs, policy evaluation, session management. The bulwark mcp server is what makes that connection.
Bulwark sits between AI agents and external tools, enforcing policies, managing credentials, inspecting content, and maintaining a complete audit trail. One policy governs all your agents — Claude Code, OpenClaw, Codex, or any MCP/HTTP client.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
MCP-native — Works as an MCP gateway or HTTP forward proxy. Governance metadata on every tool call responsename — githubMode — TransportConfiguration is passed through the environment: GITHUB_TOKEN, BULWARK_SESSION, GITHUB_PERSONAL_ACCESS_TOKEN. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.
Plenty of database access servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Bulwark's toolset — MCP-native, name, Mode — is a fair guide to whether it matches your workflow. It is maintained by bpolania; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| MCP-native | Works as an MCP gateway or HTTP forward proxy. Governance metadata on every tool call response |
| name | github |
| Mode | Transport |
| Variable | Description | Required |
|---|---|---|
| GITHUB_TOKEN | Credential the server authenticates with. | Yes |
| BULWARK_SESSION | Configuration value read at startup. | Optional |
| GITHUB_PERSONAL_ACCESS_TOKEN | Credential the server authenticates with. | Yes |
Read-only SQL access to Postgres — let your assistant inspect schemas and answer questions from real data.
Manage your whole Supabase project in conversation — database, auth, storage, Edge Functions and branches.
Query, modify and analyse local SQLite databases in conversation — the fastest way to chat with a data file.
Metabase ships its own MCP endpoint — search your BI content, build and run queries, and save questions and dashboards without leaving the chat.
Official MongoDB server covering data, schemas and Atlas management — from find queries to spinning up clusters.
Serverless Postgres with database branching — point your assistant at Neon and let it work on disposable copies.