nexus-mcp
An enterprise-grade MCP gateway and security router that gives AI agents secure, observable access to internal corporate knowledge through hybrid vector+BM25 retrieval, RBAC, and prompt injection protection.
README
Nexus-MCP ā”
<p align="center"> <strong>Production Enterprise MCP Gateway for Secure, Observable Agent Knowledge Access</strong> </p>
<p align="center"> <a href="https://www.python.org/downloads/release/python-3110/"><img alt="Python 3.11+" src="https://img.shields.io/badge/python-3.11%2B-blue.svg"></a> <a href="https://modelcontextprotocol.io"><img alt="Anthropic MCP" src="https://img.shields.io/badge/Anthropic%20MCP-v1.0-orange.svg"></a> <a href="https://opensource.org/licenses/MIT"><img alt="License: MIT" src="https://img.shields.io/badge/License-MIT-yellow.svg"></a> <a href="https://prometheus.io"><img alt="Prometheus" src="https://img.shields.io/badge/Prometheus-Telemetry-red.svg"></a> </p>
Overview
Nexus-MCP is an enterprise-grade Model Context Protocol (MCP) gateway and security router that gives AI agents (Claude Desktop, Cursor, LangGraph) secure, observable access to internal corporate knowledge.
Raw MCP implementations lack multi-tenancy, dynamic RBAC, tool injection protection, and audit logs. Nexus-MCP bridges this gap by acting as a zero-trust security router and document intelligence server.
š The Enterprise Golden Path
MCP Client āā> Authentication & Tenant Context āā> RBAC Scope Check
ā
ā¼
Prometheus & OTel āāā Response āāā Schema Extraction āāā Hybrid RAG (Vector+BM25)
Key Features
- ā” Official Anthropic MCP SDK Integration: Built natively on Anthropic's
mcpspecification supporting STDIO & SSE JSON-RPC transports. - š Multi-Tenant & ACL Isolation: Strictly isolates document search and schema extraction per
tenant_idand useracl_groups. - š”ļø Security Router & Prompt Injection Sanitizer: Prevents prompt/tool injection attacks (
DROP TABLE,IGNORE INSTRUCTIONS). - š Hybrid Vector + BM25 Retrieval: Reciprocal Rank Fusion (RRF) combining dense vector similarity and BM25 term frequency.
- š Prometheus & OpenTelemetry Observability: Tracks tool execution counts, p95/p99 latency, and token expenditure.
Quick Start
Installation
pip install nexus-mcp
Or install locally for development:
git clone https://github.com/JasleenSingh/nexus-mcp.git
cd nexus-mcp
pip install -e .
Code Example: Golden Path Demo
Run the included commercial contract intelligence demo:
python examples/contract_intelligence_demo.py
Output:
š Starting Nexus-MCP Enterprise Golden Path Demo...
ā
Ingested document into 4 hierarchical chunks for tenant 'tenant-acme-corp'.
š Executing Tool [doc_hybrid_search]...
Found 1 matching chunks with Hybrid Vector + BM25 search.
š Executing Tool [doc_extract_schema]...
Extracted Agreement Schema (3 fields):
⢠payment_terms: Net 30 days (confidence: 0.92)
⢠total_contract_value: $3,500,000.00 (confidence: 0.88)
⢠governing_law: State of Delaware (confidence: 0.90)
š Executing Tool [system_health_telemetry]...
System Health: healthy
⨠Nexus-MCP Golden Path Execution Completed Successfully!
Running Server & CLI
# Start Nexus-MCP server over STDIO transport
nexus-mcp serve --transport stdio
Running Tests & Benchmarks
# Run complete unit, integration, and security test suite
pytest tests/
# Run retrieval accuracy benchmarks (Recall@K & MRR)
pytest tests/integration/test_retrieval_benchmarks.py -v
Project Structure
nexus-mcp/
āāā src/nexus_mcp/
ā āāā models/ # Pydantic v2 domain schemas (TenantContext, DocumentChunk, SearchQuery)
ā āāā document_processor/ # Hierarchical chunker, schema extractor, and Hybrid RAG retriever
ā āāā security/ # RBAC scope validator and input injection sanitizer
ā āāā observability/ # Prometheus metrics and OpenTelemetry trace span exporters
ā āāā mcp_server/ # Official Anthropic MCP Server & tool registrations
ā āāā cli/ # Rich CLI interface (nexus-mcp serve)
āāā tests/
ā āāā unit/ # Unit tests (chunker, retriever, schemas, observability)
ā āāā integration/ # MCP JSON-RPC protocol & retrieval benchmarks
ā āāā security/ # Adversarial security tests (cross-tenant & prompt injection)
āāā examples/ # Contract intelligence demo & sample commercial agreements
āāā docs/ # System architecture & tool specs
āāā pyproject.toml
āāā README.md
License
Distributed under the MIT License.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.