ServerMCP
Model Context Protocol gateway

Give your AI agent access to your servers. Nothing else.

ServerMCP brokers MCP traffic between agents and the servers you own. Connect a node in one command, then let agents call read tools and policy-gated actions - fail-closed by default, audited end to end, with secrets redacted on the server before they ever leave it.

quickstart

# 1. Install the node on your server (runs as an unprivileged user)

$ curl -fsSL https://your-gateway/install/<token> | sudo bash

# 2. Point your agent at the MCP endpoint

$ curl https://your-gateway/mcp \

-H "Authorization: Bearer <token>" \

-d '{"method":"tools/list"}'

policy-checked · redacted · audited

Built for production servers

A thin node. A smart gateway.

All policy lives in the gateway - the node only enforces hard invariants and can't be re-opened from the centre.

Layered policy

Defaults flow to groups, servers and sites. Every call is evaluated fail-closed, with the node as the last line of defence.

Secrets never leak

Values are redacted on the node before they are logged or sent to the gateway; .env values are masked.

Human approvals

Gated writes return pending_approval and wait for an operator to approve, deny or let it expire.

Fixed action allowlist

No free shell. run_action executes a fixed enum of operations; privileged work drops to the site's user.

Metrics & audit

Rolled-up resource metrics sit beside a complete, searchable audit trail for every tool call.

Signed self-updates

Releases are cross-compiled and ed25519-signed; nodes verify and update themselves, with rollback on demand.

From zero to connected

How it works

  1. 1

    Enroll the node

    One command installs the Go node, generates its keypair via CSR and opens a mutual-TLS WebSocket to the relay.

  2. 2

    Set policy

    Allow tools per group, server or site. Reads are scoped by the credential grant; writes are deny-by-default.

  3. 3

    Agent calls MCP

    The agent talks standard MCP over HTTP. The gateway dispatches to the right node with site context.

  4. 4

    Every call is audited

    Results return redacted, and the full request lands in an audit trail you can search and retain.

Defence in depth

Safe by default, not by convention

An invalid, revoked or expired credential gets a 401 - there is no permissive fallback. The node enforces its own invariants even if the centre were compromised.

openat2 path-jail SELECT-only SQL read-only mounts sudoers-locked helper no root node
node - invariants
Path access
jailed (openat2)
Filesystem
read-only
Database
SELECT-only
Actions
fixed enum
Secrets
redacted on node

Connect your first server in one command

Read the generic agent instructions at /how-to, or sign in to issue a scoped MCP key.