Back to Browse

Impri MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Impri MCP server — human-in-the-loop approval inbox for AI agents

About

Impri MCP server — human-in-the-loop approval inbox for AI agents

Remote endpoints: streamable-http: https://api.impri.dev/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. Trust signals: trusted author (3/3 approved). 1 finding(s) downgraded by scanner intelligence.

8 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Impri API key (im_...). Get one at impri.dev or from your self-hosted server's first-run logs.Required

Environment variable: IMPRI_API_KEY

Base URL of a self-hosted Impri server (e.g. http://localhost:8484). Defaults to the hosted cloud.Optional

Environment variable: IMPRI_BASE_URL

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Impri

M8ven Score

Human-in-the-loop approval inbox for AI agents.

Your agent wants to send the email, post the reply, run the migration. You want to see it before it happens, from your phone if you're not at a desk. Impri is the inbox in between.

Agent (Claude Code / any MCP client)  →  Impri inbox  →  You approve, edit, or reject
        ↑                                                          |
        └──────────────── agent executes, reports result ──────────┘

Impri demo: an agent pushing an action, the approval inbox, a human approving it, the agent executing

Watch as MP4

The problem

Agents that only read and draft are safe by construction. The moment one can send an email, post a reply, or run a write against a database, "ask the user first" becomes a system-prompt instruction — and a instruction is something a capable model can reason its way past, forget under load, or misjudge on an edge case you didn't anticipate.

Impri turns that instruction into a data dependency instead. The agent pushes a proposed action to an inbox and polls for a decision; the execution branch is only reachable once the API actually returns status: "approved". There's nothing to talk the model past — the gate lives outside the model, not inside its prompt.

60-second install

No install at all — connect straight to the hosted endpoint if your client supports a remote MCP server:

claude mcp add --transport http impri https://api.impri.dev/mcp --header "Authorization: Bearer $IMPRI_API_KEY"
codex mcp add impri --url https://api.impri.dev/mcp
# then add to ~/.codex/config.toml under [mcp_servers.impri]:
#   bearer_token_env_var = "IMPRI_API_KEY"

Or run the local package (needed if you're pointing at a self-hosted server instead of the cloud):

Claude Code:

claude mcp add impri --env IMPRI_API_KEY=im_... --env IMPRI_BASE_URL=https://api.impri.dev -- npx -y @impri/mcp

Codex:

codex mcp add impri --env IMPRI_API_KEY=im_... --env IMPRI_BASE_URL=https://api.impri.dev -- npx -y @impri/mcp

Cursor — add to .cursor/mcp.json:

{
  "mcpServers": {
    "impri": {
      "command": "npx",
      "args": ["-y", "@impri/mcp"],
      "env": {
        "IMPRI_API_KEY": "im_...",
        "IMPRI_BASE_URL": "https://api.impri.dev"
      }
    }
  }
}

Windsurf — add the same block to mcp_config.json:

{
  "mcpServers": {
    "impri": {
      "command": "npx",
      "args": ["-y", "@impri/mcp"],
      "env": {
        "IMPRI_API_KEY": "im_...",
        "IMPRI_BASE_URL": "https://api.impri.dev"
      }
    }
  }
}

Get an im_... key with one curl call — no signup form:

curl -s -X POST https://api.impri.dev/v1/signup -H "Content-Type: application/json" -d '{"name":"my-agent"}'

IMPRI_BASE_URL defaults to http://localhost:8484 (self-host) if you omit it — set it to https://api.impri.dev for the hosted cloud, as above. Self-hosting instead of the cloud? See Self-host or cloud below.

What the agent can do

ToolWhat it does
impri_push_actionSubmit a proposed action — title, formatted preview, optional editable fields
impri_await_decisionPoll until a human approves, rejects, or the timeout elapses
impri_report_resultReport whether the approved action actually succeeded
impri_inbox_statusCheck how many actions are waiting, before starting a big batch
impri_create_watcherCreate a watcher (RSS / Reddit search / URL diff) that feeds matching items into the inbox
impri_list_watchersList configured watchers, optionally filtered by status
impri_list_watcher_presetsList the 18 ready-made watcher templates (Hacker News, GitHub releases, npm, arXiv, …)
impri_create_watcher_from_presetCreate a watcher from a preset by id + params, no config schema to write

The loop

1. impri_push_action(kind, title, preview)        → { action_id, status: "pending", inbox_url }
2. impri_await_decision(action_id)                 → waits for a human to approve/reject/edit, or times out
3. If approved: execute the real action
4. impri_report_result(action_id, "executed" | "execute_failed")

Or in plain REST, the same three calls:

ACTION=$(curl -s -X POST https://api.impri.dev/v1/actions \
  -H "Authorization: Bearer $IMPRI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"email.send","title":"Outreach: Acme","preview":{"format":"markdown","body":"Hi Sarah, ..."}}')
ID=$(echo "$ACTION" | jq -r .id)

# poll (or long-poll) until a human decides
DECISION=$(curl -s "https://api.impri.dev/v1/actions/$ID" -H "Authorization: Bearer $IMPRI_API_KEY")

# only now, and only if approved
[ "$(echo "$DECISION" | jq -r .status)" = "approved" ] && send_email "$(echo "$DECISION" | jq -r '.decision.final_preview.body // .preview.body')"

The human doesn't have to be staring at a dashboard: an action can notify Slack, Discord, Telegram, ntfy, email, or a generic webhook, and the reviewer can edit the draft before approving — the agent receives that edited text back.

Why not just a prompt instruction?

"Please ask before sending" in the system promptImpri
The model has to remember, every timeExecution is unreachable without status: "approved" from the API
No record of who decided what, or whenEvery decision is in the audit log
Can't fix a typo without a new draftEdit-before-approve — the agent gets the edited version back
One-off per agent, per projectOne inbox, six notification channels, 18 watcher presets, all agents

The honest caveat: this is a real gate only as long as the approved path is the agent's only path to the side effect — give it the raw credential too and it can route around you.

Self-host or cloud

Cloud — signup above, inbox at app.impri.dev, early beta.

Self-host — full core, MIT, no license key:

git clone https://gitlab.com/sekera.radim/impri.git
cd impri
docker compose up

Server on http://localhost:8484, web inbox on http://localhost:8080. The bootstrap admin key prints to the logs on first start. Details: Self-hosting.

Reference

Everything below is unchanged technical detail: CLI, SDKs, integrations, the full doc set, and legal.

CLI, SDKs & integrations

v0.1, pre-release. MCP is published; the CLI and both SDKs are local-install only (pre-npm / pre-PyPI) for now.

PackageLocationStatus
MCP servermcp/ / npx @impri/mcpPublished
CLI (impri)cli/Local build — see CLI reference
Python SDKsdk/python/Local install (pip install -e sdk/python)
TypeScript SDKsdk/typescript/Local install (npm install ./sdk/typescript)

Framework integrations in integrations/: packages for the Claude Agent SDK, CrewAI, LangChain, and the OpenAI Agents SDK; documented webhook-based patterns for n8n, Make, and Zapier in Integrations.

Notifications

Six channels: Slack, Discord, Telegram, email, ntfy, and generic webhook. See Notification channels and Telegram Approval Bot.

Documentation

Pricing

Free (3 watchers, 100 approvals/mo) · Indie $9/mo (20 watchers, 2,000 approvals/mo, 5-minute checks) · Team $29/mo (unlimited watchers and approvals, 1-minute checks). Self-host the full core for free — no tier limits apply outside the hosted cloud. Details: impri.dev.

Privacy & legal

License

MIT — see LICENSE. Self-host the full core freely; the hosted cloud and paid tiers are the commercial offering (see MONETIZATION.md).


Made by Radim Sekera. Related project: briefgate.dev — client intake for AI coding agents.

Reviews

No reviews yet

Be the first to review this server!