# Jamjet

> The open-source safety layer for AI agents — block unsafe tool calls, require approval, enforce budgets, audit, replay.

- **Type:** MCP server
- **Install:** `agentstack add mcp-jamjet-labs-jamjet`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [jamjet-labs](https://agentstack.voostack.com/s/jamjet-labs)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [jamjet-labs](https://github.com/jamjet-labs)
- **Source:** https://github.com/jamjet-labs/jamjet
- **Website:** https://jamjet.dev

## Install

```sh
agentstack add mcp-jamjet-labs-jamjet
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

⚡ JamJet

**The action-control plane for AI agents.** One policy file. One audit trail. Across hooks, guardrails, MCP gateways, SDKs, and custom runtimes.

[](https://glama.ai/mcp/servers/jamjet-labs/jamjet)
[](https://github.com/jamjet-labs/jamjet/actions)
[](https://pypi.org/project/jamjet)
[](https://crates.io/crates/jamjet-engram)
[](LICENSE)
[](https://github.com/jamjet-labs/jamjet/stargazers)
[](https://rustup.rs)
[](https://python.org)
[](https://openjdk.org)
[](https://jamjet.dev/quickstart)
[](https://discord.gg/SAYnEj86fr)

[jamjet.dev](https://jamjet.dev) · [Quickstart](https://jamjet.dev/quickstart) · [Docs](https://jamjet.dev/concepts) · [Examples](https://jamjet.dev/examples) · [Blog](https://jamjet.dev/blog) · [Discord](https://discord.gg/SAYnEj86fr)

[](https://codespaces.new/jamjet-labs/jamjet?quickstart=1)
[](https://gitpod.io/#https://github.com/jamjet-labs/jamjet)

---

> *Write the safety policy once. Run it everywhere your agents can act.*

JamJet sits underneath your agent — Claude Code, OpenAI Agents SDK, MCP clients, LangChain, CrewAI, ADK, custom code — and enforces what prompts cannot:

- 🛡️ **Block unsafe tool calls** at runtime (database deletes, payments, file writes)
- ✋ **Pause for human approval** on risky actions, durably
- 💸 **Cap cost** per agent, per run, per project
- 📒 **Record an audit trail** that survives a regulator's review
- ⏪ **Replay or resume** crashed runs from the last checkpoint

**Keep your agent framework. Add JamJet where tool calls need control.**

## See it in 60 seconds

```bash
pip install jamjet
jamjet demo unsafe-tool-call
```

No API key. No Docker. No cloud account. The model is mocked; the enforcement path is real. Three more demos run the same way:

```bash
jamjet demo approval        # pause-for-approval flow
jamjet demo budget-cap      # $0.05 cost cap
jamjet demo mcp-tool-policy # MCP-shaped policy (preview of JamJet Gateway)
```

Works alongside **Claude Code · OpenAI Agents SDK · MCP clients · LangChain · CrewAI · ADK · Spring AI · LangChain4j**.

## The same policy, everywhere

Every agent toolchain is inventing its own safety layer. JamJet gives you one policy file and one audit trail across all of them.

| Adapter | Install | Host |
|---|---|---|
| [`@jamjet/claude-code-hook`](https://npmjs.com/package/@jamjet/claude-code-hook) | `npm i -g @jamjet/claude-code-hook` | [Claude Code](https://docs.claude.com/en/docs/claude-code/hooks) PreToolUse hook |
| [`@jamjet/mcp-shim`](https://npmjs.com/package/@jamjet/mcp-shim) | `npx -y @jamjet/mcp-shim ...` | Any [MCP](https://modelcontextprotocol.io) client (Claude Desktop, Cursor, …) |
| [`@jamjet/openai-guardrail`](https://npmjs.com/package/@jamjet/openai-guardrail) | `npm i @jamjet/openai-guardrail` | [OpenAI Agents SDK](https://github.com/openai/openai-agents-js) tool guardrail (TS) |
| [`jamjet.integrations.openai_guardrail`](https://pypi.org/project/jamjet/) | `pip install jamjet` | [OpenAI Agents SDK](https://github.com/openai/openai-agents-python) tool guardrail (Python) |
| [`jamjet`](https://pypi.org/project/jamjet/) | `pip install jamjet` | Python SDK + runtime |
| [`@jamjet/cloud`](https://npmjs.com/package/@jamjet/cloud) | `npm i @jamjet/cloud` | TypeScript SDK + shared engine |
| [`@jamjet/cli`](https://npmjs.com/package/@jamjet/cli) | `npm i -g @jamjet/cli` | Unified `jamjet audit show` / `jamjet approve` |

All adapters load the same `policy.yaml`. All emit conformant audit JSONL to `~/.jamjet/audit/`. Run `jamjet audit show` to tail every decision across every adapter in one chronological view.

**Respect the platforms you plug into.** Claude Code gave developers a hook point — JamJet gives that hook point a real policy engine, approval flow, and audit trail, and the same rules carry to OpenAI Agents SDK, MCP, and your own Python/TS code. OpenAI Agents SDK has guardrails — JamJet lets you express the policy once and reuse it elsewhere. If your MCP gateway supports plugins, JamJet can be the policy brain; if not, the `@jamjet/mcp-shim` proxy fills the gap.

### One policy, every adapter

```yaml
# ~/.jamjet/policy.yaml
version: 1
rules:
  - { match: "*delete*", action: block }
  - { match: "payments.*", action: require_approval }
  - { match: "shell.exec", action: block }
```

Drop this file in `~/.jamjet/`. Every adapter listed above uses it automatically.

> Prompts are not a security boundary. The runtime is.

→ Read **[When AI Deletes the Database](https://jamjet.dev/blog/when-ai-deletes-the-database/)** for why this is a runtime architecture problem, not a model problem.
→ See the deeper **[durability demo at jamjet.dev/demo](https://jamjet.dev/demo)** for what happens when an agent crashes mid-tool-call.

## Policy in your own code

Drop a policy beside your agent code. The runtime intercepts any matching tool call *before* it leaves the agent's process — `blocked_tools` are refused outright, `require_approval_for` pauses execution durably and waits for an out-of-band decision (crashes don't lose the approval; execution resumes when it arrives).

```yaml
# workflow.yaml
policy:
  blocked_tools:
    - "*delete*"
    - "payments.refund"
  require_approval_for:
    - "database.*"
    - "payment.transfer"
    - "user.suspend"
```

**Python, with the hosted control plane:**

```python
import jamjet
jamjet.cloud.configure(api_key="jj_...", project="my-agent")
jamjet.cloud.policy("block", "*delete*")
jamjet.cloud.policy("require_approval", "database.*")
# Every OpenAI / Anthropic call in this process is now policy-gated.
```

→ Runnable approval workflow in **[`examples/hitl-approval`](examples/hitl-approval)** · [Cloud Quickstart](https://docs.jamjet.dev/en/docs/cloud-quickstart)

## Where JamJet sits

```text
            Your Agent / Framework
   (LangChain · CrewAI · ADK · custom · MCP client)
                     │
                     ▼
  ┌───────────────────────────────────────────────┐
  │            JamJet Safety Layer                │
  │   policy · approval · budget · audit · replay  │
  └───────────────────────────────────────────────┘
                     │
                     ▼
        Tools · MCP servers · APIs · DBs · Agents
```

## Use JamJet when your agent can…

- call MCP servers or arbitrary tools
- write to a database
- send emails or Slack messages
- trigger payments or external API calls
- access customer data or PII
- run for minutes/hours and needs to survive crashes
- spend real model budget at scale
- delegate to other agents

## What JamJet adds

| Without JamJet | With JamJet |
|---|---|
| Agent crashes lose progress | Resume from the last checkpoint |
| Tool calls rely on scattered app logic | Runtime policy blocks unsafe actions |
| Human approval is custom glue | Approval is a durable workflow step |
| Costs are discovered after the bill | Budgets enforced per agent / per run |
| Audit evidence is stitched from logs | Append-only event log, signed export |
| Memory is framework-specific | Pair with [Engram](#sub-products) for portable memory (MCP · REST · Python · Java) |
| Frameworks stay siloed | MCP + A2A connect tools and agents |

## Works with your stack — not a replacement

JamJet does not replace LangChain, LangGraph, CrewAI, Google ADK, Spring AI, or your custom agent code. Use those to build agent behavior. Use JamJet to control what happens at runtime.

| You're using | Keep it for | JamJet adds |
|---|---|---|
| **LangChain · LangGraph · CrewAI · Google ADK · AutoGen** | Authoring agent behavior | Runtime safety: policy, audit, replay, approvals |
| **LangSmith · Arize · Weights & Biases** | Observability and evaluation | Active enforcement (block at runtime) + durable recovery |
| **Temporal · Orkes · DBOS** | General durable workflows | Agent-native primitives: policy on tool calls, MCP/A2A, memory |
| **Google · AWS · Azure agent platforms** | Cloud-native ecosystems | Open-source, cloud-neutral governance — works on-prem |

Community-built integrations for **LangChain, LlamaIndex, CrewAI, AutoGen, Pydantic-AI, DSPy, Spring AI, and LangChain4j** live in [`jamjet-labs/jamjet-examples/integrations`](https://github.com/jamjet-labs/jamjet-examples/tree/main/integrations). Want to build the official integration for *your* framework? **[Claim a slot](https://github.com/jamjet-labs/jamjet-examples/issues?q=is%3Aissue+is%3Aopen+label%3Awanted-integration)** — first 10 merged contributors get JamJet swag.

## Examples

| Example | What it shows |
|---------|--------------|
| [`hitl-approval`](examples/hitl-approval) | Human approval as a first-class workflow primitive |
| [`coordinator-routing`](examples/coordinator-routing) | Dynamic agent routing with structured scoring |
| [`claims-processing`](examples/claims-processing) | Insurance pipeline — 4 specialist agents + HITL + audit |
| [`eval-harness`](examples/eval-harness) | Batch evaluation with LLM judge scoring |
| [`mcp-tool-consumer`](examples/mcp-tool-consumer) | Connect to external MCP tool servers |

→ [All 19 examples](examples/) · [Community integrations](https://github.com/jamjet-labs/jamjet-examples/tree/main/integrations) · [Build your own](https://github.com/jamjet-labs/jamjet-examples/issues?q=is%3Aissue+is%3Aopen+label%3Awanted-integration)

## Sub-products

**[Engram](runtime/engram-server/README.md)** — the JamJet ecosystem's memory layer for agents. Where JamJet provides durable *execution* (process can crash and resume), Engram provides durable *memory* (facts persist across runs and version cleanly via `supersede()`). Temporal knowledge graph, hybrid retrieval, conflict detection. Ships as a [Rust crate](https://crates.io/crates/jamjet-engram) (also bundled into the Rust runtime above), an [MCP server](https://registry.modelcontextprotocol.io/servers/io.github.jamjet-labs/engram-server) (Docker · GHCR), a [standalone Python library](https://pypi.org/project/jamjet-engram) ([github.com/jamjet-labs/engram](https://github.com/jamjet-labs/engram), 71% on LongMemEval-S), a [Python client](https://pypi.org/project/jamjet) for the MCP server, and a [Spring AI `ChatMemoryRepository`](https://central.sonatype.com/artifact/dev.jamjet/engram-spring-boot-starter). Comparison with Mem0/Zep → [java-ai-memory.dev](https://java-ai-memory.dev).

**[JamJet Java Runtime](https://github.com/jamjet-labs/jamjet-runtime-java)** — embeds durable execution directly in your JVM, no Docker or sidecar, **8.9× faster** than calling out to one. Works with Spring AI, LangChain4j, and Google ADK. → [Launch post](https://jamjet.dev/blog/zero-sidecar-durable-agents-java/).

## Architecture

Stack diagram

```
┌──────────────────────────────────────────────────────────┐
│                     Authoring Layer                       │
│     Python SDK  |  Java SDK  |  Go SDK (planned)  |  YAML  │
├──────────────────────────────────────────────────────────┤
│                 Compilation / Validation                   │
│           Graph IR  |  Schema  |  Policy lint             │
├────────────────────────────┬─────────────────────────────┤
│      Rust Runtime Core     │      Protocol Layer          │
│  Scheduler  |  State SM    │  MCP Client  |  MCP Server   │
│  Event log  |  Snapshots   │  A2A Client  |  A2A Server   │
│  Workers    |  Timers      │                              │
├────────────────────────────┴─────────────────────────────┤
│                    Enterprise Services                     │
│  Policy  |  Audit  |  PII Redaction  |  OAuth  |  mTLS     │
├──────────────────────────────────────────────────────────┤
│                      Runtime Services                      │
│  Model Adapters  |  Tool Execution  |  Engram Memory      │
├──────────────────────────────────────────────────────────┤
│                         Storage                           │
│           Postgres (production)  |  SQLite (local)        │
└──────────────────────────────────────────────────────────┘
```

*"Engram Memory" here is the in-process distribution bundled with the Rust runtime. Engram also ships standalone — see [Sub-products](#sub-products).*

## Documentation

Full docs at **[jamjet.dev](https://jamjet.dev/quickstart)**

[Quickstart](https://jamjet.dev/quickstart) · [Concepts](https://jamjet.dev/concepts) · [Python SDK](https://jamjet.dev/python-sdk) · [Java SDK](https://jamjet.dev/java-sdk) · [YAML Workflows](https://jamjet.dev/yaml-workflows) · [REST API](https://jamjet.dev/api-reference) · [MCP](https://jamjet.dev/mcp) · [A2A](https://jamjet.dev/a2a) · [Eval](https://jamjet.dev/eval) · [Enterprise](https://jamjet.dev/enterprise) · [Observability](https://jamjet.dev/observability) · [CLI](https://jamjet.dev/cli) · [Deployment](https://jamjet.dev/deployment)

## Contributing

Contributions welcome — see [CONTRIBUTING.md](CONTRIBUTING.md).

**Looking for a starter task?**
- Build a [framework integration](https://github.com/jamjet-labs/jamjet-examples/issues?q=is%3Aissue+is%3Aopen+label%3Awanted-integration) — 8 slots open, first 10 contributors get JamJet swag
- Browse [good first issues](https://github.com/jamjet-labs/jamjet/labels/good%20first%20issue)
- Join the conversation in [Discord](https://discord.gg/SAYnEj86fr)

## Community

[GitHub Discussions](https://github.com/jamjet-labs/jamjet/discussions) · [Issues](https://github.com/jamjet-labs/jamjet/issues) · [Discord](https://discord.gg/SAYnEj86fr)

## License

Apache 2.0 — see [LICENSE](LICENSE).

---

*Hosted control plane available at [app.jamjet.dev](https://app.jamjet.dev) — traces, approval queue, audit retention, team projects. Optional. The runtime, both SDKs, and Engram are Apache-2.0 with no usage limits.*

### ⭐ Star JamJet if you believe agents need a runtime safety layer

Built by Sunil Prakash · © 2026 JamJet Labs · jamjet.dev · Apache 2.0

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [jamjet-labs](https://github.com/jamjet-labs)
- **Source:** [jamjet-labs/jamjet](https://github.com/jamjet-labs/jamjet)
- **License:** Apache-2.0
- **Homepage:** https://jamjet.dev

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-jamjet-labs-jamjet
- Seller: https://agentstack.voostack.com/s/jamjet-labs
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
