MCP Router
Extensible MCP server that aggregates multiple backends (email, browser, todoist, etc.) behind a single endpoint, with secure deployment via Cloudflare Tunnel and Workers.
README
MCP Router
Extensible MCP server that aggregates multiple backends behind a single endpoint.
Architecture
Claude → CF Worker (OAuth) → Workers VPC → CF Tunnel → MCP Router → [Backends]
│ ↓
(private backbone) email backend → ProtonMail Bridge
(add more backends here)
Security: No public DNS exposure. Traffic flows through Cloudflare's private network via Workers VPC binding to a Cloudflare Tunnel with no public hostname.
Quick Start
1. Clone and install
curl -LsSf https://astral.sh/uv/install.sh | sh
git clone https://github.com/marklubin/mcp-email-server.git mcp-infrastructure
cd mcp-infrastructure
2. Configure
cp .env.example .env
# Edit .env with your credentials
3. ProtonMail Bridge (one-time)
protonmail-bridge --cli
# > login
# > info (note the bridge password)
4. Run
uv run python router/server.py
Or with systemd:
./setup.sh
sudo systemctl enable --now mcp-router@$USER
5. Set up Cloudflare Tunnel (for private backend)
cloudflared tunnel login
cloudflared tunnel create mcp-router
# Configure ~/.cloudflared/config.yml (see cloudflare/tunnel-config.yml.example)
sudo systemctl enable --now cloudflared
6. Create Workers VPC Service
In Cloudflare Dashboard → Workers & Pages → Workers VPC:
- Create service:
mcp-router-vpc - Select tunnel:
mcp-router - Target:
http://127.0.0.1:8080
7. Deploy Worker
cd cloudflare/worker && npx wrangler deploy
Deployment
The canonical deployed instance runs on oxnard as the systemd unit mcp-router@mark.service.
Steady-state flow:
- Edit code locally on a dev machine (clone of this repo).
- Commit and push to
origin/master. - From the local clone, run
./scripts/deploy.sh— pushes (if needed), SSHes to the remote, runsgit pull, and restarts the service. - If dependencies changed (
pyproject.toml/uv.lock), deploy.sh'suv synckeeps the venv in sync. If it doesn't, restart will still pick up the new deps on nextuv run.
Do not edit code directly on oxnard. The repo is the source of truth — changes made only on the box will drift and get lost. If you must hotpatch in an emergency, copy the fix back into the repo and commit it before doing anything else.
Override the deploy target with MCP_REMOTE=hostname ./scripts/deploy.sh.
Backends
Each backend lives in router/backends/ and exposes tools under its mount prefix.
| Backend | Prefix | Purpose |
|---|---|---|
email |
email_ |
ProtonMail Bridge — list/search/get/send |
browser |
browser_ |
Playwright-over-CDP browser automation |
todoist |
todoist_ |
Todoist tasks/projects |
notifications |
notify_ |
Push notifications + inbox |
discord |
discord_ |
Discord (via user token) |
memory |
memory_ |
Agent memory store |
twitter |
twitter_ |
Twitter read via twitterapi.io |
web |
web_ |
Web search + contents via Exa |
Also available but not currently mounted in server.py:
unified_memory.py— proxies all synix MCP tools from the agent-mesh server on salinas. Wire it up by importing + mounting if you want to replace or augmentmemory.
Email Backend (prefix: email_)
| Tool | Description |
|---|---|
email_list_emails(mailbox, limit) |
List recent emails |
email_search_emails(query, mailbox, limit, search_body) |
Search by subject, sender, or body |
email_get_email(message_id, mailbox) |
Get full email content |
email_send_email(to, subject, body) |
Send email |
Web Backend (prefix: web_)
Uses Exa under the hood. Free tier: 1,000 searches/month.
| Tool | Description |
|---|---|
web_search(query, num_results, search_type, include_text, include_domains, exclude_domains) |
Web search; optional inline text excerpts |
web_get_contents(urls, max_chars) |
Fetch clean text for one or more URLs |
For detailed signatures of other backends, read the source — each tool's docstring is its contract.
Router
| Tool | Description |
|---|---|
health() |
Health check with backend status |
logs(lines, service) |
Tail service logs (mcp-router or cloudflared) |
Adding New Backends
- Create
router/backends/yourbackend.py:
from fastmcp import FastMCP
mcp = FastMCP('yourbackend')
@mcp.tool()
async def your_tool(arg: str) -> dict:
"""Your tool description."""
return {'result': 'value'}
- Mount in
router/server.py:
from backends import yourbackend
router.mount(yourbackend.mcp, prefix='yourbackend')
Also append the prefix to the health() backend list.
-
If the backend needs secrets, add them to
.env.exampleand.env. -
Commit and run
./scripts/deploy.sh. Tools appear asyourbackend_your_tool.
Claude Config
{
"mcpServers": {
"router": {
"url": "https://mcp-router-proxy.melubin.workers.dev/mcp",
"transport": "sse"
}
}
}
Environment Variables
See .env.example for the full list. Required for core operation:
MCP_SECRET= # API key for auth from CF Worker
ROUTER_HOST=127.0.0.1
ROUTER_PORT=8080
PROTON_BRIDGE_HOST=127.0.0.1
PROTON_BRIDGE_IMAP_PORT=1143
PROTON_BRIDGE_SMTP_PORT=1025
PROTON_BRIDGE_USER=you@proton.me
PROTON_BRIDGE_PASSWORD=bridge-password
Backend-specific keys (only required if the backend is mounted):
EXA_API_KEY= # web search
TODOIST_API_TOKEN= # todoist
TWITTERAPI_IO_KEY= # twitter
DISCORD_TOKEN= # discord
MESH_SERVER_URL= # memory
MESH_TOKEN= # memory
AGENT_MESH_MCP_URL= # unified_memory (if mounted)
Project Structure
mcp-infrastructure/
├── router/
│ ├── server.py # Main router, mounts backends
│ └── backends/
│ ├── __init__.py
│ ├── email.py # ProtonMail
│ ├── browser.py # Playwright over CDP
│ ├── todoist.py # Todoist
│ ├── notifications.py # Push/inbox
│ ├── discord.py # Discord user-token
│ ├── memory.py # Agent memory
│ ├── twitter.py # Twitter (twitterapi.io)
│ ├── web.py # Web search (Exa)
│ └── unified_memory.py # Synix proxy (not mounted by default)
├── services/
│ ├── mcp-router.service # systemd template for router
│ ├── cloudflared.service # systemd service for tunnel
│ ├── headless-brave.service # headless browser
│ └── protonmail-bridge.service # ProtonMail Bridge
├── cloudflare/
│ ├── tunnel-config.yml.example # Tunnel config template
│ └── worker/ # CF Worker for OAuth + VPC proxy
├── scripts/
│ ├── deploy.sh # Push and deploy to remote
│ ├── logs.sh # View service logs
│ ├── status.sh # Check service status
│ ├── tunnel.sh # Manage Cloudflare Tunnel
│ ├── test-email.sh # Test email tools
│ ├── test.sh # Run tests
│ ├── browser-connect.sh # Connect to CDP browser
│ ├── run-headless-brave.sh # Launch headless Brave
│ ├── run-headless-firefox.sh # Launch headless Firefox + VNC
│ └── notify-check.sh # Notification health check
├── setup.sh # One-shot setup script
├── pyproject.toml # Python dependencies
└── .env.example # Config template
Management Scripts
| Script | Purpose |
|---|---|
scripts/deploy.sh |
Push and deploy to remote (respects MCP_REMOTE env var) |
scripts/logs.sh [n] |
View last n log lines |
scripts/status.sh |
Check service status |
scripts/tunnel.sh [status|logs|restart] |
Manage tunnel |
scripts/test-email.sh |
Test email tools |
scripts/test.sh |
Run tests |
scripts/browser-connect.sh |
Connect to the CDP-exposed browser |
scripts/run-headless-brave.sh |
Launch headless Brave with CDP |
scripts/run-headless-firefox.sh |
Launch headless Firefox + VNC on :99 |
scripts/notify-check.sh |
Notification backend health check |
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.