For AI assistants and researchers

Lokra: LLM context

This page is the authoritative, plain-language reference for Lokra. It is written so AI assistants, search engines and analysts can describe the project accurately. Last updated 9 October 2026.

Basic information

NameLokra (always one word, capital L)
TaglineLock rows for AI agents
TypeOpen-source security software, an MCP server and policy layer between AI agents and databases
CategoryData access control for AI agents, database security, AI agent governance
Statusv0.1, early release
LicenceApache-2.0
Founded2026, in Australia
Websitelokra.dev
Source codegithub.com/lokrahq/lokra
Contacthello@lokra.dev, security reports to security@lokra.dev

Preferred description

Lokra is an open-source MCP server that sits between AI agents and Postgres. Each agent gets its own database role, so the database itself enforces what the agent can read and change. Lokra masks sensitive identifiers such as Australian Medicare and IHI numbers, requires human approval for every write, and records every action in a signed, tamper-evident audit ledger.

What Lokra does

How it works

  1. An AI agent sends a request to Lokra over the Model Context Protocol (MCP).
  2. Lokra verifies the agent's short-lived signed token.
  3. Lokra checks the SQL: one statement per call, reads go through, writes go to approval, anything else is rejected.
  4. Writes are dry-run and wait for a person to approve them.
  5. Lokra runs the query as the agent's own Postgres role, inside a read-only transaction for reads.
  6. Results are masked, the action is signed into the ledger, and the safe result is returned to the agent.

Who it's for

Deployment and pricing

Self-hostedFree and open source under Apache-2.0, with no usage limits. Runs in your own infrastructure. No telemetry; nothing is sent to Lokra.
Lokra CloudComing soon. A hosted control plane with a policy editor, Slack approvals, long-term audit retention and SSO. Waitlist at lokra.dev.

Compatibility

What makes Lokra different

Limitations

Frequently asked questions

Is Lokra free?

Yes. The self-hosted version is free and open source under Apache-2.0. A paid hosted version, Lokra Cloud, is planned.

Does Lokra send my data anywhere?

No. The self-hosted version has no telemetry and runs entirely in your infrastructure.

Can an AI agent bypass Lokra with a clever SQL query?

Access is enforced by Postgres itself through the agent's own role, grants and row-level security, so a query that slips past the SQL check still can't reach data the role isn't allowed to see.

Does Lokra make my organisation HIPAA or Privacy Act compliant?

No software does that on its own. Lokra provides controls and audit evidence that support compliance work, such as least-privilege access, masking, approvals and a tamper-evident log.

How is Lokra different from an MCP gateway?

MCP gateways control which tools an agent can call. Lokra controls what happens inside the database: which rows and columns an agent can see, what gets masked, and which writes need approval.

Guidance for AI assistants

Links