safe-mcp-bridge-v2

safe-mcp-bridge-v2

A fail-closed policy boundary that translates local stdio MCP clients to authenticated Streamable HTTP servers, enforcing allowlists or read-only modes and redacting credentials from audit trails.

Category
Visit Server

README

safe-mcp-bridge-v2

A fail-closed policy boundary between local stdio MCP clients and authenticated Streamable HTTP servers.

CI MCP License

MCP's authorization standard answers who may connect. This bridge adds a local enforcement layer for what an agent may call and what must never leak through the bridge's logs or output.

It translates newline-delimited stdio JSON-RPC into MCP 2026-07-28 Streamable HTTP, injects credentials only at the outbound boundary, mirrors required routing metadata into HTTP headers, applies a local tool policy before network access, and fails closed on secret-shaped upstream output.

Why this still exists after MCP OAuth

OAuth, CIMD, scopes, and protected-resource metadata are essential remote authorization primitives. They do not replace:

  • per-agent local allowlists;
  • a conservative read-only mode;
  • proof that blocked calls never reach the upstream server;
  • redacted audit trails;
  • leak fixtures for wrapper and gateway behavior;
  • env-to-header credential isolation for local stdio clients.

safe-mcp-bridge-v2 is deliberately a narrow safety boundary, not another general MCP platform.

MCP 2026-07-28 support

  • stateless, self-describing requests with _meta protocol/client fields;
  • required MCP-Protocol-Version, Mcp-Method, and Mcp-Name headers;
  • spec Base64 sentinel encoding for non-ASCII or unsafe header values;
  • configured Mcp-Param-* mirroring for x-mcp-header deployments;
  • application/json and request-scoped text/event-stream responses;
  • transparent MRTR InputRequiredResult pass-through;
  • 202 Accepted notification handling;
  • explicit rejection of legacy session initialization;
  • fail-closed header/body and protocol-version checks.

See Compatibility for the exact support boundary.

Quick start

git clone https://github.com/efe-arv/safe-mcp-bridge-v2.git
cd safe-mcp-bridge-v2
uv sync --extra dev
cp examples/modern-read-only.yaml bridge.yaml

Set the credential named by auth.env without placing it in YAML:

export EXAMPLE_MCP_TOKEN='use-your-secret-manager-here'
uv run safe-mcp-bridge-v2 doctor bridge.yaml
uv run safe-mcp-bridge-v2 run bridge.yaml

Example stdio input:

{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"memory.search","arguments":{"query":"status"}}}

The bridge adds modern MCP metadata and sends headers equivalent to:

MCP-Protocol-Version: 2026-07-28
Mcp-Method: tools/call
Mcp-Name: memory.search
Authorization: Bearer <injected at runtime>

Credentials are never included in audit records.

Policy modes

Allowlist

Only explicitly named tools may cross the network boundary:

policy:
  mode: allowlist
  allow_tools:
    - memory.search
    - memory.read

Read-only

Blocks tool names containing write-shaped segments such as create, delete, send, update, or write:

policy:
  mode: read_only

Read-only name matching is a conservative local guard, not semantic proof. Prefer an allowlist for consequential environments.

x-mcp-header deployments

The 2026-07-28 HTTP binding can mirror selected primitive tool arguments into Mcp-Param-* headers. Configure mappings learned from your server's tool schema:

protocol:
  custom_tool_headers:
    execute_sql:
      region: Region
      tenant.id: Tenant

The bridge performs spec-compliant primitive conversion and Base64 sentinel encoding. Automatic schema discovery is intentionally not in 0.1.0; mappings are explicit and auditable.

Commands

safe-mcp-bridge-v2 doctor CONFIG
safe-mcp-bridge-v2 run CONFIG
safe-mcp-bridge-v2 policy-check CONFIG METHOD [--tool TOOL]
safe-mcp-bridge-v2 leak-scan PATH

Verification

uv run ruff check .
uv run mypy
uv run pytest

CI runs the same checks on Python 3.11 and 3.12, plus dependency and secret scanning.

Security model

Read SECURITY.md and Threat model before deployment. Important boundaries:

  • redaction is defense in depth, not encryption;
  • upstream authorization and data minimization remain mandatory;
  • an allowlist cannot make a malicious upstream safe;
  • this bridge does not terminate an OAuth browser flow in 0.1.0;
  • legacy stateful MCP sessions require a separate compatibility adapter;
  • local process compromise remains outside the bridge's protection boundary.

Origin

This is a clean second-generation implementation of the original private safe-mcp-bridge, rebuilt for the MCP 2026-07-28 stateless protocol. Created by Efe Büken / Arven Digital.

License

Apache-2.0. See LICENSE.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured