Marrow
Marrow gives your agent a governance loop that compounds. With @getmarrow/mcp, any MCP-compatible client can ask Marrow before risky work, inspect live loop state during work, collect required proof, and commit outcomes when the work is done. That means your agent stops operating without accountability and starts carrying forward real decision history. Your agent stops repeating the same mistake
README
@getmarrow/mcp
MCP-native runtime control, proof, and fleet intelligence for AI agents.
Marrow is the runtime control and proof layer for teams running AI agents. It applies policy and prior lessons before consequential actions, then records the evidence and outcome afterward.
Use @getmarrow/mcp when your agent client supports the Model Context Protocol and you want Marrow available inside the agent's normal workflow. It works with Claude Code, Claude Desktop, Cursor and other MCP-compatible clients without replacing the model or harness.
Install
npx @getmarrow/mcp setup
Set the key through trusted secret storage:
export MARROW_API_KEY=mrw_live_...
Then configure the MCP server:
{
"mcpServers": {
"marrow": {
"command": "npx",
"args": ["-y", "@getmarrow/mcp"]
}
}
}
For most new installations, start with the universal installer instead:
npx @getmarrow/install --yes
What's New in v3.9.43
v3.9.43 aligns the package entry point with Marrow's business product contract:
- runtime control before consequential actions;
- proof and outcome closure afterward;
- tenant-scoped fleet improvement across interchangeable agents and harnesses;
- context, lessons, and workflow examples presented as supporting controls rather than a separate memory product.
This patch changes package documentation and positioning. Existing MCP tool behavior and names remain compatible.
Governed Action Flow
Before deploys, merges, publishes, migrations, credential changes, financial operations, or customer-impacting work:
- Call
marrow_agent_runtimeormarrow_decision_brief. - Stop when the returned decision is
blockorreview_required; otherwise follow its prior lesson and proof contract. - Call
marrow_thinkto record intent and obtain thedecision_idthat will be closed. - Perform the action only when its gate allows it.
- Call
marrow_commitwith thatdecision_id, the outcome, gate receipt, and required proof.
Example pre-action request:
{
"tool": "marrow_agent_runtime",
"arguments": {
"action": "deploy the production worker",
"type": "deploy",
"role": "deploy",
"surfaces": ["repository", "deployment", "production"]
}
}
Example closeout:
{
"tool": "marrow_think",
"arguments": {
"action": "deploy the production worker",
"type": "process",
"checkLoop": true
}
}
{
"tool": "marrow_commit",
"arguments": {
"decision_id": "decision_id returned by marrow_think",
"gate_receipt_id": "receipt id returned by marrow_agent_runtime",
"success": true,
"outcome": "Production deploy succeeded and smoke checks passed.",
"proof": {
"checks": ["tests passed", "secret scan passed", "production smoke passed"],
"rollback_target": "previous release"
}
}
}
High-risk work can be allowed, warned, held for review, or blocked according to account policy. Low-risk work can use passive guidance and bounded cached state where the runtime contract permits it.
Passive Use
npx @getmarrow/mcp setup installs supported hooks so the agent can receive before-action context and record meaningful tool outcomes without the owner repeatedly prompting it to use Marrow.
Check the installed runtime:
marrow_agent_status
Status diagnostics distinguish missing keys, invalid keys, wrong bound-agent identity, network limits, missing hooks, and incomplete proof. They include an exact repair action without exposing secrets.
Primary MCP Tools
| Tool | Purpose |
|---|---|
marrow_agent_runtime |
One-call pre-action status, policy gate, relevant lessons, proof requirements, and exact next action |
marrow_decision_brief |
Compact operating brief for meaningful work |
marrow_think |
Record intent and retrieve relevant governance intelligence |
marrow_commit |
Close an action with outcome, receipt, and proof |
marrow_workflow_gate |
Evaluate a workflow action against policy |
marrow_completion_contracts |
List proof contracts for consequential action types |
marrow_evaluate_completion_contract |
Check whether evidence is sufficient to call work complete |
marrow_agent_status |
Verify capture, identity, outcome coverage, and hook health |
marrow_value_report |
Return account/agent value evidence without requiring a dashboard |
marrow_buyer_proof |
Return owner-ready governance and reliability evidence |
marrow_governance_timeline |
Inspect decisions, gates, proof packs, and outcomes over time |
marrow_fleet_lessons |
Retrieve proven lessons authorized for the current account or agent |
marrow_model_usage |
Record compact token, cost, and latency counts when the harness exposes them |
The package also exposes key management, fleet handoff, deployment history, adaptive policy, context/lesson, query, and workflow-example tools. See the complete source-of-truth documentation for every tool and field.
Context and Workflow Examples
The stable marrow_*memory* tools manage authorized context and prior lessons used by governance decisions. They are advanced supporting APIs, not a separate product category.
The template tools expose 24 configurable workflow examples. They are starting points for policy design, not customer case studies, regulatory validation, legal advice, or proof of production use in each listed industry.
Trust and Data Boundaries
- Private account, fleet, workflow, proof, and agent data remains tenant-scoped by default.
- Agent-bound keys can be restricted to an allowed identity and permission set.
- Sanitized aggregate contribution is optional and never means sharing raw prompts, code, secrets, proof packs, account identifiers, agent identifiers, or customer identities.
- Existing API keys are never returned after creation; key material should be supplied through the client's secret store.
- Marrow returns guidance and policy data. Agents must not execute returned text as shell input.
See the Trust Center for implemented controls, current limits, and roadmap status.
Environment
| Variable | Required | Purpose |
|---|---|---|
MARROW_API_KEY |
Yes | Account or agent-bound API key |
MARROW_BASE_URL |
No | API base override |
MARROW_AGENT_ID |
No | Bound agent identity for MCP tools |
MARROW_FLEET_AGENT_ID |
No | Fleet agent identity used by passive setup |
Documentation
License
MIT
Related Packages
- @getmarrow/install - default installer, self-test, governed runner, and operator TUI
- @getmarrow/sdk - Node.js and TypeScript integration for owned agent runtimes
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
Neon Database
MCP server for interacting with Neon Management API and databases
E2B
Using MCP to run code via e2b.
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.