Hugging Face MCP server, with a policy gate.
Search Hugging Face models, datasets, and papers from any MCP client through your Gentkey — no account required, and the one tool that can write is gated.
https://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP clientWhat’s free, what needs a grant.
Reads: Model, dataset, paper, and doc search work with no grant — and no Hugging Face account.
Writes: The filesystem tool is deliberately excluded from the free-read set: it can mutate repo storage when authenticated.
Gentkey proxies the official Hugging Face MCP server (https://huggingface.co/mcp) — you get the vendor’s own tools, with custody, gating, and audit added in front.
| Grant | What it governs |
|---|---|
mcp-huggingface.write | The filesystem tool and anything else that can mutate repo storage |
Connect once, use everywhere.
Sign in at gentkey.com, add Hugging Face (no account needed), then point each client at your endpoint. Every client completes a standard OAuth flow and lands in your Gentkey — your connections, nobody else’s.
claude.ai (web & mobile)
- Settings → Connectors
- Add custom connector
- Paste
https://app.gentkey.com/mcpand finish the OAuth prompt
Claude Code
claude mcp add --transport http \
gentkey https://app.gentkey.com/mcpCursor
// .cursor/mcp.json
{
"mcpServers": {
"gentkey": { "url": "https://app.gentkey.com/mcp" }
}
}Things agents do with Hugging Face here.
- Find the best small embedding models released this year.
- What datasets exist for legal document summarization?
- Summarize the paper behind the Qwen3 release.
- How do I use the transformers pipeline for token classification?
Custody, gating, and audit — built in.
The model never sees a credential
Your Hugging Face token is encrypted at rest and injected server-side at call time. Your stored credential never enters a context window.
Writes need a grant
Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.
A trail you can act on
Every decision is attributed to the agent that made it — allowed, denied, or denied by constraint.
Fair questions.
Why put a public-data connector behind a gateway at all?
Because it's one of many services behind the same URL — an agent that already talks to your Gentkey gets Hugging Face search for free, without another connector slot — and because the one upstream tool that can mutate repo storage stays gated rather than trusted.
What happens when an agent calls a Hugging Face write tool it hasn't been granted?
The call is denied at the gateway — nothing reaches Hugging Face — and the denial is recorded in the audit log along with the grant that would have authorized it, so you can decide deliberately instead of finding out later.
Where are my credentials stored?
Encrypted at rest (AES-256-GCM) on Gentkey's server and injected server-side at call time. No credential you store with Gentkey ever enters a model's context window or an agent's config file.
Can I use this from claude.ai's free plan?
Yes — and it's the strongest case for a gateway: free claude.ai accounts currently get a single custom connector, so pointing that one slot at Gentkey puts every connector you've linked behind it.
How do I revoke an agent's access?
Revoke the grant (the next write is denied) or revoke the agent's tokens entirely in one click. Other agents and their grants are untouched — no shared key to rotate.
Is Gentkey affiliated with Hugging Face?
No. Gentkey is an independent MCP gateway. Trademarks belong to their owners; where an official Hugging Face MCP server exists, Gentkey proxies it and adds custody, gating, and audit on top.
Often connected together.
Cut Hugging Face a smaller key.
Sign in, connect Hugging Face, and grant your first scoped capability in under a minute.