For AI agents & their operators

Chainsaw speaks MCP. Pick the mode before you pick the key.

Mode A sets up the proxy; Mode B manages policy. The CLI and decision engine are open source at github.com/chain305/chainsaw-core.

Step 1 · Route the user

Match the user to a mode

If you can't tell which mode they need, ask.

PersonaThey'll sayRoute to
End-user developer end_user_dev “set up chainsaw for python” Mode A · client-setup, onboard with skip=true
AppSec appsec “draft a CVSS policy” Mode B · manage-propose
DevSecOps / Platform devsecops “add proxy to GitHub Actions” Mode A · client-setup
Enterprise IT enterprise_it “export SBOM” Mode B · manage-readonly

Pass skip=true to chainsaw_onboard to silence the persona nudge.

Step 2 · Pick the mode

Two workflows, two key presets

ModePresetScopesToolsKey
Mode AConfigure my project to install through Chainsaw client-setup repos:read list_my_repositoriesget_install_snippetsetup_doctor Mint a client-setup key
Mode BManage Chainsaw: policies, audit, SBOMs manage-readonly / manage-propose policies:readpolicies:manage*audit:readpackages:read list_policiespropose_policyget_audit_logcheck_vulnerabilitiesget_package_info Mint a manage-readonly key

Mode A routes npm, pip or docker installs through the proxy: the human mints the client_credential, and the agent edits config files and never holds it. In Mode B, manage-propose drafts go through Billy's human approval by default.

Step 3 · Connect

Point your MCP client at Chainsaw

  1. 01 · Discover

    /.well-known/mcp.json
  2. 02 · Authenticate

    POST /api/auth/cli/device

    Device code. Never POST /api/login.

  3. 03 · First call

    chainsaw_introduce

    Its response is the source of truth, not this page.

{
  "mcpServers": {
    "chainsaw": {
      "type": "streamable-http",
      "url": "https://chain305.com/chainproxy/mcp",
      "headers": { "Authorization": "Bearer <TOKEN>" }
    }
  }
}

Security model

What stops an agent over-reaching

  1. 01 · Proposed

    A human or an AI agent

    Dashboard, or MCP with the manage-propose key

  2. 02 · Billy queue

    • the diff
    • blast radius, last 7 days
    • routed to the rule's owner
  3. 03 · Owner signs off

    Inside the SLA

    Unacknowledged requests escalate

  4. 04 · Enforced

    Live on the proxy

    Every transition writes a signed audit row

Self-approval refused. An agent's proposal goes through the same queue as a human's, under the same RBAC.

Least-privilege presetsclient-setup can't read audit data or touch policy. manage-readonly can't mutate.
Per-agent tokensEach agent gets its own revocable token, attributed in the audit log.
Drift checkchainsaw doctor verify-hook catches client-side bypasses.

Building against Chainsaw?

Start with the MCP discovery files

Fetch /llms.txt and /.well-known/mcp.json first. Everything else chains off those.