drive-relay-mcp
Uploads a file that already exists on a persona container's local disk to Microsoft OneDrive/Graph without round-tripping the bytes through an MCP tool-call argument.
README
drive-relay-mcp
Uploads a file that already exists on a persona container's local disk to Microsoft OneDrive/Graph — without round-tripping the bytes through an MCP tool-call argument.
Why this exists
Every other Graph upload path in this fleet (ms-mcp's upload_file /
upload_large_file) requires the full file content as base64 inside the
JSON tool-call argument. That has a hard ceiling (~60KB) on the size an LLM
can practically emit as output tokens — well below what a scanned receipt or
generated PDF needs. ms-mcp's save_attachment_to_drive solves this for
Microsoft Graph mail attachments (fetched server-side, never touching an
LLM argument) — but that only works when the source is a Graph attachment
(message_id + attachment_id). It cannot help a file that only exists on a
persona container's local disk (e.g. a receipt photo converted to PDF).
This service closes that gap: given a small filename reference (not file
content), it reads the file directly off a shared host directory and uploads
it via a Graph chunked-upload session — the same mechanism save_attachment_to_drive
uses, just sourced from local disk instead of a Graph attachment fetch.
Architecture
- Shared host directory:
/home/admin/hermes-shared-uploads/<persona_key>/is bind-mounted into each persona's Docker container at/data/shared-uploads. This service (running natively on the same host asms-mcp, via systemd) reads the same host path directly — no extra Docker networking needed. - Tool surface: one tool,
upload_local_file(file_name, folder_path, target_file_name?, confirm, idempotency_key?, keep_source?).file_nameis a filename only — no path separators, no subdirectories. The server resolves it strictly to<shared-root>/<persona_key-from-JWT>/<file_name>, wherepersona_keycomes from the authenticated gateway JWT, never a caller-supplied field. Seesrc/utils/safe-path.tsfor the symlink-escape hardening (a persona container runs as root and could otherwise plant a symlink pointing at an arbitrary host file). - Auth: ported from
ms-mcp's proven gateway-JWT + persona-scoping stack (src/auth/), trimmed to a singleuploads: booleancapability. Runs inenforcemode from day one (no off/shadow rollout ramp — this is a new service with no legacy unauthenticated traffic to protect). - Cleanup: deletes the source file on successful upload by default
(
keep_source: trueto opt out), plus an hourly TTL sweep of anything left behind by a failed/abandoned upload.
Setup
pnpm install
cp .env.example .env # fill in AZURE_TENANT_ID, AZURE_CLIENT_ID, GATEWAY_ISSUER, AUTH_TOKEN, BOOT_AUTH_TOKEN
pnpm build
pnpm auth # one-time interactive device-code sign-in (per deployment identity)
pnpm start # or: systemd unit, see systemd/drive-relay-mcp.service
config/persona-scopes.json is the fail-closed allowlist — a persona absent
from this file gets 403 Forbidden regardless of JWT validity.
Development
pnpm test:coverage
pnpm lint
pnpm typecheck
pnpm build
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.