For AI agents & their operators
Chainsaw speaks MCP. Pick the mode before you pick the key.
Mode A sets up the proxy; Mode B manages policy. The CLI and decision engine are open source at github.com/chain305/chainsaw-core.
Step 1 · Route the user
Match the user to a mode
If you can't tell which mode they need, ask.
| Persona | They'll say | Route to |
|---|---|---|
End-user developer end_user_dev | “set up chainsaw for python” | Mode A · client-setup, onboard with skip=true |
AppSec appsec | “draft a CVSS policy” | Mode B · manage-propose |
DevSecOps / Platform devsecops | “add proxy to GitHub Actions” | Mode A · client-setup |
Enterprise IT enterprise_it | “export SBOM” | Mode B · manage-readonly |
Pass skip=true to chainsaw_onboard to silence the persona nudge.
Step 2 · Pick the mode
Two workflows, two key presets
| Mode | Preset | Scopes | Tools | Key |
|---|---|---|---|---|
| Mode AConfigure my project to install through Chainsaw | client-setup | repos:read | list_my_repositoriesget_install_snippetsetup_doctor | Mint a client-setup key |
| Mode BManage Chainsaw: policies, audit, SBOMs | manage-readonly / manage-propose | policies:readpolicies:manage*audit:readpackages:read | list_policiespropose_policyget_audit_logcheck_vulnerabilitiesget_package_info | Mint a manage-readonly key |
Mode A routes npm, pip or docker installs through the proxy: the human mints the client_credential, and the agent edits config files and never holds it. In Mode B, manage-propose drafts go through Billy's human approval by default.
Step 3 · Connect
Point your MCP client at Chainsaw
-
01 · Discover
/.well-known/mcp.json -
02 · Authenticate
POST /api/auth/cli/deviceDevice code. Never POST /api/login.
-
03 · First call
chainsaw_introduceIts response is the source of truth, not this page.
{
"mcpServers": {
"chainsaw": {
"type": "streamable-http",
"url": "https://chain305.com/chainproxy/mcp",
"headers": { "Authorization": "Bearer <TOKEN>" }
}
}
} Security model
What stops an agent over-reaching
-
01 · Proposed
A human or an AI agent
Dashboard, or MCP with the
manage-proposekey -
02 · Billy queue
- the diff
- blast radius, last 7 days
- routed to the rule's owner
-
03 · Owner signs off
Inside the SLA
Unacknowledged requests escalate
-
04 · Enforced
Live on the proxy
Every transition writes a signed audit row
Self-approval refused. An agent's proposal goes through the same queue as a human's, under the same RBAC.
| Least-privilege presets | client-setup can't read audit data or touch policy. manage-readonly can't mutate. |
|---|---|
| Per-agent tokens | Each agent gets its own revocable token, attributed in the audit log. |
| Drift check | chainsaw doctor verify-hook catches client-side bypasses. |
Building against Chainsaw?
Start with the MCP discovery files
Fetch /llms.txt and /.well-known/mcp.json first. Everything else chains off those.