Definitions · M · Runtime enforcement
MCP proxy
The Blekline MCP proxy sits between an agent client and downstream MCP servers — evaluating tool calls against workspace policy before execution. It is the primary governance surface for Cursor, Claude Code, and Codex integrators.
The Blekline MCP proxy (blekline-proxy) governs downstream MCP tool calls after the primary Blekline MCP server connects your client. It evaluates each tool invocation against workspace policy before forwarding to sandboxed or production MCP servers.
Responsibilities
- Tool allow/deny and argument scanning
- Metadata-only governance events (
blekline_log_governance_event) - Optional chaining: client → Blekline MCP → proxy → downstream server
In Blekline
- Configure from /operations/mcp and /docs/mcp/proxy.
- Track 01 eval path wires MCP before any sidecar deploy.
- Cursor hooks complement but do not replace proxy enforcement for tool egress.
Related terms
Used in
- Runtime enforcement
- Why Ingress
- Architecture
- Cursor
- Continue
- GitHub Copilot
- OpenHands
- Sourcegraph Cody
- MCP Server
- MCP Proxy
- Client QA Matrix
- Agent Clients
- Frameworks & RAG
- Azure OpenAI Stack
- AWS Bedrock Stack
- Google Vertex Stack
- OpenRouter Stack
- Together Stack
- Fireworks Stack
- Mistral Stack
- Cohere Stack
- Replicate Stack
- Qwen Stack
- LangChain Stack
- LlamaIndex Stack
- PydanticAI Stack
- TaskWeaver Stack
- Relevance AI Stack
- Supabase Stack
- Chroma Stack
- Pinecone Stack
- Contextual AI Stack
- LangSmith Stack
- Guardrails Stack
- Sandbox Providers
- Daytona Stack
- Modal Stack
- Vercel Sandbox Stack
- Cloudflare Stack
- E2B Stack
- Browser Extension
- Cursor Enterprise Governance
- Compliance evidence
- SSO & Deployment
- Latency SLO
- Trust Boundaries
- MCP Identity Pinning