Bastion MCP server
Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
6 stars45 downloads/wk
Reviews
Write oneNobody has reviewed Bastion yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Bastion tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it
- Code scan6 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 1 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
What the publisher says
From the Bastion repository's README, as published. We do not edit it. Read it on GitHub
🛡️ mcp-bastion
A reliability & security proxy for the Model Context Protocol (MCP).
Self-healing connections, runtime tool-security, and a compliance-mapped audit trail for your MCP servers.
-2ea44f>)
mcp-bastion sits between your MCP client (Claude Code, Cursor, Cline, Windsurf, Zed, Claude Desktop, or any MCP-compliant agent) and your MCP servers. It is client-agnostic — it works with any compliant client through configuration alone, with zero client-specific code — and non-invasive: your servers run unchanged, and removing Bastion is a one-line config revert.
📦 Package: mcp-bastion on npm · 🗂️ Official MCP Registry: io.github.Gowthaman90/mcp-bastion
🔒 Security, measured: on the open, vendor-neutral mcp-defense-bench, Bastion covers 63% of the MCP attack surface (15.0/24 vectors; 11 enforced) at zero false positives — the broadest of the proxies measured.
📖 Launch story: Medium · dev.to
👤 Created & maintained by Gowthaman Arumugam — Independent Researcher. Companion benchmark: mcp-defense-bench.
Contents
- Why
- How it works
- Features
- Quick start
- Demo
- Control tools
- Configuration
- Transports
- Runtime security
- Audit & compliance
- Client setup
- Architecture
Why
When an MCP server disconnects mid-session, the agent only sees a generic "No such tool available" error — indistinguishable from a tool that never existed — and it cannot reconnect; only a human can. Long agent sessions silently lose capabilities and fail in confusing ways.
Bastion closes that gap. It health-checks every server, auto-reconnects with backoff, and — crucially — exposes control tools so the agent itself can inspect connection health and recover a dropped server without human intervention.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y mcp-bastion on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mcp-bastion -- npx -y mcp-bastion
Bastion: common questions
- Is Bastion MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the Bastion safety report
- How do I install Bastion?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Bastion need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Bastion maintained?
- The last commit was in the last day (2026-09-24). The latest release is v0.6.1.
- What can I use instead of Bastion?
- Servers from other publishers that do the same job: MCPProxy MCP server, npm Registry MCP Server and prodlint MCP server. Compare all Bastion alternatives.
Alternatives to Bastion
Same job from other publishers: the closest match first, then the best rated.
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- prodlintProduction readiness for vibe-coded apps. 52 checks for security, reliability, and performance.not reviewedGrowingA
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
- GuardvibeDeterministic security layer your AI can't be. 479 rules, 39 tools, CLI + doctor + host audit.not reviewedGrowingC