# delimit-mcp-server

> Unify Claude Code, Codex, Cursor, and Gemini CLI with persistent context, governance, and multi-model debate. 186 MCP tools. 123 tests.

- **URL**: https://www.freshcrate.ai/projects/delimit-mcp-server
- **Author**: delimit-ai
- **Category**: MCP Servers
- **Latest version**: `v4.7.1` (2026-06-04)
- **License**: MIT
- **Source**: https://github.com/delimit-ai/delimit-mcp-server
- **Homepage**: https://delimit.ai
- **Language**: Python
- **GitHub**: 13 stars, 5 forks
- **Registry**: github
- **Tags**: `ai-governance`, `api-governance`, `breaking-changes`, `claude-code`, `codex`, `cross-model`, `cursor`, `deliberation`, `model-context-protocol`, `python`

## Description

Unify Claude Code, Codex, Cursor, and Gemini CLI with persistent context, governance, and multi-model debate. 186 MCP tools. 123 tests.

## Recent releases

| Version | Date | Urgency | Changes |
| --- | --- | --- | --- |
| `v4.7.1` | 2026-06-04 | High | ## What's Changed * ci(publish): switch npm publish to OIDC Trusted Publishing (no token) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/110 * release: v4.7.1 — verify OIDC trusted-publishing pipeline (provenance) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/111 * ci(publish): drop registry-url so OIDC trusted publishing works (v4.7.1 E404 fix) by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/112 * ci(publish): run publish j |
| `v4.5.13` | 2026-05-08 | High | ## What's Changed * fix(publish): compile license_core .so AFTER sync-gateway — 4.5.13 by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/91   **Full Changelog**: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.5.12...v4.5.13 |
| `v4.5.5` | 2026-05-07 | High | ## What's Changed * fix(hooks): 3-tier fallback for delimit setup hooks (LED-1248) — 4.5.5 by @infracore in https://github.com/delimit-ai/delimit-mcp-server/pull/82   **Full Changelog**: https://github.com/delimit-ai/delimit-mcp-server/compare/v4.5.4...v4.5.5 |
| `v4.3.4` | 2026-04-23 | High | **Second release shipped through the dogfood chain.** Clears the known-debt tail from v4.3.3.  ## Dogfood evidence chain  \| Gate \| Result \| \|---\|---\| \| `delimit_repo_diagnose` \| ✓ \| \| `delimit_security_audit` (direct-python, bypassing MCP cache) \| ✓ 22 findings → 1 (upstream npm-audit moderate; 21 pattern false positives suppressed by new nosec-aware scanner) \| \| `delimit_test_smoke` \| ✓ 165/165 \| \| `delimit_changelog` \| ✓ \| \| `delimit_deploy_plan` \| ✓ \| \| CI (Node 18 / 20 / 22 + CodeQL + API Ch |
| `v4.2.0` | 2026-04-22 | High | **Full-stack deploy: gateway + UI + npm bundle**  ## Added (LED-987 through LED-1008)  - **ACTION_DENYLIST (LED-988)** — executor gains an explicit denylist of prohibited action categories (money, legal/identity, credentials, deploy, contracts) that fires BEFORE the ACTION_SPEC whitelist check. Defense in depth against LLM-driven executor drift. - **`propose_pr` autonomous build primitive (LED-988)** — executor can propose PRs against an allowlisted repo set (`PROPOSE_PR_ALLOWED_REPOS`) with a f |
| `v4.1.38` | 2026-04-04 | High | ## What's New in v4.1.29-4.1.38  ### Persistent Memory - `delimit remember "context"` -- save memories across sessions and models - `delimit recall [query]` -- search, filter by tag, export as markdown - `delimit forget <id>` -- delete a memory  ### Local Governance Gates - `delimit check` -- pre-commit check (exits non-zero on breaking changes) - `delimit hooks install` -- install git pre-commit/pre-push hooks - `delimit ci` -- generate GitHub Action workflow in one command  ### Session Lifecyc |
| `v3.10.3` | 2026-03-21 | Low | Dockerfile for Glama MCP inspector. Glama badge. Mobile-friendly README. |
| `v3.9.2` | 2026-03-21 | Low | ## What's New  **IP Protection:** - Pro tool source removed from public repo (stubs only) - Crown jewels (deliberation, governance, license) compiled with Nuitka to native binaries - 6 platform builds: Linux x64 + macOS ARM × Python 3.10-3.12 - Git history scrubbed of Pro source code  **Licensing:** - Runtime license gate blocks 32 Pro tools without valid key - 30-day re-validation against Lemon Squeezy (privacy-preserving) - 7-day grace period, 14-day hard block - 3 free deliberations/month for |
| `v3.8.1` | 2026-03-21 | Low | ## What's New  **Cross-model continuity** — Your tasks, memory, and governance carry between Claude Code, Codex, and Gemini CLI. Switch models without losing context.  **Project scan** — `delimit_scan` discovers OpenAPI specs, frameworks, security issues, and tests in your project. The first-run "aha moment."  **CLI-first deliberation** — Uses your existing CLI subscriptions (Claude Pro, Codex Pro, Gemini Ultra) instead of separate API keys. No extra cost.  **Governance trigger** — AI assistants |
| `v3.6.11` | 2026-03-21 | Low | ## What's New  **Multi-model deliberation** — Run consensus across Grok, Gemini, GPT-4o, Claude, or Codex CLI. Setup silently auto-detects your API keys.  **Security hardening:** - Pinned Python dependencies with isolated venv install - All internal paths removed from shipped package - No hardcoded credentials, tokens, or infrastructure details  **Gemini CLI support** — Full MCP integration with all 79 tools. Fixed `type` parameter naming that broke Gemini's function calling API.  **GitHub Actio |

## Citation

- HTML: https://www.freshcrate.ai/projects/delimit-mcp-server
- Markdown: https://www.freshcrate.ai/projects/delimit-mcp-server.md
- Dependencies JSON: https://www.freshcrate.ai/api/projects/delimit-mcp-server/deps

_Generated by freshcrate.ai. Indexes github releases for AI-agent ecosystem packages._
