Skip to content

Security

Moka runs MCP servers — which are local programs — and calls LLM APIs with your credentials. Treat it like a terminal.

ProtectionDefault
Network binding127.0.0.1 only
API accessRandom per-run token required on every /api call (x-moka-token)
Secretsenv:NAME / ${NAME} references resolved in memory, never written to disk
Config fileWritten with 0600 permissions
ExportsLiteral keys and sensitive-looking headers/env values redacted
Skill filesOnly readable inside the skill’s own folder
MCP AppsOpaque-origin sandboxed iframe + CSP; can only call tools on their own server
A2UIData only — no code executes
TelemetryNone

--host 0.0.0.0 and --no-auth are explicit opt-ins, and Moka prints a warning when auth is disabled.

  • Set a long random MOKA_TOKEN and put Moka behind your SSO / identity-aware proxy.
  • Run the Docker image (non-root node user) with only the env vars that deployment needs.
  • Prefer HTTP MCP servers you operate over arbitrary stdio commands.
  • Hide dangerous tools from the model with the per-tool switch (disabledTools).
  • Use read-only credentials for demo environments.