Highlights
Profiles now enforce policy (Spec 108). A profile can cap the tool tier (max_tier: read / write / destructive), allow or deny individual tools with server:tool globs, decide how unannotated tools are treated, and switch off code_execution or the management tools. This is enforced on every execution surface (call_tool_*, /mcp/all, nested code_execution calls, REST) and in discovery: retrieve_tools filters by policy before it cuts to the limit, and it reports hidden_by_profile. The same access explainer is available in the Web UI, the macOS app, mcpproxy access explain and the new profiles MCP tool. → Profiles
A credential per client. Connect no longer writes the admin API key into client configs. Each client gets an mcp_cli_ credential bound to a profile, valid on MCP endpoints only. Rotate or forget it per client from the new Clients hub. Configs that still hold the admin key are reported, never rewritten automatically: use Upgrade clients holding the admin key, then rotate the key. → Connect Clients
Agents find their tools (#1486).
/mcp,/mcp/calland/mcp/codenow actually send initialize instructions.- Each caller's instructions end with a YOUR ACCESS block: its profile, the connected servers it can reach, and its allowed operations, all filtered by profile and agent-token scope.
- The
retrieve_toolsdescription names those servers, so Claude Code's tool search finds it. - Opt out with
advertise_upstream_servers: false. mcpproxy agent-instructionsprints a CLAUDE.md / AGENTS.md snippet. → Agent Instructions
Navigation rebuilt around one list (Spec 109).
- One needs-attention list across Home, tray,
statusanddoctor. - A Review queue that starts fail-closed.
- Catalog-first Add Server with a real popularity signal (Spec 110).
- Clients hub, grouped sidebar and command palette (Cmd/Ctrl+K).
- Deep-linkable Activity filters.
- One status vocabulary on every surface.
Security and reliability fixes
- Upgrade keeps quarantined servers quarantined (#1485, #1488). v0.69 restarts could overwrite a held server's recorded quarantine, and the upgrade then auto-approved all of its tools. A server is now admitted on upgrade only with an approval baseline. Implicit quarantine also survives restarts and config writes (#1463), and an explicit
quarantinedvalue given on add or import is persisted. - Dead stdio servers come back (#1489). A stdio upstream whose process died used to keep reporting healthy while every call failed. Now it is marked unhealthy at once and respawned.
- A malformed import no longer bricks startup (#1490). An entry the boot path would refuse is rejected at import time.
- Open-object schemas survive (#1434, #1438).
call_tool_*arguments and/mcp/alltools keepadditionalPropertiesand$defs. Grammar-constrained local models read{"properties":{}}as "no arguments". - Client header forwarding to upstreams (Spec 112), and a versioned search index with automatic migration (#1386).
Upgrade notes
- Downgrading: set
require_mcp_auth: truebefore going back to v0.69 or earlier. Older binaries don't knowmcp_cli_credentials, and with MCP auth off they grant them unconfined access. - Vetted servers with no approved tools (prompt/resource-only servers, servers not connected since v0.21) are held for review once. Approve them, or set
"quarantined": falsebefore upgrading. - CLI tables changed for
upstream list,statusanddoctor.-o jsonis unchanged; scripts should use it. describe_toolreportsnot_foundinstead ofinvisiblefor tools outside your scope.- Profile refusals now name the caller's own profile. Match on
block_reason(profile_tier,profile_rule,profile_unannotated) rather than the text.
Full write-up: MCPProxy v0.70.0 on the blog. Changes since v0.69.0: v0.69.0...v0.70.0.
Download Installers
| Platform | Download | Notes |
|---|---|---|
| macOS (Apple Silicon) | Download DMG | Signed & Notarized - Recommended for M1/M2/M3/M4 |
| macOS (Intel) | Download DMG | Signed & Notarized |
| Windows (64-bit) | Download Setup | Setup wizard |
| Windows (ARM64) | Download Setup | For ARM Windows devices |
| Linux Debian/Ubuntu (AMD64) | Download .deb | sudo apt install ./mcpproxy_*.deb
|
| Linux Debian/Ubuntu (ARM64) | Download .deb | For ARM64 (Raspberry Pi etc.) |
| Linux Fedora/RHEL (AMD64) | Download .rpm | sudo dnf install ./mcpproxy-*.rpm
|
| Linux Fedora/RHEL (ARM64) | Download .rpm | For ARM64 |
| Linux (AMD64) — tarball | Download tar.gz | Binary only |
| Linux (ARM64) — tarball | Download tar.gz | Binary only |
Homebrew (macOS/Linux):
brew install smart-mcp-proxy/mcpproxy/mcpproxy