Zero Day Room
Live
Incidents

Stacklok releases open-source ToolHive for secure MCP server

Stacklok has released ToolHive, an open-source platform for securely running Model Context Protocol servers inside isolated containers.

Stacklok has released ToolHive, an open-source platform for securely running Model Context Protocol servers inside...

Stacklok has launched ToolHive, an open-source platform designed to run Model Context Protocol servers inside secure containers. The tool, available under the Apache 2.0 license, provides a runtime, a Kubernetes operator, and a registry at no cost for self-hosting.

An MCP server acts as a connector, allowing AI clients like Cursor or Claude Code to access external tools. A manually installed server typically operates with the host machine's full credentials and network permissions. ToolHive addresses this by placing each server into its own container with a minimal permission file and no attached local credentials. The platform can be configured to enforce identity and access policies per request and generate audit logs when pointed at an authentication source. Without this configuration, it primarily functions as a sandbox.

Platform components

ToolHive consists of four main components. The Runtime is the core component that executes MCP servers in containers. It supports local deployment via Docker or Podman and cluster deployment through a Kubernetes operator. It applies permissions, network filtering, and secrets management. The Runtime can also containerize servers that were not originally shipped as images, pulling them directly from a package manager.

The Registry Server allows administrators to curate a catalog of approved servers for their team. It implements the official MCP Registry API, handles server signing, and verifies provenance. The Gateway, referred to by Stacklok as the Virtual MCP Server, consolidates multiple backend servers behind a single endpoint. It integrates features like OIDC or OAuth single sign-on, OpenTelemetry traces, and Prometheus metrics. The Portal serves as the user interface, offering a desktop application with a browsable catalog and one-click installations.

One component is undergoing change. The browser-based cloud user interface has been marked as retired. Stacklok advises building deployment strategies around the desktop application and command-line interface instead of the web interface.

Operational security focus

Building an MCP server is described as the easy part, with many existing tools available for the task. The operational challenge lies in managing which servers are running, where they are located, and what resources they can access. ToolHive specifically targets this operational security gap.

The container boundary provides isolation with minimal user configuration. However, implementing advanced features like identity enforcement, audit trails, and policy filtering requires integrating ToolHive with an existing identity provider and telemetry stack. Installing the tool on a laptop provides basic isolation, but establishing full governance is a separate undertaking.

ToolHive is available for free on GitHub.

Related coverage

More from Incidents