Goose is an extensible framework that, by default, allows you to install any MCP server. However, you may want stricter controls on which MCP servers can be installed as extensions (e.g. in a corporate setting).
This guide explains how you can create an **allowlist** of safe extensions that work with Goose Desktop and CLI. An allowlist lets administrators control which MCP servers can be installed as Goose extensions. When enabled, Goose will only install extensions that are on the list, and will block installation of any others.
## How It Works
1. The allowlist is a YAML file that contains a list of allowed extension commands.
2. Goose fetches the allowlist from a URL specified by the `GOOSE_ALLOWLIST` environment variable.
3. The allowlist is fetched when first needed and is cached. It is refetched on every restart of Goose.
4. When a user attempts to install an extension, Goose checks the MCP server's installation command against the allowlist.
5. If the command is not in the allowlist, the extension installation is rejected.
## Configuration
### 1. Create and Deploy Allowlist
The allowlist must be a YAML file with the following structure:
```yaml
extensions:
- id:extension-id-1
command:command-name-1
- id:extension-id-2
command:command-name-2
# ... more extensions
```
#### Example
In this example, only the Slack, GitHub, and Jira extensions can be installed:
```yaml
extensions:
- id:slack
command:uvx mcp_slack
- id:github
command:uvx mcp_github
- id:jira
command:uvx mcp_jira
```
After creating the allowlist, you must deploy it to a URL.
### 2. Set Environment Variable
Create an environment variable called `GOOSE_ALLOWLIST` and set the value to the URL of your YAML file: