Home/Compare/mcp-trust-plane vs manifest

Comparison

mcp-trust-plane vs manifest

Verdict

Pick mcp-trust-plane if mCP Trust Plane is designed for organizations that need to enforce security policies on MCP traffic without modifying core components of the protocol stack; pick manifest if manifest is a TypeScript framework under MIT license that enables integration of AI agents across various providers, with an emphasis on observability and tracking mechanisms such as token and cost-tracking.

Markdown twin · mcp-trust-plane alternatives · manifest alternatives

GraphCanon updated Sep 20, 2026

5views this month

mcp-trust-plane logo

mcp-trust-plane

abluva-research/mcp-trust-plane

100pushed Jun 19, 2026
vs
manifest logo

manifest

mnfst/manifest

7.5kpushed Sep 10, 2026

Trust & integrity

Signalmcp-trust-planemanifest
Maintenance
Steady (85d since push)
As of Sep 13, 2026 · github_public_v1
Very active (0d since push)
As of Sep 10, 2026 · github_public_v1
Provenance
Not a fork · Organization account
As of Sep 13, 2026 · github_public_v1
Not a fork · Organization account
As of Sep 10, 2026 · github_public_v1
OSV dependency advisories
No lockfile (source not queried)
As of Jul 15, 2026 · osv@v1
No lockfile (source not queried)
As of Jul 15, 2026 · osv@v1
deps.dev advisories
Not queried
deps.dev@v1
Not queried
deps.dev@v1
OpenSSF Scorecard
Not queried
openssf-scorecard@v1
Not queried
openssf-scorecard@v1

Tagline

mcp-trust-plane
Pluggable security framework for MCP traffic
manifest
Connect Your Agents And Harnesses With Any Provider

Stars

mcp-trust-plane
100
manifest
7.5k

Forks

mcp-trust-plane
26
manifest
508

Open issues

mcp-trust-plane
0
manifest
110

Language

mcp-trust-plane
JavaScript
manifest
TypeScript

Adopt for

mcp-trust-plane
MCP Trust Plane is designed for organizations that need to enforce security policies on MCP traffic without modifying core components of the protocol stack.
manifest
Manifest is a TypeScript framework under MIT license that enables integration of AI agents across various providers, with an emphasis on observability and tracking mechanisms such as token and cost-tracking.

Persona

mcp-trust-plane
-
manifest
-

Runtime

mcp-trust-plane
-
manifest
-

License

mcp-trust-plane
Apache-2.0
manifest
MIT

Last pushed

mcp-trust-plane
Jun 19, 2026
manifest
Sep 10, 2026

Categories

mcp-trust-plane
AI Agents, Evaluation & Observability
manifest
AI Agents, Evaluation & Observability

Trust and health

Maintenance

mcp-trust-plane
Steady (60%)
manifest
Very active (96%)

Days since push

mcp-trust-plane
85d
manifest
0d

Open issues (now)

mcp-trust-plane
0
manifest
110

Stars delta

mcp-trust-plane
+1 (30d)
manifest
+100 (30d)

Open issues delta

mcp-trust-plane
0 (30d)
manifest
+1 (30d)

Full report

mcp-trust-plane
Trust report
manifest
Trust report

Choose mcp-trust-plane if…

  • mcp-trust-plane is primarily JavaScript; manifest is TypeScript.
  • License: mcp-trust-plane is Apache-2.0, manifest is MIT.
  • Pricing: MCP Trust Plane is open-source under Apache 2.0, making it available at no cost but provides flexibility to extend commercially through proprietary filter implementations..
  • Requirements: Min 1 GB RAM.
  • Tags unique to mcp-trust-plane: access-control, data-governance-and-ai, data-security, enterprise-security.
  • mcp-trust-plane ships Docker support for self-hosted deployment.
  • MCP Trust Plane should be used when you require granular control over tool calls in your MCP-enabled systems, such as enforcing PII redaction or operation blocking.

When NOT to use mcp-trust-plane

  • Avoid MCP Trust Plane if your security needs do not require modification of traffic post-response, as it introduces an additional layer of complexity and latency.
  • MCP Trust Plane may not be the best choice for environments that strictly enforce language-specific policies since its filters are written in any language and must comply with a strict contract.

Choose manifest if…

  • manifest is primarily TypeScript; mcp-trust-plane is JavaScript.
  • License: manifest is MIT, mcp-trust-plane is Apache-2.0.
  • Tags unique to manifest: llm-observability.
  • When you need to establish connections between multiple AI providers without altering the core functionality or architecture of your existing systems.

When NOT to use manifest

  • If your project strictly requires use cases with non-TypeScript languages, as this would necessitate additional integration work.
  • When you require a mature framework; given Manifest's beta status, it might not be the best choice for production environments sensitive to potential bugs or incomplete features.

Explore

Sources

Every stat on this page traces to a dated GitHub sync, license file, enrichment field, or trust scan.

GitHub stars on cards: mcp-trust-plane 100 · manifest 7.5k (synced Sep 20, 2026).

Common questions

What is the difference between mcp-trust-plane and manifest?
mcp-trust-plane: Pluggable security framework for MCP traffic. manifest: Connect Your Agents And Harnesses With Any Provider. See the comparison table for live GitHub stats and shared categories.
When should I choose mcp-trust-plane over manifest?
Choose mcp-trust-plane over manifest when mcp-trust-plane is primarily JavaScript; manifest is TypeScript; License: mcp-trust-plane is Apache-2.0, manifest is MIT; Pricing: MCP Trust Plane is open-source under Apache 2.0, making it available at no cost but provides flexibility to extend commercially through proprietary filter implementations.; Requirements: Min 1 GB RAM; Tags unique to mcp-trust-plane: access-control, data-governance-and-ai, data-security, enterprise-security; mcp-trust-plane ships Docker support for self-hosted deployment; MCP Trust Plane should be used when you require granular control over tool calls in your MCP-enabled systems, such as enforcing PII redaction or operation blocking.
When should I choose manifest over mcp-trust-plane?
Choose manifest over mcp-trust-plane when manifest is primarily TypeScript; mcp-trust-plane is JavaScript; License: manifest is MIT, mcp-trust-plane is Apache-2.0; Tags unique to manifest: llm-observability; When you need to establish connections between multiple AI providers without altering the core functionality or architecture of your existing systems.
When should I avoid mcp-trust-plane?
Avoid MCP Trust Plane if your security needs do not require modification of traffic post-response, as it introduces an additional layer of complexity and latency. MCP Trust Plane may not be the best choice for environments that strictly enforce language-specific policies since its filters are written in any language and must comply with a strict contract.
When should I avoid manifest?
If your project strictly requires use cases with non-TypeScript languages, as this would necessitate additional integration work. When you require a mature framework; given Manifest's beta status, it might not be the best choice for production environments sensitive to potential bugs or incomplete features.
Is mcp-trust-plane or manifest more popular on GitHub?
manifest has more GitHub stars (7,514 vs 100). Stars measure visibility, not whether either tool fits your constraints.
Are mcp-trust-plane and manifest open source?
Yes - both are open-source projects on GitHub (mcp-trust-plane: Apache-2.0, manifest: MIT).
Where can I find alternatives to mcp-trust-plane or manifest?
GraphCanon lists graph-backed alternatives at mcp-trust-plane alternatives and manifest alternatives (mcp-trust-plane markdown twin, manifest markdown twin), ranked by typed relationship edges rather than popularity votes.
Is there a machine-readable version of this comparison?
Yes. The markdown twin at this comparison mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.
Which is better maintained, mcp-trust-plane or manifest?
mcp-trust-plane: Steady. manifest: Very active. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.
Where are the full trust reports for mcp-trust-plane and manifest?
GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: mcp-trust-plane trust report; manifest trust report.

Was this helpful?

Anonymous feedback helps us improve pages and translations.