Emisar MCP Server

Leave the agent working. Keep production authority bounded. emisar gives MCP-capable agents a catalog of declared infrastructure actions instead of a shell. Policy decides what runs, what waits for a person, and what is denied. A small outbound-only runner checks the action again on the host before it executes anything. It is available as a remote MCP endpoint.

Teams that want a hosted security endpoint instead of running a local process. The project is written in Elixir.

VERIFIED ACTIVE

LAST COMMIT 2026-08-23 · ★ 409 · #53 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25

NOASSERTION · Elixir · how we verify → /methodology

01 · Install Emisar

Claude Code

claude mcp add andrewdryga-emisar --transport http https://emisar.dev/api/mcp/rpc

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "andrewdryga-emisar": {
      "url": "https://emisar.dev/api/mcp/rpc"
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

https://emisar.dev/api/mcp/rpc

transport: streamable-http

endpoint alive - authentication required · probed 2026-08-25

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as remote - your agent's requests go to emisar.dev

endpoint auth requires authentication - rejected our unauthenticated MCP initialize

license no standard license detected - usage rights unclear; check the repo before commercial use

registry vendor namespace dev.emisar - domain-verified with the official MCP registry

03 · What Emisar can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

runner-v0.22.0 · 2026-08-23

Container image (linux/amd64, linux/arm64 - signed provenance + SBOM): · ghcr.io/andrewdryga/emisar-runner:0.22.0@sha256:3919eb4c39734346de7abd5f9c523a544dadfbc31c4f031451585a7f1a439b51

mcp-v0.10.0 · 2026-08-23

runner-v0.21.0 · 2026-08-21

Container image (linux/amd64, linux/arm64 - signed provenance + SBOM): · ghcr.io/andrewdryga/emisar-runner:0.21.0@sha256:37ebec82cf132288c3bd2d4794b501ba9e1a5bfaf899970d8ac83ae7bbb54760

04 · Who maintains Emisar

emisar is maintained by andrewdryga. It's the only MCP server we track from this author; the repo dates to May 2026.

05 · Facts

category
security - ranked #53 of 182 actively-maintained security servers as of 2026-08-25.
release cadence
10+ releases in the last 90 days (latest 2026-08-23)
registry
dev.emisar/emisar (active, first published 2026-07-12 · 21 versions)

06 · Emisar FAQ

What is Emisar?

Leave the agent working. Keep production authority bounded. emisar gives MCP-capable agents a catalog of declared infrastructure actions instead of a shell. Policy decides what runs, what waits for a person, and what is denied. A small outbound-only runner checks the action again on the host before it executes anything. It is available as a remote MCP endpoint.

Is Emisar still maintained?

Yes - as of 2026-08-25, its last commit was 2026-08-23 and it shipped 10+ releases in the last 90 days. We re-verify nightly.

How do I install Emisar?

Run `claude mcp add andrewdryga-emisar --transport http https://emisar.dev/api/mcp/rpc`. You can also paste the ready-made client config above.

Does Emisar require authentication?

Yes - when we probed the endpoint on 2026-08-25, it rejected an unauthenticated MCP initialize; you'll need credentials to connect.

07 · Alternatives to Emisar

More security MCP servers · Apiiro Guardian Agent · Pihole · Threatintel · Apocdata MCP Server · Niro