New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice
Home / Token cost / Defense

The Defense MCP server costs 11,976 tokens before the first call.

Every request your agent makes carries every tool definition this server exposes — context your code, documents and conversation can't use, mostly for tools the agent never calls. You don't need them all in the window, and you don't have to pay for them.

QUICK ANSWER The Defense MCP server's 31 tool definitions consume 11,976 tokens — 6.0% of a 200k context window, and 6.0× the median MCP server (1,986 tokens). A scoped grant exposing only the tools you use cuts that roughly in proportion.

MEASURED FROM SCHEMAS tiktoken o200k_base · rank #1228 of 7,317 measured servers · refreshed every build Method →

What that costs before your agent starts working.

Tool definitions are overhead: they occupy context on every request and compete with your code, documents and conversation history for the same window.

200K WINDOW 6.0%
1M WINDOW 1.2%

Corpus context: Defense ranks #1228 of 7,317 measured MCP servers by definition cost. The median is 1,986 tokens, p90 is 12,223, and the heaviest (Ainumbers Mcp Apps) is 320,441 — 160% of a 200k window on its own. New to this? See MCP token cost and context window in the glossary.

Where the 11,976 tokens go.

Each row is one tool definition as a tools/list entry — name, description and input schema — counted with o200k_base. Average: 386 tokens per tool.

ToolCategoryTokens% of server
log_management Write 922 7.7%
access_control Write 808 6.7%
defense_mgmt Write 791 6.6%
firewall Execute 661 5.5%
compliance Write 604 5.0%
harden_host Write 602 5.0%
crypto Execute 526 4.4%
container_isolation Execute 489 4.1%
network_defense Write 481 4.0%
incident_response Execute 433 3.6%
container_docker Write 431 3.6%
zero_trust Execute 429 3.6%
harden_kernel Execute 426 3.6%
malware Execute 410 3.4%
integrity Write 399 3.3%
backup Write 353 2.9%
vuln_manage Execute 295 2.5%
secrets Read 289 2.4%
waf_manage Execute 248 2.1%
patch Write 245 2.0%
dns_security Read 239 2.0%
sudo_session Execute 219 1.8%
threat_intel Write 219 1.8%
supply_chain Write 209 1.7%
ebpf Execute 208 1.7%
honeypot_manage Execute 203 1.7%
app_harden Execute 193 1.6%
api_security Read 183 1.5%
process_security Write 174 1.5%
cloud_security Read 149 1.2%
wireless_security Execute 138 1.2%

Your agent uses a handful of these tools. It pays for all 31.

You don't need all 31 of those definitions in the window. PolicyLayer is an MCP gateway that sits in front of Defense: only the tools you grant are exposed to the agent, the rest never load. A smaller window means a sharper agent — less noise when it picks a tool — and every request costs less:

Grant scopeDefinition costReduction
All 31 tools (no gateway) 11,976 tokens
3 granted tools ~1,159 tokens −90%
5 granted tools ~1,932 tokens −84%
10 granted tools ~3,863 tokens −68%
  1. Create a free account and register Defense — nothing to install.
  2. Grant only the tools you use — ungranted definitions never enter the context window.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
CUT DEFENSE TOKEN COST →

Instant setup, no code required.

Defense token-cost questions.

How many tokens does the Defense MCP server use?+

Its 31 tool definitions total 11,976 tokens — 6.0% of a 200k context window — measured with tiktoken o200k_base over the serialised tools/list payload. Exact counts vary slightly by client and model.

Why does Defense consume tokens before I send a message?+

MCP clients load every connected server's tool definitions — name, description, and input schema — into the model's context so it knows what it can call. That payload is charged against your context window on every request, whether or not a tool is used.

How do I reduce Defense's token usage?+

Expose fewer tools. A PolicyLayer grant scopes Defense to only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. A grant of 3 typical tools costs roughly 1,159 tokens, a 90% reduction.

Does deferred tool loading fix this?+

Partially, in some clients. Claude Code defers MCP tool schemas behind a tool-search step by default, and VS Code has experimental grouping — but you still pay tokens per search and reload, and Cursor, Windsurf and Gemini CLI load definitions upfront. Reducing the exposed tool set cuts the cost in every client.

How these numbers were measured.

01
Serialisation

Each tool is serialised as a tools/list entry — name, description, input schema — from the schemas in the PolicyLayer scan database. Clients differ slightly in framing, so treat counts as close estimates.

02
Tokeniser

tiktoken o200k_base (GPT-4o/o-series). Anthropic's current tokeniser isn't published, so Claude's exact counts will differ; for English text and JSON schemas the totals are close enough to treat these as estimates.

03
Deferred loading

Some clients now defer schema loading (Claude Code's tool search; VS Code experimental grouping). You still pay per search and reload — and Cursor, Windsurf and Gemini CLI load everything upfront.

Computed 23-08-2026 from the PolicyLayer scan database over all 31 catalogued Defense tools. Counts refresh with every site build.

Expose only the tools you use — the rest never enter your context.

A PolicyLayer grant scopes Defense to the tools you actually allow. Ungranted definitions never load, and every call that does run is checked against policy first.

Instant setup, no code required.

46,500+ MCP servers and 515,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.