Pangea MCP Proxy MCP Server

Protect any MCP server from malicious entities and confidential PII.

Local serverstdio

What is the Pangea MCP Proxy MCP server?

If you already use Pangea MCP Proxy, the pangea mcp proxy mcp server is the piece that lets your assistant work with it directly. Protect any MCP server from malicious entities and confidential PII.

What the server does

Protect communications between a client and any MCP server. Now with 99% less prompt injection! The Pangea MCP proxy allows any MCP client to secure the messages it sends and receives to/from an MCP server, using the [Pangea AI Guard][] service to guard tools' inputs and outputs.

Credentials and setup notes

Configuration is passed through the environment: PANGEA_VAULT_TOKEN, PANGEA_VAULT_ITEM_ID. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

  • Node.js v22.15.0 or greater. - A Pangea API token with access to AI Guard. This token needs to be stored in Pangea Vault. See [Service Tokens][] for documentation on how to create and manage Pangea API tokens. - A Pangea API token with access to Vault. This will be used to fetch the above token at runtime.

Installation

Installation goes through your MCP client rather than a global install: point it at @pangeacyber/mcp-proxy on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

Where it fits

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. It is maintained by pangeacyber; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

How to install the Pangea MCP Proxy MCP server

{
  "mcpServers": {
    "qrcode": {
      "command": "npx",
      "args": ["-y", "@jwalsh/mcp-server-qrcode"]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

  • Node.js v22.15.0 or greater. - A Pangea API token with access to AI Guard. This token needs to be stored in Pangea Vault. See [Service Tokens][] for documentation on how to create and manage Pangea API tokens. - A Pangea API token with access to Vault. This will be used to fetch the above token at runtime.
VariableDescriptionRequired
PANGEA_VAULT_TOKENCredential the server authenticates with.Yes
PANGEA_VAULT_ITEM_IDConfiguration value read at startup.Optional

Frequently asked questions

It connects Pangea MCP Proxy to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Pangea MCP Proxy directly.