Skip to main content
Glama
Devarinti9

Enterprise MCP Gateway and Tool Registry

by Devarinti9
README.md
# Enterprise MCP Gateway and AI Tool Registry

Secure tool-discovery and execution gateway for AI-agent integrations. The project combines a runnable FastAPI gateway with an optional standards-based MCP server entrypoint built with the official Python MCP SDK.

## Highlights
- JWT authentication with demo admin, developer, and viewer roles
- RBAC enforcement for tool execution and administrative operations
- Persistent tool registry and audit logs with SQLAlchemy
- Built-in calculator, summarizer, keyword extractor, and gateway-health tools
- Allowlisted HTTP tool registration for controlled external API integration
- Redis-backed rate limiting with an in-memory fallback
- Optional OpenTelemetry export to Jaeger
- Prometheus-style gateway metrics at `/metrics`
- REST endpoints for browser testing and an optional FastMCP Streamable HTTP server
- Automated tests and GitHub Actions CI

## Architecture
```text
AI Client / Developer
        |
        v
 FastAPI Gateway -----> JWT Auth + RBAC
        |
        +-----> Tool Registry -----> Built-in Tools
        |                     `----> Allowlisted HTTP Tools
        |
        +-----> Rate Limiter ------> Redis or in-memory fallback
        |
        +-----> Audit Store -------> SQLite quick start / PostgreSQL Docker mode
        |
        `-----> OpenTelemetry -----> Jaeger (optional)
```

## Quick Start
```bash
python -m venv .venv
source .venv/bin/activate
python -m pip install -r requirements-dev.txt
cp .env.example .env
python -m uvicorn app.main:app --host 0.0.0.0 --port 8000
```
Open `http://localhost:8000/docs`.

## Demo Accounts
| Username | Password | Role |
|---|---|---|
| `admin` | `admin123` | admin |
| `developer` | `developer123` | developer |
| `viewer` | `viewer123` | viewer |

These are intentionally demo-only credentials. Replace the identity layer before deployment.

## Run Tests
```bash
python -m pytest -q
```

## Optional Standards-Based MCP Server
```bash
python -m pip install -r requirements-mcp.txt
python mcp_server.py
```
Connect an MCP client or MCP Inspector to `http://localhost:8000/mcp`.

## Docker Compose
```bash
docker compose up --build
```
- API docs: `http://localhost:8000/docs`
- Jaeger UI: `http://localhost:16686`

## Documentation
See [`docs/`](./docs) for setup, architecture, API reference, MCP notes, and security considerations.

## Security Note
The REST gateway demonstrates authentication, authorization, rate limiting, auditing, and allowlisted outbound calls. The optional local MCP server is a separate SDK demonstration. A remote MCP deployment should use OAuth 2.1 resource-server protection and production identity infrastructure.