PolicyLayer Registry

by Unknown

Not rated
Website

About

Check any MCP server's identity, risk grade and tool classifications before installing it.

Details

Author
Unknown
Categories
Developer Tools, Security, Infrastructure

Connect your agent to the registry itself. Before it installs or allows any MCP server, it asks one question:is this safe?It gets back the published record: verified identity with the evidence, risk grade, auth posture and every tool's classification. The registry tracks 44,603 servers and 362,000 classified tools, kept current by continuous scanning. Single-server lookups are free.

ENDPOINThttps://api.policylayer.com/mcpStreamable HTTP · no key needed for lookups

claude mcp add --transport http policylayer https://api.policylayer.com/mcp
Settings → Connectors → Add custom connector URL: https://api.policylayer.com/mcp
{ "mcpServers": { "policylayer": { "url": "https://api.policylayer.com/mcp" } } }
--header "Authorization: Bearer plr_..."

In Cursor / Windsurf / VS Code, add inside "policylayer":

"headers": { "Authorization": "Bearer plr_..." }

Claude desktop/web connectors can't send headers; free lookups only.

Then tell your agent:“check any MCP server against PolicyLayer before installing it.”Add it to your team's agent instructions and every install gets vetted.

check_mcp_serverFull record for one server: identity + evidence, risk grade, posture, tools riskiest-first. Unknown servers are queued for scanning by the lookup itself. FREE

search_registryFind published servers by name, slug or package substring, with grade and verification on every match. FREE

check_toolOne tool's full classification: risk analysis and evidence, OWASP classes, parameters, recommended policy default. FREE

get_change_eventsThe ordered change feed: drift, posture flips, impostor flags. Cursor-based, severity filters. LICENCE

Everything about asingleserver is free and complete: the full record, every tool, the whole classification. A licence adds breadth across the catalogue: thechange feedhere, plus bulk snapshots, keyset paging and webhooks on the/v1 API. Keys are self-serve on thelicensing page.

The moment a server is about to enter your stack is the moment its record matters. Your agent checks identity, posture and tool intelligence across every tracked server without leaving the conversation.

check_toolanswers the narrower question: shouldthistool onthisserver be allowed? It returns the classification, the evidence and a recommended policy default your agent can apply.

Look up a server we don't know and the lookup itself queues it for identity resolution and a priority scan. Ask again shortly and the record is there.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

Official managed MCP server for the Cycode platform. Exposes projects, violations, compliance frameworks, audit logs, brokers, SBOM, and more via OAuth-authenticated remote access — no local install required.

Compliance-as-Code framework that automatically enforces GDPR, OWASP, NIST, and CIS engineering standards.

Performs a Trivy scan to produce a Software Bill of Materials (SBOM) in CycloneDX format.

An MCP server for interacting with the Tenable Nessus vulnerability scanner.

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

Provides SD Elements API integration for security and compliance management.

AISG MCP Gateway — a security & DLP proxy for the Model Context Protocol. Aggregates your MCP servers behind one endpoint and enforces policy on every tool call

Cloud security insights, guardrail guidance, and compliance checking via Dawnguard.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.