Give your AI agent access to your servers. Nothing else.
ServerMCP brokers MCP traffic between agents and the servers you own. Connect a node in one command, then let agents call read tools and policy-gated actions - fail-closed by default, audited end to end, with secrets redacted on the server before they ever leave it.
# 1. Install the node on your server (runs as an unprivileged user)
$ curl -fsSL https://your-gateway/install/<token> | sudo bash
# 2. Point your agent at the MCP endpoint
$ curl https://your-gateway/mcp \
-H "Authorization: Bearer <token>" \
-d '{"method":"tools/list"}'
Built for production servers
A thin node. A smart gateway.
All policy lives in the gateway - the node only enforces hard invariants and can't be re-opened from the centre.
Layered policy
Defaults flow to groups, servers and sites. Every call is evaluated fail-closed, with the node as the last line of defence.
Secrets never leak
Values are redacted on the node before they are logged or sent to the gateway; .env values are masked.
Human approvals
Gated writes return pending_approval and wait for an operator to approve, deny or let it expire.
Fixed action allowlist
No free shell. run_action executes a fixed enum of operations; privileged work drops to the site's user.
Metrics & audit
Rolled-up resource metrics sit beside a complete, searchable audit trail for every tool call.
Signed self-updates
Releases are cross-compiled and ed25519-signed; nodes verify and update themselves, with rollback on demand.
From zero to connected
How it works
-
1
Enroll the node
One command installs the Go node, generates its keypair via CSR and opens a mutual-TLS WebSocket to the relay.
-
2
Set policy
Allow tools per group, server or site. Reads are scoped by the credential grant; writes are deny-by-default.
-
3
Agent calls MCP
The agent talks standard MCP over HTTP. The gateway dispatches to the right node with site context.
-
4
Every call is audited
Results return redacted, and the full request lands in an audit trail you can search and retain.
Defence in depth
Safe by default, not by convention
An invalid, revoked or expired credential gets a 401 - there is no permissive fallback. The node enforces its own invariants even if the centre were compromised.
- Path access
- jailed (openat2)
- Filesystem
- read-only
- Database
- SELECT-only
- Actions
- fixed enum
- Secrets
- redacted on node
Connect your first server in one command
Read the generic agent instructions at /how-to, or sign in to issue a scoped MCP key.