Skip to main content
Glama
Nagendda

MCP Tool Manager

by Nagendda

MCP Tool Manager

A production-hardened, AI-native tool registry and agent management system built on the Model Context Protocol (MCP).

Node.js License: MIT MCP Security


๐Ÿ“– Table of Contents

  1. What Is This?

  2. Architecture Overview

  3. Project Structure

  4. Quick Start

  5. Configuration Reference

  6. API Reference

  7. Implementation Plan

  8. Security Model

  9. Monitoring & Observability

  10. Roadmap

  11. Contributing


Related MCP server: mcp-tool-gateway

What Is This?

MCP Tool Manager is a dual-server platform that solves the hardest operational problems in AI-integrated tool systems:

Problem

Solution

LLMs burning context windows on huge API responses

Per-tool byte budget with graceful truncation signalling

Upstream API failures cascading to the LLM

Per-tool circuit breaker (CLOSED โ†’ OPEN โ†’ HALF-OPEN)

All data lost on server restart

Automatic periodic disk snapshots, restored on startup

Brute force / injection attacks on the API gateway

10-family threat detector + tiered rate limiting + IP auto-block

No way to trace a request end-to-end

X-Trace-ID header propagated across all layers and to upstream APIs

Tools/agents registered in volatile memory only

File-persisted call log + agent JSON configs + state snapshots


Architecture Overview

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                        MCP Tool Manager Platform                        โ”‚
โ”‚                                                                         โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚   Manager Server      โ”‚        โ”‚    Hardened MCP Server             โ”‚ โ”‚
โ”‚  โ”‚   src/server          โ”‚        โ”‚    mcp-server-project              โ”‚ โ”‚
โ”‚  โ”‚                       โ”‚        โ”‚                                    โ”‚ โ”‚
โ”‚  โ”‚  โ€ข REST API (CRUD)    โ”‚        โ”‚  โ€ข MCP Protocol endpoint           โ”‚ โ”‚
โ”‚  โ”‚  โ€ข JWT + API key auth โ”‚        โ”‚  โ€ข Agent API key auth + expiry     โ”‚ โ”‚
โ”‚  โ”‚  โ€ข Tool registry      โ”‚        โ”‚  โ€ข Circuit breaker per tool        โ”‚ โ”‚
โ”‚  โ”‚  โ€ข Agent management   โ”‚        โ”‚  โ€ข Retry + exponential backoff     โ”‚ โ”‚
โ”‚  โ”‚  โ€ข Credential vault   โ”‚        โ”‚  โ€ข Response cache (TTL per tool)   โ”‚ โ”‚
โ”‚  โ”‚  โ€ข Audit log          โ”‚        โ”‚  โ€ข Context window limiting         โ”‚ โ”‚
โ”‚  โ”‚  โ€ข State snapshots    โ”‚        โ”‚  โ€ข File-persisted call log         โ”‚ โ”‚
โ”‚  โ”‚  โ€ข WebSocket events   โ”‚        โ”‚  โ€ข 10-family threat detection      โ”‚ โ”‚
โ”‚  โ”‚  โ€ข Response cache     โ”‚        โ”‚  โ€ข Admin /metrics endpoint         โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚             โ”‚                                    โ”‚                       โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚   React Dashboard     โ”‚        โ”‚    Claude Desktop / LLM Agent      โ”‚ โ”‚
โ”‚  โ”‚   src/dashboard       โ”‚        โ”‚    (connects via MCP SDK)          โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚                                                                         โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚
โ”‚  โ”‚  Cross-cutting: X-Trace-ID ยท Rate Limiting ยท Helmet CSP ยท        โ”‚   โ”‚
โ”‚  โ”‚  Structured Logging ยท Connection Limit ยท Compression             โ”‚   โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Project Structure

mcp/
โ”œโ”€โ”€ .env.example                    # Template โ€” copy to .env and fill in values
โ”œโ”€โ”€ .gitignore                      # Excludes .env, node_modules, logs, snapshots
โ”œโ”€โ”€ package.json                    # Root scripts โ€” start both servers, CLI, tests
โ”œโ”€โ”€ README.md                       # This file
โ”œโ”€โ”€ REPORT.md                       # Full technical capability report
โ”œโ”€โ”€ CHANGELOG.md                    # Version history
โ”‚
โ”œโ”€โ”€ src/
โ”‚   โ”œโ”€โ”€ server/                     # Manager Server (REST API)
โ”‚   โ”‚   โ”œโ”€โ”€ index.js                # Entry point โ€” snapshot restore + server start
โ”‚   โ”‚   โ”œโ”€โ”€ app.js                  # Express app โ€” all middleware wired
โ”‚   โ”‚   โ”œโ”€โ”€ routes/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ tools.js            # CRUD + test execution for tools
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ agents.js           # Agent management + tool discovery
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ auth.js             # Login, register, API key management
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ credentials.js      # Encrypted credential vault
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ monitoring.js       # Stats, audit log, cache, snapshot status
โ”‚   โ”‚   โ”œโ”€โ”€ middleware/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ auth.js             # JWT + API key auth + RBAC
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ error-handler.js    # Typed errors + global handler
โ”‚   โ”‚   โ”œโ”€โ”€ storage/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ in-memory-store.js  # All in-memory Maps + operations
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ seeder.js           # Initial data (skipped if snapshot exists)
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ state-snapshot.js   # Periodic disk snapshots (JSON files)
โ”‚   โ”‚   โ”œโ”€โ”€ utils/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ trace.js            # X-Trace-ID middleware
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ context-limit.js    # Response byte budget + pagination guard
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ response-cache.js   # node-cache wrapper + TTL presets
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ encryption.js       # AES-256-CBC for credential vault
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ logger.js           # Levelled logger (error/warn/info/debug)
โ”‚   โ”‚   โ””โ”€โ”€ websocket.js            # Real-time events via WebSocket
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ dashboard/                  # React + Vite management UI
โ”‚   โ”‚   โ”œโ”€โ”€ src/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ pages/              # Dashboard, Tools, Agents, Monitoring, Settings
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ components/         # Sidebar, Topbar, ToastContainer
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ services/api.js     # Axios client for Manager Server
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ styles/             # global.css, sidebar.css
โ”‚   โ”‚   โ””โ”€โ”€ vite.config.js
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ sdk/
โ”‚   โ”‚   โ””โ”€โ”€ index.js                # Developer SDK โ€” npm-publishable client
โ”‚   โ”‚
โ”‚   โ””โ”€โ”€ cli/
โ”‚       โ””โ”€โ”€ index.js                # Admin CLI (17 commands)
โ”‚
โ”œโ”€โ”€ mcp-server-project/             # Hardened MCP Server
โ”‚   โ”œโ”€โ”€ package.json
โ”‚   โ”œโ”€โ”€ src/
โ”‚   โ”‚   โ”œโ”€โ”€ server.js               # Boot sequence โ€” all 7 security layers
โ”‚   โ”‚   โ”œโ”€โ”€ mcp-protocol.js         # MCP spec endpoint (/mcp/tools, /mcp/invoke)
โ”‚   โ”‚   โ”œโ”€โ”€ routes/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ invoke.js           # Tool invocation (retry + CB + cache + limit)
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ info.js             # Tool discovery per agent
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ metrics.js          # Admin monitoring endpoint
โ”‚   โ”‚   โ”œโ”€โ”€ middleware/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ auth.js             # Agent auth + expiry + scope + disabled check
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ trace.js            # X-Trace-ID attachment
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ context-limit.js    # Response byte budget
โ”‚   โ”‚   โ”œโ”€โ”€ state/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ call-log.js         # Disk-persisted call log (NDJSON)
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ circuit-breaker.js  # Per-tool CLOSED/OPEN/HALF state machine
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ response-cache.js   # TTL cache with auto-eviction
โ”‚   โ”‚   โ”œโ”€โ”€ loaders/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ registry.js         # Central tool+agent in-memory registry
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ tool-loader.js      # Loads *.json from /tools/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ agent-loader.js     # Loads *.json from /agents/
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ credential-loader.js # Merges .env + JSON credentials
โ”‚   โ”‚   โ””โ”€โ”€ watcher.js              # chokidar hot-reload on /tools/ and /agents/
โ”‚   โ”œโ”€โ”€ security/
โ”‚   โ”‚   โ”œโ”€โ”€ middleware/
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ security-headers.js # Strict Helmet CSP + CORS
โ”‚   โ”‚   โ”‚   โ”œโ”€โ”€ rate-limiter.js     # 3-tier rate limiting + IP auto-block
โ”‚   โ”‚   โ”‚   โ””โ”€โ”€ threat-detector.js  # 10-family injection/attack detector
โ”‚   โ”‚   โ””โ”€โ”€ logger/
โ”‚   โ”‚       โ””โ”€โ”€ security-log.js     # Structured security event log (5 levels)
โ”‚   โ”œโ”€โ”€ tools/                      # Tool definition JSON files
โ”‚   โ”œโ”€โ”€ agents/                     # Agent definition JSON files
โ”‚   โ”œโ”€โ”€ credentials/                # .env and JSON secrets (gitignored)
โ”‚   โ”œโ”€โ”€ logs/                       # Security log + call log (gitignored)
โ”‚   โ””โ”€โ”€ security-tests/             # Attack simulation suite + benchmark
โ”‚
โ”œโ”€โ”€ snapshots/                      # Manager server state snapshots (gitignored)
โ””โ”€โ”€ examples/                       # Example tool/agent JSON files

Quick Start

Prerequisites

Requirement

Version

Node.js

โ‰ฅ 16.0.0

npm

โ‰ฅ 7.0.0

Git

any

1. Clone

git clone https://github.com/YOUR_USERNAME/mcp-tool-manager.git
cd mcp-tool-manager

2. Install dependencies

# Root (Manager Server + CLI + SDK)
npm install

# Dashboard
cd src/dashboard && npm install && cd ../..

# MCP Server
cd mcp-server-project && npm install && cd ..

3. Configure

# Manager Server
cp .env.example .env
# Edit .env with your JWT_SECRET, ENCRYPTION_KEY, etc.

# MCP Server
cp mcp-server-project/credentials/.env.example mcp-server-project/credentials/.env
# Edit credentials/.env with your agent keys and tool API keys

4. Run

# Terminal 1 โ€” Manager Server (port 5000)
npm run dev:server

# Terminal 2 โ€” React Dashboard (port 3000)
npm run dev:dashboard

# Terminal 3 โ€” MCP Server (port 5001 by default)
cd mcp-server-project && npm start

5. Access

Default Login (Manager)

Email:    admin@mcp-tool-manager.dev
Password: admin123

โš ๏ธ Change this immediately in production via ADMIN_USERNAME / ADMIN_PASSWORD env vars.


Configuration Reference

Manager Server (.env)

# Core
NODE_ENV=development
MCP_SERVER_PORT=5000
MCP_SERVER_HOST=localhost
LOG_LEVEL=info

# Auth
JWT_SECRET=your-super-secret-key-min-32-chars
JWT_EXPIRY=24h
ENCRYPTION_KEY=your-encryption-key-exactly-32-ch

# Context Window
MCP_MAX_RESPONSE_BYTES=65536        # 64 KB default response budget
MCP_MAX_PAGE_SIZE=100               # Max items per paginated endpoint

# Scalability
MCP_MAX_CONNECTIONS=500             # TCP connection limit
SNAPSHOT_DIR=./snapshots            # State persistence directory
SNAPSHOT_INTERVAL_SECS=60           # Save state every 60 seconds
SNAPSHOT_RESTORE=true               # Restore state on startup

# Cache TTLs (seconds)
CACHE_TTL_TOOL_LIST=30
CACHE_TTL_TOOL_ITEM=60
CACHE_TTL_AGENT_LIST=30
CACHE_TTL_STATS=10
CACHE_TTL_ACTIVITY=300

# Future (not yet wired โ€” provide connection string to enable)
DATABASE_URL=postgresql://user:password@localhost:5432/mcp_tools
REDIS_URL=redis://localhost:6379

MCP Server (mcp-server-project/credentials/.env)

# Agent API Keys (convention: AGENT_<AGENTID_UPPERCASE>_KEY)
AGENT_MY_AGENT_KEY=your-agent-secret-key

# Tool credentials (referenced by credential_ref in tool JSON)
OPENAI_API_KEY=sk-...
WEATHER_API_KEY=...
SLACK_BOT_TOKEN=xoxb-...

# Admin
ADMIN_KEY=your-admin-key-for-metrics-endpoint

# Server
MCP_PORT=5001
MCP_MAX_CONNECTIONS=200
MCP_MAX_RESPONSE_BYTES=32768        # 32 KB default per tool response

Tool JSON Fields (MCP Server)

{
  "name": "my_tool",
  "description": "Human-readable description for the LLM",
  "endpoint_url": "https://api.example.com/endpoint",
  "method": "POST",
  "credential_ref": "MY_API_KEY",
  "parameters": {
    "type": "object",
    "properties": {
      "query": { "type": "string", "description": "Search query" }
    },
    "required": ["query"]
  },
  "cache_ttl_seconds": 60,
  "max_response_bytes": 8192,
  "retry_max": 3,
  "timeout_ms": 10000,
  "circuit_failure_threshold": 5,
  "circuit_open_window_ms": 30000
}

Agent JSON Fields (MCP Server)

{
  "agent_id": "my-agent",
  "allowed_tools": ["weather_lookup", "send_email"],
  "expires_at": "2027-01-01T00:00:00Z",
  "disabled": false
}

API Reference

Manager Server (http://localhost:5000)

Auth

Method

Path

Auth

Description

POST

/api/auth/login

โ€”

Get JWT token

POST

/api/auth/register

โ€”

Create account

GET

/api/auth/me

โœ…

Current user + API keys

POST

/api/auth/api-keys

โœ…

Generate new API key

DELETE

/api/auth/api-keys/:key

โœ…

Revoke API key

Tools

Method

Path

Auth

Description

GET

/api/tools

โœ…

List tools (paginated)

POST

/api/tools

โœ…

Register new tool

GET

/api/tools/:id

โœ…

Tool details

PUT

/api/tools/:id

โœ…

Update tool

DELETE

/api/tools/:id

โœ…

Remove tool

POST

/api/tools/:id/test

โœ…

Test tool invocation

Agents

Method

Path

Auth

Description

GET

/api/agents

โœ…

List agents

POST

/api/agents

โœ…

Register agent

GET

/api/agents/:id

โœ…

Agent details

PUT

/api/agents/:id

โœ…

Update agent

DELETE

/api/agents/:id

โœ…

Remove agent

POST

/api/agents/:id/tools

โœ…

Discover tools for agent

Monitoring

Method

Path

Auth

Description

GET

/api/monitoring/health

โ€”

Liveness probe

GET

/api/monitoring/stats

โœ…

Full system stats + cache + snapshot

GET

/api/monitoring/activity

โœ…

Real hourly call timeline (24h)

GET

/api/monitoring/top-tools

โœ…

Top N tools by call count

GET

/api/monitoring/audit-log

โœ…

Audit entries

GET

/api/monitoring/cache

โœ…

Cache hit-rate + entries

GET

/api/monitoring/snapshot

โœ…

Last snapshot timestamp + counts

MCP Server (http://localhost:5001)

Method

Path

Auth

Description

GET

/health

โ€”

Liveness probe

GET

/info

AGENT_KEY

List tools for calling agent

GET

/info/all

ADMIN_KEY

All tools + all agents

GET

/mcp/tools

โ€”

Claude Desktop compatible tool list

POST

/mcp/invoke/:tool

โ€”

MCP protocol invocation

POST

/invoke/:toolName

AGENT_KEY

Direct tool invocation

GET

/metrics

ADMIN_KEY

Full monitoring dashboard

GET

/metrics/health

โ€”

Lightweight liveness probe

GET

/metrics/calls

ADMIN_KEY

Recent call history


Implementation Plan

This section documents the complete roadmap โ€” what is built, what is in progress, and what requires infrastructure decisions.

Phase 1 โ€” Foundation โœ… Complete

  • Manager Server REST API (tools, agents, auth, credentials, monitoring)

  • In-memory store with full CRUD operations

  • JWT + API key dual authentication with RBAC

  • AES-256-CBC credential vault

  • React dashboard (Tools, Agents, Monitoring, Settings pages)

  • WebSocket real-time event broadcasting

  • Developer SDK (src/sdk/index.js)

  • Admin CLI with 17 commands (src/cli/index.js)

  • MCP Protocol endpoint (Claude Desktop compatible)

  • File-based tool/agent registry with hot-reload (chokidar)

  • Audit log with rolling ring buffer

Phase 2 โ€” Security Hardening โœ… Complete

  • 10-family threat detector (SQL/NoSQL/XSS/SSRF/Shell/Template/Path/CMDi/Null/Header injection)

  • Scanner user-agent blocking (sqlmap, nikto, nmap, Burp Suite, 20+ scanners)

  • 3-tier rate limiting (global + strict + speed slow-down)

  • Auto IP block after brute force (20+ hits)

  • Structured security event log with 5 severity levels

  • Helmet strict CSP (defaultSrc: 'none')

  • Agent key expiry + disabled flag

  • Scope enforcement (requireScope middleware)

  • Auth failure + scope violation security logging

  • Security test suite + benchmark (compare hardened vs. unprotected)

Phase 3 โ€” Operational Capabilities โœ… Complete (This Release)

  • X-Trace-ID โ€” unique request correlator, propagated through all layers and upstream APIs

  • Circuit Breaker โ€” CLOSED/OPEN/HALF-OPEN per tool (configurable thresholds)

  • Retry with exponential backoff โ€” 200ms โ†’ 400ms โ†’ 800ms, skips 4xx errors

  • Response cache โ€” TTL per tool/data-type, hit-rate tracking, prefix invalidation

  • Context window limiting โ€” per-tool byte budget, graceful truncation with signalling

  • Pagination guard โ€” global ?limit clamp (default max 100 items)

  • State snapshots โ€” atomic periodic writes, restored on startup (tools/agents/users survive restart)

  • Connection limit guard โ€” drops TCP sockets over configurable max

  • Rate limiting activated (Manager) โ€” 300 global + 15 auth per minute per IP

  • Real monitoring โ€” activity timeline from actual call data (removed Math.random() mock)

  • /metrics endpoint (MCP) โ€” full admin dashboard (calls, cache, circuit breakers, memory)

  • node-cache activated (Manager) โ€” TTL presets per data type, hit-rate tracking

  • /api/monitoring/cache and /api/monitoring/snapshot new endpoints

Phase 4 โ€” Persistence & Distribution ๐Ÿ”ฒ Pending Your Input

These require infrastructure. pg and ioredis are already installed โ€” only connection strings needed.

  • PostgreSQL โ€” migrate in-memory-store.js to persistent database

    • tools, agents, users, api_keys, credentials, audit_log tables

    • Connection pool via pg (DATABASE_URL already in .env.example)

  • Redis โ€” shared rate limit + session + response cache store

    • Replace node-cache with ioredis for multi-instance safety

    • Shared IP block list across all server instances

    • (REDIS_URL already in .env.example)

  • Horizontal scaling โ€” once Redis + Postgres are wired, deploy N instances behind nginx

Phase 5 โ€” Developer Experience ๐Ÿ”ฒ Optional

  • OpenAPI/Swagger spec auto-generation (swagger-jsdoc)

  • zod env schema validation at startup (fail-fast on missing config)

  • JWT refresh tokens + blacklist

  • Prometheus metrics export (/metrics/prometheus endpoint)

  • OpenTelemetry distributed tracing

  • Tool compatibility matrix

  • WebSocket dashboard for real-time circuit breaker state


Security Model

Manager Server

Request
  โ”‚
  โ”œโ”€โ”€ X-Trace-ID attachment (Layer 0)
  โ”œโ”€โ”€ Helmet strict CSP (Layer 1)
  โ”œโ”€โ”€ Global rate limit 300/min (Layer 2a)
  โ”œโ”€โ”€ Auth rate limit 15/min on /api/auth (Layer 2b)
  โ”œโ”€โ”€ Body size limit 2 MB (Layer 3)
  โ”œโ”€โ”€ Context window budget (Layer 4)
  โ”œโ”€โ”€ Pagination guard max 100 items (Layer 5)
  โ”œโ”€โ”€ JWT / API key verification (per-route)
  โ””โ”€โ”€ RBAC role check (per-route)

MCP Server

Request
  โ”‚
  โ”œโ”€โ”€ X-Trace-ID attachment (Layer 0)
  โ”œโ”€โ”€ Strict Helmet CSP (Layer 1)
  โ”œโ”€โ”€ IP block list check (Layer 2)
  โ”œโ”€โ”€ Body size guard (Layer 3)
  โ”œโ”€โ”€ Context window budget (Layer 4)
  โ”œโ”€โ”€ HTTP method whitelist (Layer 5)
  โ”œโ”€โ”€ Scanner user-agent block (Layer 6)
  โ”œโ”€โ”€ Global rate limit + speed slow-down (Layer 7)
  โ”œโ”€โ”€ 10-family threat detection (Layer 8)
  โ”œโ”€โ”€ Agent API key auth + expiry + disabled check (per-route)
  โ”œโ”€โ”€ Tool scope enforcement (per-route)
  โ”œโ”€โ”€ Circuit breaker check (per-tool)
  โ”œโ”€โ”€ Response cache lookup (per-tool)
  โ””โ”€โ”€ Retry + context limit on upstream call (per-tool)

Monitoring & Observability

Available Data

Source

What it shows

GET /api/monitoring/stats

System overview, cache stats, snapshot info, context limit config

GET /api/monitoring/activity

Real 24h hourly call timeline (success + error counts)

GET /api/monitoring/top-tools

Top tools by call count + success rate

GET /api/monitoring/audit-log

All admin actions (tool create/delete, agent add/remove)

GET /api/monitoring/cache

Cache hit-rate, entry count, evictions

GET /api/monitoring/snapshot

Last snapshot timestamp + record counts

GET /metrics (MCP, admin)

Circuit breaker states, call log, cache stats, system memory

GET /metrics/health (MCP, public)

Uptime + memory (lightweight probe)

logs/calls.ndjson (MCP)

Full call history: trace ID, agent, tool, latency, success, retries

logs/security.log (MCP)

All security events: AUTH failures, threats, rate limits, circuit trips

snapshots/meta.json (Manager)

Last snapshot: timestamp + counts for all data types

X-Trace-ID Flow

Client โ†’ [generates or passes X-Trace-ID]
  โ†’ Manager/MCP Server [attaches to req.traceId, echoes in X-Trace-ID response header]
    โ†’ Security log entries [include traceId]
      โ†’ Call log entries [include traceId]
        โ†’ Upstream API call [X-Trace-ID forwarded in headers]
          โ†’ Response [traceId in JSON body]

Roadmap

v2.1 (Next)

  • Wire PostgreSQL for persistent storage

  • Wire Redis for distributed rate limiting + cache

  • zod env schema validation at startup

v2.2

  • JWT refresh token + blacklist

  • Prometheus metrics export

  • Per-API-key rate limiting (not IP-based)

v3.0

  • Full OpenAPI spec

  • OpenTelemetry distributed tracing

  • OAuth2/OIDC federated agent identity


Contributing

See CONTRIBUTING.md for branch strategy, PR process, and code style guide.


License

MIT ยฉ MCP Tool Manager Team


See REPORT.md for the full technical capability assessment.

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

โ€“Maintainers
โ€“Response time
โ€“Release cycle
โ€“Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    A secure tool-execution plane for agentic AI that enforces JWT authentication, rate limiting, prompt-injection inspection, and audit logging, while ingesting downstream OpenAPI endpoints as MCP tools.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to access a unified catalog of tools from various APIs (OpenAPI, GraphQL, MCP, Google Discovery) through the MCP protocol.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to securely call MCP tools with risk scoring, checkpoints, rollback, and approval workflows.
    134
    MIT

View all related MCP servers

Related MCP Connectors

  • Hosted MCP endpoint with realistic fake data for prototyping agents. 12 tools, no setup.

  • Free public MCP for AI agents โ€” 193 tools, 44 workflows. No API key.

  • Hosted MCP with 91 agent tools: X, domains, SEO, Maps, Trends, Search, YouTube, TikTok, and more.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Nagendda/MCP-Tool-Manager'

If you have feedback or need assistance with the MCP directory API, please join our Discord server