Govern Claude Desktop's MCP tools with DVARA
Claude Desktop can call any MCP server you add to it. Out of the box, nothing sits in between: whatever a tool can do, Claude can ask it to do.
Put DVARA in between and Claude Desktop sees one MCP server, DVARA. DVARA passes each tool call on only if your workspace's policy allows it. It redacts personal data in results and records every call.
What you need
- A DVARA MCP Gateway with at least one MCP server behind it. The
MCP quickstart gives you one in
about five minutes. It runs at
http://localhost:8080/mcp, and its API key isDEMO_API_KEYin the quickstart's.env. - A DVARA workspace API key.
- Node.js, for
npx.
Claude Desktop starts MCP servers as local commands, so it can't send an API key
to a remote server by itself. The open-source
mcp-remote bridge does that: Claude
Desktop starts it, and it forwards every message to DVARA with your key.
Add DVARA to Claude Desktop
Open Claude Desktop's config file. In Claude Desktop, go to Settings → Developer → Edit Config, or open it directly:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
Add DVARA under mcpServers. Replace <your-api-key> with your DVARA key:
{
"mcpServers": {
"dvara": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"http://localhost:8080/mcp",
"--header",
"Authorization:${AUTH_HEADER}"
],
"env": {
"AUTH_HEADER": "Bearer <your-api-key>"
}
}
}
}
The key sits in env rather than in args on purpose: some systems split an
argument at its spaces, which would break Bearer <key>.
Save the file and restart Claude Desktop.
Use its https:// address in place of http://localhost:8080/mcp. mcp-remote
only accepts plain http:// for localhost. On a private network you trust, add
"--allow-http" to args to use http:// anyway.
Try it
DVARA lists each server's tools with the server's id in front, so the quickstart's
tools appear as demo-tools__get_order_status, demo-tools__lookup_customer
and demo-tools__delete_customer.
Ask Claude:
Look up customer C-42, then delete them.
With the quickstart's policy, Claude gets the customer record back with the email, phone number and card number redacted:
Customer C-42: Jane Doe, [REDACTED_EMAIL], [REDACTED_PHONE_NUMBER],
card on file [REDACTED_CREDIT_CARD], plan Enterprise.
The delete is refused before it reaches the MCP server, with the policy's message:
delete_customer is irreversible and not allowed in this workspace
Both calls are in Flightdeck under MCP → Tool Calls.
Govern your own MCP servers
Add each MCP server to DVARA instead of to Claude Desktop, and keep only the
dvara entry in Claude Desktop's config. Then:
- Write the rules for what Claude may call in your workspace's policy. See Policy as Code.
- Turn on PII redaction for tool results. See PII detection.
- Hold a sensitive tool call until a person approves it. See the MCP Gateway.
Where to go next
- MCP Gateway for everything DVARA does to a tool call.
- Other MCP clients: Cursor, Claude Code, Spring AI, LangGraph.