mcpgawk Platform
We emailed you a license key when your seat was issued. Two commands: install mcpgawk, then log in with the key.
Check your status
Paste your license key to confirm it's active right now — before you touch a terminal.
The same install as everyone else — your key is the only thing a licence adds. No GitHub account, no Node toolchain, nothing built on your machine.
uv tool install --force mcpgawk
No uv? curl -LsSf https://astral.sh/uv/install.sh | sh — no admin rights needed. pipx install --force mcpgawk works too.
mcpgawk login 'your-key-from-our-email'
The quotes matter: the key contains | characters, which your shell would otherwise read as a pipe and split the key at the first one.
login fetches the paid engine with your key — a pre-built package, checked against the sha256 the server published — installs it into the same place as the free scanner, and saves the key to ~/.gawk/config.json (mode 0600). The paid pillars (monitor, enforce) become subcommands of the one mcpgawk binary. A key that is not on a live trial or licence gets one line saying so and nothing is installed. (Lost your key? email us and we'll resend it.)
For CI, set GAWK_LICENSE_KEY as a secret instead — the env var takes priority over a saved key.
mcpgawk enforce status
The first time you run any paid pillar (enforce, monitor) on a machine, it activates your key — this registers that machine as one of your license's seats (up to 3 per key). After that, it's checked automatically before each run, with a 24-hour local cache so you're not making a network call on every single command.
mcpgawk verify is free and needs no key — sandboxed behavioural verification ships with the open-source scanner. A licence adds the capabilities below.
mcpgawk enforce serve ... — the gateway: one endpoint in front of your MCP fleet, per-principal keys and policy, hash-chained audit
mcpgawk monitor run — continuous drift monitoring
mcpgawk build openapi.json — generate an MCP server from an OpenAPI spec (in development)
Run mcpgawk <pillar> --help for each tool's own full usage — mcpgawk passes your arguments straight through, it doesn't reinterpret them.
GAWK_LICENSE_KEY isn't set, or isn't set in the shell/process actually running the command (common in CI: check it's in the job's env, not just your local shell).| Free | Paid | |
|---|---|---|
mcpgawk scan — local token-cost + capability measurement | ✓ | ✓ |
mcpgawk verify — sandboxed reproduction of findings | ✓ | ✓ |
mcpgawk monitor — continuous drift detection | — | ✓ |
mcpgawk enforce — the gateway: a key per agent, policy per call, a hash-chained audit log | — | ✓ |
mcpgawk build — generate an MCP server from an OpenAPI spec | — | in development |
Nothing about the free scanner changes with a paid license — mcpgawk scan runs the same, locally, nothing uploaded, whether or not GAWK_LICENSE_KEY is set.