Skip to content
MoorAI
// blog · buyer’s guide

How MoorAI protects AI apps and APIs

An AI service acts in three places: it calls its model API, it runs tools, and it calls MCP servers that someone else operates. MoorAI v1.4 puts a check at each of those points, in your own environment, and sends only content-free signals out of it.

MoorAI v1.4 diagram with an AI agent or AI app in the middle. To the left, its requests to an Anthropic or OpenAI model API pass through the MoorAI model proxy, which is report-only by default and refuses denied requests in enforce mode. To the right, its MCP tool calls pass through the MoorAI MCP gateway: an allowed call is forwarded to the remote MCP server, and a denied call is stopped at the gateway and never reaches the server. Below, the app asks the moorai-serve sidecar on 127.0.0.1:8790 whether to allow a call and gets allow or deny back. A strip lists the real MCP clients tested: Claude Code, Cursor CLI, MCP SDK and MCP Inspector. MoorAI v1.4 AI security at the point. LLM API Anthropic · OpenAI MOORAI Model proxy moorai-model-proxy checks what your agent sends to the LLM >_ AI agent or AI app MOORAI MCP gateway moorai-mcp-gateway checks every tool call MCP servers remote, over HTTP allowed call: forwarded denied call never reached the server Report-only by default. Enforce mode refuses denied requests. allow this call? allow / deny MOORAI Sidecar decision API moorai-serve · 127.0.0.1:8790 your app asks before a tool runs TESTED WITH REAL MCP CLIENTS Claude Code·Cursor CLI·MCP SDK·MCP Inspector Open source · MIT · moorai.dev MoorAI

MoorAI runs inside coding agents on developers’ laptops. The same engine runs in front of AI apps and APIs: as a decision API your code calls before a tool runs, as a hook inside an Agent SDK service, as a gateway in front of remote MCP servers, and as a proxy between an agent and its model API. This guide covers where each check sits, what it does, how to keep it out of the agent’s reach, and what has been tested with real clients.

Where the check happens

Each component runs next to the workload it protects. All of them are in the MoorAI agent, which is open source under MIT; the current release is v1.4.1.

Where the AI actsMoorAI componentWhat it checks
Any agent framework, before a tool runsmoorai-serve sidecarThe tool call your code asks about. A localhost HTTP decision API on 127.0.0.1:8790 answers allow or deny.
A service built on the Agent SDK@moorai/agent-sdkEvery tool call, inside your service’s own process.
Remote MCP serversmoorai-mcp-gatewayEvery MCP message between the agent and the server, including each tool call and each streamed event.
The model APImoorai-model-proxyWhat the agent sends to the model and the tool calls that come back, on 127.0.0.1:8791, for Anthropic and OpenAI routes.
Coding agentsHooksTool calls and prompts in Claude Code, Codex, Copilot CLI, Cursor and Gemini CLI.

Which one you need

They combine. A service can call the sidecar for its own tools, reach its MCP servers through the gateway and its model through the proxy.

The sidecar: a decision API for any framework

moorai-serve is a localhost HTTP decision API on 127.0.0.1:8790. Before your code runs a tool, it sends the call to the sidecar and gets back the decision MoorAI’s hook would make for that call. Your code does what the answer says. Any language or framework that can make a local HTTP request can use it.

Run it in the agent’s pod or compose network, so the agent reaches it on loopback and no port is opened to the outside. The quick start’s Run it as a sidecar section has the command, the endpoints and the compose and Kubernetes examples.

The Agent SDK hook: in process

For a service built on the Agent SDK, @moorai/agent-sdk registers MoorAI’s hooks inside your service’s own process. The check runs in your code path before each tool call. The model doesn’t decide whether it is consulted.

The MCP gateway: in front of remote MCP servers

moorai-mcp-gateway is an HTTP MCP guard. The agent connects to the gateway, and the gateway connects to the remote server. Every message passes through these checks:

A tool call that policy denies is refused at the gateway and doesn’t reach the server. The gateway has run in front of a real remote MCP server, an AppCrane MCP endpoint with 62 tools. For the wider question of trusting MCP servers you don’t run, see MCP security.

The model proxy: between the agent and its model API

moorai-model-proxy listens on 127.0.0.1:8791 and serves Anthropic and OpenAI routes. The agent sends its model requests to the proxy, and the proxy forwards them to the provider.

The proxy has been tested against a fake provider. It hasn’t yet been run with the providers’ own SDKs or against a real provider, which is why report-only is the place to start.

Keep them out of the agent’s reach

A guardrail the agent can edit isn’t a guardrail. The container image ghcr.io/gitayg/moorai-server holds all three server commands (moorai-serve, moorai-mcp-gateway and moorai-model-proxy), for amd64 and arm64, and runs as a non-root user (uid 1000). Run them in their own container and the agent process can’t edit their policy or files.

Routing is the other half. When your network policy forces the workload’s model and MCP traffic through the proxy and the gateway, the agent can’t route around them. MoorAI doesn’t set that up for you: the restriction is your own network policy.

For coding agents on servers and in CI, MoorAI’s hooks sit in Claude Code’s system-wide managed settings, which a repository can’t switch off. On a laptop the hook runs as the developer, so disabling it is detected, not prevented: an enrolled device sends a daily coverage heartbeat, and the console raises “agent active, no MoorAI hook traffic”. The full breakdown of what is prevented, what is detected and what is out of scope is in tamper resistance and the FAQ.

What leaves your environment

Prompts, code, files and secrets are checked where the agent runs. They aren’t sent anywhere to be checked. The console receives content-free signals about what fired, not the content that fired it. Trust lists what leaves and what stays.

What was tested

On 2026-10-06, on macOS, four real MCP clients ran through MoorAI’s stdio MCP proxy and its HTTP gateway, in front of a test MCP server:

Not tested yet

Claude Desktop, VS Code and the Cursor desktop app. Windows and Linux for these real-client runs. OAuth through the gateway. A live, model-driven denied call through the gateway. The model proxy with the providers’ own SDKs or a real provider: it has been tested against a fake provider only.

Questions to ask of any guardrail

Whichever product sits in front of your AI app, these questions separate a check from a log line:


MoorAI is open-source (MIT) runtime guardrails for AI agents, apps and APIs. See also: Run it as a sidecar, MCP security, and The layer above the model.

AI security at the point.
Runtime guardrails for AI agents, apps and APIs. Open source under MIT; checks run where the agent runs, and the console gets content-free signals.
Run it as a sidecar → See MoorAI