<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws" -->

---
title: Obot Platform v0.25.0: Tool Call Enforcement, MCP...
description: Obot Platform v0.25.0 introduces tool call enforcement, allowing administrators to define an allowlist of approved tools and MCP servers. Obot Sentry checks...
canonical: https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels &amp; Agent Auth Scopes | daily.dev
og:description: Obot Platform v0.25.0 introduces tool call enforcement, allowing administrators to define an allowlist of approved tools and MCP servers. Obot Sentry checks...
og:url: https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws
og:image: https://api.daily.dev/og/posts/cRA8P9Jws.png
og:image:alt: Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels &amp; Agent Auth Scopes
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels & Agent Auth Scopes

**[Obot AI](https://daily.dev/sources/snprm3tml5d33cwmq1w5q)** · [@obot_ai](https://daily.dev/obot_ai) · 1 min read · 0 upvotes · 0 comments

## Summary

Obot Platform v0.25.0 introduces tool call enforcement, allowing administrators to define an allowlist of approved tools and MCP servers. Obot Sentry checks every tool call against this allowlist via a pre-tool hook before execution, failing closed and logging every decision. The release also adds MCP Tunnels for reaching private-network MCP servers via outbound WebSocket connections without firewall changes, Agent Auth Scopes providing scoped expiring API keys for headless agents, and a new Community tier making all auth and model providers available without an enterprise license.

## Content

**Obot Platform v0.25.0 is out**, and it closes the loop on something we've been working toward for a few releases: governing not just what flows through Obot, but what AI agents do on developer machines before a request ever reaches a gateway.

Device management in v0.22.0 gave admins inventory. v0.24.0 added audit logs via Obot Sentry. v0.25.0 adds enforcement: administrators can now define an allowlist of approved tools and MCP servers, and Obot Sentry checks every tool call against it through the coding agent's pre-tool hook before it runs. Fails closed. Every decision is logged.

But that's just the headline. This release also adds:

- **MCP Tunnels** — reach MCP servers on private networks via an outbound WebSocket connection, no inbound firewall changes required
- **Agent Auth Scopes** — scoped, expiring API keys for autonomous and headless agents that can't do a browser sign-in
- **Obot Community tier** — all auth and model providers now available without an enterprise license

Full breakdown in the release notes below.

📓 [Full release notes](https://obot.ai/blog/announcing-obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-and-agent-auth-scopes/?utm_source=dailydev&utm_medium=syndication&utm_campaign=obot-v0-25-0) · 🐙 [GitHub v0.25.0](https://github.com/obot-platform/obot/releases/tag/v0.25.0)

_Originally published on _[_Obot AI_](https://obot.ai/blog/announcing-obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-and-agent-auth-scopes/?utm_source=dailydev&utm_medium=syndication&utm_campaign=obot-v0-25-0)

---

Tags: [#security](https://daily.dev/tags/security), [#ai-agents](https://daily.dev/tags/ai-agents), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws","headline":"Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels & Agent Auth Scopes","text":"Obot Platform v0.25.0 introduces tool call enforcement, allowing administrators to define an allowlist of approved tools and MCP servers. Obot Sentry checks every tool call against this allowlist via a pre-tool hook before execution, failing closed and logging every decision. The release also adds MCP Tunnels for reaching private-network MCP servers via outbound WebSocket connections without firewall changes, Agent Auth Scopes providing scoped expiring API keys for headless agents, and a new Community tier making all auth and model providers available without an enterprise license.","url":"https://daily.dev/posts/obot-platform-v0-25-0-tool-call-enforcement-mcp-tunnels-agent-auth-scopes-cra8p9jws","datePublished":"2026-08-03T13:08:39.831Z","dateModified":"2026-08-03T13:14:11.227Z","author":{"@type":"Person","name":"Obot AI","url":"https://daily.dev/obot_ai","image":"https://media.daily.dev/image/upload/s--uppa7UXU--/f_auto/v1779993498/avatars/avatar_SnPRm3tML5D33cwMQ1w5q?_a=BAMAMiWQ0","description":"Open-source AI Control Plane","interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"EndorseAction"},"userInteractionCount":90}},"image":"https://media.daily.dev/image/upload/s--OUfpjHhA--/f_auto/v1785762850/posts/cRA8P9Jws?_a=BAMAMicg0","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/snprm3tml5d33cwmq1w5q","name":"Obot AI"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Obot AI","item":"https://daily.dev/sources/snprm3tml5d33cwmq1w5q"},{"@type":"ListItem","position":3,"name":"Obot Platform v0.25.0: Tool Call Enforcement, MCP Tunnels & Agent Auth Scopes"}]}
```

