Skip to main content
Glama

nodus-mcp

nodus-mcp is the Research Workbench's thin stdio gateway to the bearer-authenticated Streamable HTTP MCP server built into Nodus. It exposes only the architect-approved tool allowlist and contains no graph logic or graph cache.

The stdio entry supports MCP 2026-07-28's stateless server/discover lifecycle and legacy initialize-based clients. The upstream HTTP client probes for the same modern lifecycle and falls back to legacy initialization when the installed Nodus build needs it. Upstream-derived tool catalogs use a short private cache lifetime.

Setup

npm install
npm run build
npm test

Set NODUS_MCP_TOKEN after enabling MCP in Nodus settings, or set NODUS_MCP_TOKEN_FILE to a JSON file containing a token field. The upstream URL defaults to http://127.0.0.1:4319/mcp and can be changed with NODUS_MCP_URL. Only plain-HTTP URLs using the exact loopback hostnames 127.0.0.1, localhost, or [::1] and the exact /mcp path are accepted. Userinfo is rejected and redirects are never followed.

The gateway mirrors schemas from upstream tools/list at runtime for only the 30 contracted tools. It does not use Nodus's separate port-4321 Zotero bridge. When Nodus MCP is disabled, nodus_gateway_health remains available and reports the exact enable step; no empty graph result is fabricated.

npm test uses an in-process mock Streamable HTTP MCP server and covers a closed port, bad bearer token, and allowlist drift.

License: MIT. See LICENSE.

Available Tools

1 tool
nodus_gateway_healthCheck Nodus gateway healthA
Read-only

Check whether the Nodus MCP server is reachable and authenticated. Never errors.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the readOnlyHint and destructiveHint annotations, the description adds the behavioral guarantee 'Never errors.' This is useful context that tells the agent the call will not fail at the protocol level, though it does not explain what the success response contains.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single front-loaded sentence that conveys purpose and a key behavioral trait without filler. Every word earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter health check with no output schema, the description adequately conveys what is being checked and that it never errors. It stops short of describing the return value, which would be helpful but is not critical given the tool's simplicity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters, so the baseline is 4. The description appropriately does not attempt to document nonexistent parameters, and no further parameter clarification is needed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Check') and names both the resource ('Nodus MCP server') and the two conditions being verified ('reachable and authenticated'). It clearly distinguishes the tool's purpose even without sibling tools to compare against.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The intended use as a health check is implied by the description, but there is no explicit statement of when to call it (e.g., before other Nodus operations) or any alternatives. Since there are no siblings, this is acceptable but still leaves usage timing to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.1.0
    • First observednodus_gateway_health

TDQS

A3.8/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of confusing it with other operations. Its purpose as a health/readiness check is clear and unambiguous.

Naming Consistency5/5

The single tool name is clear, descriptive, and follows a consistent hierarchical pattern with the server prefix. There are no mixed conventions to cause confusion.

Tool Count1/5

A lone health-check tool is a trivial surface for an MCP server. Even as a gateway utility, it provides almost no functional value and appears extremely under-scoped.

Completeness1/5

The server exposes only a health check, so no substantive domain operations exist. Any real workflow would dead-end immediately after confirming reachability.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides a secure, token-authenticated command execution tool over MCP Streamable HTTP, with a default-deny allowlist and shell metacharacter rejection.
    6 npm
    1
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Exposes a verified tool registry (calculator, sandboxed file read, web fetch) over MCP stdio, enabling any MCP-capable client to reuse the same tools from the inspectable ReAct loop.
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Acts as a stdio-to-HTTP proxy for Modus Brain, enabling MCP-compatible AI clients to access an organization's knowledge base in ModusOp.
    23 npm
    Cryptographic Autonomy 1.0 (Combined Work Exception)
  • F
    license
    A
    quality
    B
    maintenance
    A single local MCP gateway for Neo4j that exposes both proxied generic Neo4j tools (schema, Cypher, GDS) and custom YAML-defined use-case tools behind one stdio endpoint.
    3
    -