Team-governed Fentaris Proxy
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Team-governed Fentaris Proxylist my available tools and fetch the latest release notes"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Team-governed Fentaris proxy
A runnable TypeScript example of a shared MCP endpoint with API-key authentication, group policies, remote tools, local tools, and structured JSON logs. Built with Fentaris.
This project is maintained separately from the Fentaris SDK repository. It uses
published @fentaris/core and @fentaris/cli packages and has its own lockfile.
What you will run
The proxy listens on http://127.0.0.1:4100/mcp and combines two namespaces:
specification: a public remote MCP server athttps://mcp.specification.website/mcp.workspace: local tools implemented insrc/index.tswithapp.local(...).
API-key user | Group | Visible and callable tools |
|
|
|
|
| Reader access plus |
Policy applies to both tool discovery and execution. Calling a hidden tool directly is denied before its handler runs. Logs include subject and group tags.
Related MCP server: AISIX AI Gateway
Prerequisites
Node.js 24 or newer.
pnpm 11.
Network access for dependency installation and the optional public upstream.
The local workspace tools work even when the remote upstream is unavailable.
Quick start
git clone https://github.com/Fentaris/team-governed-proxy.git
cd team-governed-proxy
pnpm install --frozen-lockfile
pnpm build
pnpm check
pnpm run doctor
pnpm exec fentaris auth api-key add reader --generate --non-interactive
pnpm exec fentaris auth api-key add maintainer --generate --non-interactive
pnpm devSave both generated client keys when printed. The following sections explain credential storage and how to verify access as each user.
Install and validate
pnpm install --frozen-lockfile
pnpm build
pnpm check
pnpm run doctorAll four commands should exit successfully before provisioning local identity.
Provision API-key identities
Let the CLI generate a project-local encryption key in the ignored .env on
the first credential write:
pnpm exec fentaris auth api-key add reader --generate --non-interactive
pnpm exec fentaris auth api-key add maintainer --generate --non-interactiveSave each generated API key when it is printed; Fentaris stores only its hash.
For the smoke tests below, set READER_API_KEY or MAINTAINER_API_KEY in the
client shell without committing either value.
The encrypted .fentaris/credentials.enc.json file and encryption key are
local state and must not be committed. The committed
.fentaris/secrets.manifest.json contains schema only.
Start the proxy
pnpm devExpected startup output includes:
Proxy ready
Listening on: http://127.0.0.1:4100/mcpIn a second shell, export the same client API key used for the curl tests so
doctor can authenticate. The project script loads FENTARIS_AUTH_KEY from
.env automatically:
export FENTARIS_API_KEY="$READER_API_KEY"
pnpm exec fentaris doctor --runtime --non-interactiveFENTARIS_AUTH_KEY unlocks the local encrypted store; FENTARIS_API_KEY is
the raw client key sent as x-fentaris-api-key. Without the latter, runtime
probing returns HTTP 401 on this example.
Expected result: the MCP initialize check passes for
http://127.0.0.1:4100/mcp.
Test an authenticated MCP session
Initialize as the reader and save the returned session header:
curl -sS -D reader-headers.txt -o reader-initialize.json \
-X POST http://127.0.0.1:4100/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H "x-fentaris-api-key: $READER_API_KEY" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"curl","version":"1"}}}'
READER_SESSION="$(grep -i '^mcp-session-id:' reader-headers.txt | tr -d '\r' | cut -d' ' -f2)"Send the initialized notification and list visible tools:
curl -sS -X POST http://127.0.0.1:4100/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H "x-fentaris-api-key: $READER_API_KEY" \
-H "mcp-session-id: $READER_SESSION" \
-d '{"jsonrpc":"2.0","method":"notifications/initialized"}'
curl -sS -X POST http://127.0.0.1:4100/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H "x-fentaris-api-key: $READER_API_KEY" \
-H "mcp-session-id: $READER_SESSION" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'The reader result includes workspace__status and hides
workspace__release_notes. Remote specification__* tools appear when the
public upstream is reachable.
Calling the hidden maintainer tool directly as the reader is denied before its local handler runs:
curl -sS -X POST http://127.0.0.1:4100/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H "x-fentaris-api-key: $READER_API_KEY" \
-H "mcp-session-id: $READER_SESSION" \
-d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"workspace__release_notes","arguments":{}}}'Expected result: the MCP tool result has isError: true, with Fentaris error
code -32030 and denial reason not-permitted in _meta.error. Repeat the
session with MAINTAINER_API_KEY; the maintainer tool is listed and returns:
Release notes are visible to maintainers only.You can also use MCP Inspector:
npx @modelcontextprotocol/inspectorPoint it at http://127.0.0.1:4100/mcp and set the
x-fentaris-api-key request header.
Project layout
File | Purpose |
| Users, groups, policies, upstream, local tools, and log tags |
| Endpoint, entrypoint, and local auth directory |
| Committed upstream-secret schema (empty for this example) |
| Locked dependencies for reproducible installs |
| Strict TypeScript configuration |
pnpm dev runs the TypeScript entrypoint; pnpm build compiles it and pnpm start
runs the compiled application. Both start commands load the local .env file.
Troubleshooting
HTTP 401: send the raw client API key in
x-fentaris-api-key.FENTARIS_AUTH_KEYunlocks the credential store; it is not a client API key.Credentials cannot be decrypted: use the encryption key that created the local store. Check
.envor an explicitly exportedFENTARIS_AUTH_KEY.Remote tools are missing: check connectivity to the public upstream. Verify
workspace__statusfirst to test the local proxy independently.Port 4100 is occupied: stop the other process or change
portinfentaris.json.Doctor warns about API-key hashes not listed in the manifest: the manifest describes upstream secrets; the API-key hashes live separately in the encrypted auth store. This example has no upstream credentials.
Scope and extensions
This example demonstrates two groups, one remote upstream, local tools, API-key identity, policy filtering, and JSON logging. The curl checks above are manual. Rate limits, Telegram approvals, three remote upstreams, and automated smoke checks are future extensions. Configure network controls before making the localhost endpoint accessible to other machines.
Documentation and license
MIT licensed; see LICENSE.txt.
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.1MIT

AISIX AI Gatewayofficial
AlicenseAqualityAmaintenanceSelf-hosted MCP gateway that registers upstream MCP servers and fronts them behind one governed Streamable HTTP endpoint: per-tool access control by caller API key, guardrails over tool arguments and results, rate limits, and usage logs. The same Rust gateway also proxies LLM and A2A agent traffic.41173Apache 2.0- AlicenseNot gradedqualityBmaintenanceEnables clients to access multiple backend MCP servers through a single endpoint, with OAuth 2.1 authorization, namespaced tools, and secure credential management.2MIT
- AlicenseNot gradedqualityAmaintenanceProvides a single MCP endpoint that dynamically discovers, routes, policy-checks, and executes hundreds of MCP tools from any agent, with optional LLM-based routing.21 npm1Apache 2.0