warmplane
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@warmplanelist all tools and resources available from all upstream servers"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Warmplane
Security controls:
The local control plane that keeps Model Context Protocol (MCP) sessions warm with compact capability facades, policy governance, and deterministic execution.
v0.28.0 — Changelog · User Guide · Agent Skill · Performance · Whitepaper · OpenAPI
⚡ What is Warmplane?
Warmplane is a local control plane and reverse proxy for AI tool calling. It maintains persistent, warm connections to multiple upstream MCP servers and multiplexes them behind a single, governed interface.
The Problems Warmplane Solves
Context Window Token Bloat: Sending massive JSON schemas for dozens of tools on every turn wastes tens of thousands of prompt tokens. Warmplane provides a compact catalog index (cutting payload size by 58–96%), on-demand schema discovery, and SHA-256 ETag caching.
Poor Tool Descriptions & Ambiguity: Many upstream tools have sparse, misleading, or poorly phrased docstrings that confuse LLMs. Warmplane lets you override tool summaries and descriptions via polymorphic aliases (
AliasTarget) and generates compact parameter signatures (tool(req, [opt])) to optimize zero-shot agent accuracy without upstream code edits.Duplicate Invocations & Retries: When network hiccups occur, naive agents retry blind mutations. Warmplane provides crash-resilient, exactly-once idempotency deduplication (
idk_<sha256>) and explicit retry classifications (safe,idempotent,unsafe).Ungoverned Execution & Security: Connecting agents directly to live infrastructure risks unauthorized operations. Warmplane enforces multi-tenant RBAC, per-profile server constellations, secret redaction, and Human-in-the-Loop (HITL) approval gates.
Cascading Hangs & Flakiness: Slow or crashed upstream processes freeze agent loops. Warmplane monitors health with sub-microsecond circuit breakers and self-healing process supervision.
Related MCP server: MCP Server Proxy
🚀 Quick Start
1. Installation
Homebrew (macOS & Linux):
brew tap warmplane/tap
brew install warmplaneCargo (crates.io):
cargo install warmplane
# Optional: with local ONNX vector search (FastEmbed)
cargo install warmplane --features semantic-searchBuild from Source:
git clone https://github.com/Warmplane/warmplane.git
cd warmplane
cargo install --path . --features semantic-search2. Configure Upstream Servers
Add servers interactively or import from existing AI tools:
# Interactive setup wizard
warmplane server add
# Or non-interactively
warmplane server add filesystem --command npx --arg "-y" --arg "@modelcontextprotocol/server-filesystem" --arg "/tmp"
warmplane server add context7 --url "https://mcp.context7.ai/sse" --bearer-env "CONTEXT7_API_KEY"
# Or 1-click import from Claude Desktop, Cursor, OpenCode, Zed
warmplane config importOr configure mcp_servers.json:
{
"port": 9090,
"toolTimeoutMs": 15000,
"capabilityAliases": {
"db.query": "sqlite.read_query",
"search": {
"target": "semble-rs.search",
"summary": "Search codebase using semantic or BM25 ranking. Pass absolute repo path."
}
},
"policy": {
"allow": ["db.*", "fs.*", "search"],
"deny": ["fs.delete*"],
"requireApproval": ["db.mutation*"],
"redactKeys": ["token", "password", "api_key"]
},
"profiles": {
"coding": {
"servers": ["filesystem", "sqlite"],
"description": "Local engineering and exploration tools"
}
},
"mcpServers": {
"sqlite": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-sqlite", "./test.db"] },
"filesystem": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-filesystem", "/tmp"] }
}
}3. Start Warmplane
# Start background daemon & Web Control Deck on http://127.0.0.1:9090
warmplane daemon
# Or expose Warmplane as a stdio MCP server for Claude Desktop or Cursor
warmplane mcp-server🔌 Client Interfaces
Warmplane exposes three primary access models sharing the same unified core state, policy gates, and telemetry:
1. Native MCP Stdio Proxy (warmplane mcp-server)
Point any MCP-native desktop client (Claude Desktop, Cursor, Zed, Windsurf) directly to Warmplane:
{
"mcpServers": {
"warmplane": {
"command": "warmplane",
"args": ["mcp-server", "--config", "mcp_servers.json", "--profile", "coding"]
}
}
}2. HTTP REST Control Plane (warmplane daemon)
Full-featured HTTP JSON API for gateways, web apps, and backend services:
GET /v1/capabilities: Compact capability catalog indexPOST /v1/capabilities/search: Hybrid lexical + semantic capability searchPOST /v1/tools/call: Normalized execution envelope with context distillation (_jsonpath,_limit_lines) and idempotency keysPOST /v1/tools/batch_call: Chained multi-step execution with$step.fieldparameter interpolationGET /v1/tasks&POST /v1/tasks/:id/update: SEP-2663 async task lifecycle & HITL reviewGET /ui: Embedded standalone Web Control Deck
3. In-Process Embedded Engine (EmbeddedWarmplane)
Direct in-process Rust library for zero-overhead agent execution without HTTP child processes or network hops:
use warmplane::{EmbeddedWarmplane, engine::ExecutionOptions};
use serde_json::json;
#[tokio::main]
async fn main() -> anyhow::Result<()> {
let (cp, _token) = EmbeddedWarmplane::start_from_path("mcp_servers.json").await?;
let res = cp.call_capability(
"filesystem.read_file",
json!({ "path": "/tmp/test.txt" }),
ExecutionOptions::default().with_request_id("req-1"),
).await;
println!("Output: {:?}", res.data);
Ok(())
}🤖 Teach Your AI Agent Warmplane (Agent Skill)
Warmplane includes an official Agent Skill (.skills/warmplane/) adhering to the agentskills.io open standard. Point your coding agent (Claude Code, Google Antigravity, Cursor, OpenCode, Codex) directly to this repository:
# Install Warmplane Skill into Claude Code
claude skill install Warmplane/warmplane
# Or copy into your agent workspace
mkdir -p .agents/skills/warmplane && cp -r .skills/warmplane/* .agents/skills/warmplane/📖
.skills/warmplane/SKILL.md— Core prompt triggers and standard agent workflows🔌
references/mcp_stdio_usage.md— 1-Click client configs (17 IDEs) & MCP facade tools⚙️
references/configuration_schema.md—mcp_servers.jsonschema & dynamic secrets🛠️
references/cli_cheatsheet.md— Terminal commands for daemon, sync, and vault🚑
references/error_resolution.md— Circuit breakers, policy denials, and recovery
📊 Performance Highlights
Warmplane is engineered in pure Rust with zero-cost abstractions:
50.4 ns: ETag Cache Validation (
If-None-Match$\rightarrow$304 Not Modified)159.8 ns: Idempotent Cache-Hit Deduplication
1.58 µs: SHA-256 Incremental Catalog Version Hashing ($N=10$)
15.9 µs: Filtered Hybrid Capability Search ($N=50$)
372.1 µs: Zero-Allocation Lexical Tag Search across 1,000 Tools
👉 See complete benchmarks and methodology in docs/PERFORMANCE.md.
🛡️ Core Capabilities Matrix
Capability | Since | Description |
Real-Time MCP | v0.28.0 | Real-time tool/resource/prompt list change notifications, SEP-1319 |
Custom Alias Descriptions & Signatures | v0.27.0 | Polymorphic docstring overrides ( |
1-Click AI Client Injector & Sync | v0.26.0 | Bidirectional MCP adapter engine for Claude Desktop, OpenCode, Claude Code, Cursor, Zed, Windsurf, Cline |
Native OS Keychain Vault | v0.26.0 | Secure OS Keychain storage and dynamic secret URI resolution ( |
Actionable ChatOps Webhooks | v0.26.0 | Bidirectional Slack, Discord, and Microsoft Teams approval cards with HMAC-SHA256 signatures |
Per-Profile Governance & Constellations | v0.26.0 | Fine-grained per-profile policy rules, constellation boundary badges, and live filter metrics |
Control Deck Tasks & HITL UI | v0.25.0 | Live Tasks & Approvals hub, MRTR input resolution forms, Playground async toggle, and embedded task API |
SEP-2663 Tasks Extension | v0.24.0 | Non-blocking |
In-Process Embedded Rust Engine | v0.23.0 |
|
Streamable HTTP/SSE MCP Transport | v0.22.0 | Co-hosted |
Named Server Constellations | v0.21.0 | Profile grouping ( |
Multi-Tenant RBAC | v0.20.0 | Role-based token access, deterministic catalog partitioning, tenant context propagation |
Client-Delegated MCP Sampling | v0.19.0 | Reverse RPC sampling ( |
Persistent State Subsystem | v0.18.0 | Atomic restart-resilient disk storage ( |
Signal Handling & Graceful Teardown | v0.18.0 | Robust |
MCP Resource & Prompt Studio | v0.17.0 | 360° resource explorer, prompt template renderer with dynamic forms, and SSE syncing |
Multi-Step Batch Pipelines | v0.17.0 | Visual pipeline editor with reference parameter interpolation ( |
Enterprise Security & Auth | v0.16.0 | Token-based middleware protection, WORM audit HMAC verification, and secret masking |
Fault Tolerance & Supervision | v0.15.0 | Degraded startup, per-server circuit breakers, exponential backoff restart supervision |
Agent Enrichment Suite | v0.14.0 | Facade search, context distillation ( |
HITL Approval Engine | v0.13.0 | Operator gate approval engine, suspension, argument editing, and HMAC webhook dispatch |
WORM Audit & SIEM | v0.12.0 | Append-only SHA-256 hash-chained audit logging, verification API, and Splunk/Webhook SIEM export |
Control Deck Web UI | v0.11.0 | Standalone embedded web dashboard for servers, testing playground, policy & telemetry |
Dynamic Hot-Reloading | v0.11.0 | Zero-downtime upstream mounting/unmounting, explicit |
Changelog
v0.28.0 — Real-Time MCP list_changed Notifications, SEP-1319 Discovery Hints & Passthrough Tools
Real-Time MCP
list_changedNotifications (src/mcp_server.rs,src/daemon/state.rs): AdvertisedlistChanged: trueacrosstools,resources, andpromptscapabilities (enable_tool_list_changed,enable_resources_list_changed,enable_resources_subscribe,enable_prompts_list_changed). Active MCP stdio sessions receive real-time JSON-RPC notifications whenever upstream servers mount/unmount or config/aliases mutate.SEP-1319 Metadata Discovery Hints (
src/mcp_server.rs): Injectedio.warmplane/discovery_hintmetadata payload intonotifications/tools/list_changedadvising agents to runcapabilities_listto discover backend capabilities without incurring constant token costs on tool schemas.Top-Level Native Tool Passthrough (
src/config.rs,src/mcp_server.rs,src/cli_config.rs): Promoted capability aliases (passthrough: true) into native top-level tools exported directly intools/listwith strict MCP name sanitization (^[a-zA-Z0-9_-]{1,64}$) and direct dispatch resolution.WORM Audit Trail on Dynamic Mutations (
src/daemon/lifecycle.rs,src/http_v1/config_api.rs): Added tamper-evident SHA-256 hash-chainedAuditEventType::ConfigMutationaudit records across server mounts/unmounts, alias mutations, security policy updates, and profile configuration changes.Interactive Alias Management UI (
ui/src/components/aliases.ts,ui/src/main.ts): Added click-to-edit alias rows, passthrough toggle pill badges, and input sanitization directly in the Control Deck web UI.
v0.27.0 — Custom Alias Descriptions, Compact LLM Tool Signatures & Task Inspector
Custom Alias Descriptions & Docstring Overrides (
src/config.rs,src/supervisor.rs): Upgraded alias configuration model to support polymorphic definitions (AliasTarget). Aliases can be simple target strings ("alias": "server.tool") or detailed objects ("alias": { "target": "server.tool", "summary": "...", "description": "..." }), enabling platform engineers and developers to repair or improve poorly-described upstream tools for zero-shot LLM ergonomics without upstream source changes.Compact LLM Tool Signatures (
src/supervisor.rs,src/daemon/types.rs,src/engine/types.rs): Derived deterministic, compact parameter signatures (tool_name(req1, [opt1], [opt2])) from JSON Schemas (accounting for required fields vs nullable/optional properties). Surfaced across MCPcapabilities_list, catalog search, and Web UI index summaries.Bidirectional Alias Resolution (
src/supervisor.rs): Resolved mapping mismatch where supervisory discovery checks target equality against configured alias keys, ensuring canonical targets are promoted seamlessly to client interfaces.Rich Task Inspector Modal & Dual Controls (
ui/src/components/tasks.ts): Enhanced Tasks & Approvals UI with dedicated inspector modal, live state viewers, formatted JSON payload inspections, and dual inspect/cancel action controls.Server Template Missing Secret Warnings (
ui/src/components/servers.ts,src/vault/): Added live(Missing Keys)warning badges and status indicators across server cards and diagnostics when required template environment variables or Keychain secrets are unconfigured.Live Alias Configuration API & UI: Added custom summary inputs to the Control Deck Aliases tab (
ui/src/components/aliases.ts) and CLI (warmplane config alias set --summary ...) with automated live hot-reloading reconciliation on disk mutation.
v0.26.1 — MCP Stdio Stream Isolation & Logging Fix
MCP Stdio Stream Isolation (
src/telemetry.rs): Configuredtracing_subscriber::fmt::layer()to write tostderr(.with_writer(std::io::stderr)). Prevents runtime structured JSON logs and span diagnostics from pollutingstdout.Upstream Process Stderr Inheritance (
src/supervisor.rs): Upstream stdio child processes now explicitly inherit Warmplane's standard error (cmd.stderr(std::process::Stdio::inherit())). Prevents upstream startup banners (e.g. Memory and Filesystem server banners) from leaking into stdio JSON-RPC sessions.Client Protocol Reliability: Resolves JSON-RPC initialization failure (
invalid message version tag ""; expected "2.0") when running Warmplane in stdio server mode (warmplane mcp-server) with AI agents and IDEs.
v0.26.0 — 1-Click AI Client Sync, Native Secrets Vault, ChatOps & Profile Governance
1-Click AI Client Injector & Ecosystem Sync (
src/client_sync.rs): Zero-configuration bidirectional MCP adapter engine. Detects, injects, and detaches Warmplane proxy configurations with profile binding across Claude Desktop (macOS, Linux, Windows), OpenCode, Claude Code CLI (CLAUDE_CONFIG_DIR), Cursor (Global & Workspace), Zed Editor (context_servers), Windsurf, and Roo Code / Cline.100% Agent Config Import Parity (
src/config_import.rs): Unified external config discovery with dialect-aware parsers (StandardMcpServers, OpenCodemcp, Zedcontext_servers) and self-proxy protection.Native OS Keychain Vault & Dynamic Secrets (
src/vault/): Added secure OS-level credential management (warmplane secret set/get/delete) and dynamic runtime secret expansion (keychain://,op://,env://) in environment variables with masked logs.Actionable ChatOps & Bidirectional Webhooks (
src/chatops/): Rich interactive approval cards for Slack (Block Kit), Discord (Embeds), and Microsoft Teams (Adaptive Cards) with HMAC-SHA256 signature verification.Per-Profile Governance Policies (
src/policy.rs,ui/src/components/policy.ts): Fine-grained per-profileallow,deny, andrequireApprovalrules overriding or scoping global policies.Constellation Boundaries & Dynamic Visibility (
ui/src/components/servers.ts): Visual constellation badges (✔ IN CONSTELLATION,🚫 EXCLUDED FROM PROFILE), auto-derived<server>.*implicit policy denials, and 1-click membership toggles.Server Diagnostics & 1-Click Restart: Added live error diagnostics modals, server restart endpoint (
POST /v1/config/servers/:id/restart), and automated smoke testing suite for all 25 MCP server templates (scripts/test-templates.ts).Dynamic Catalog ETag Fingerprinting & Layout Stabilization: Profile-aware fingerprint hashing (
sha256:...-p:<profile_id>:<hash>) ensuring immediate ETag invalidation and playground catalog re-population. Stabilized viewport layouts with continuous scrollbar gutter reservation.
v0.25.2 — Official MCP Registry Metadata & MCPB Packaging Format
MCPB Distribution Format (
packaging/mcpb/,.github/workflows/release-artifacts.yml): Added automated build and packaging of platform-specific Model Context Protocol Bundles (.mcpb) containing standalone binaries, bootstrap configurations, and standardized manifests (manifest_version: "0.3").Official MCP Registry Metadata (
server.json): Release workflows now automatically generate canonical registry metadata adhering to the officialserver.schema.jsonspecification (io.github.warmplane/warmplane) with multi-arch SHA-256 package digests.Homebrew Tap (
Warmplane/homebrew-tap): Configured official tap distribution with prebuilt macOS and Linux formula (brew tap warmplane/tap && brew install warmplane).
v0.25.1 — Asynchronous Task Completion State Machine Fix
Asynchronous Task Finalization (
src/engine/mod.rs,src/http_v1/execute.rs): Resolved regression where asynchronous capability executions (async_task: trueorPrefer: respond-async) and tasks resumed after Human-in-the-Loop (HITL) input responses remained indefinitely inTaskStatus::Working. Background workers now reliably record terminal state (TaskStatus::Completedwithresult, orTaskStatus::Failedwith structured error) directly intoTaskRegistry.Embedded Task Lifecycle Tests (
tests/embedded_tests.rs,tests/tasks_tests.rs): Added comprehensive automated integration tests verifying thatget_taskandlist_tasksobserve terminalcompletedstatus with upstream payload following approval submissions and direct asynchronous calls.
v0.25.0 — Control Deck Tasks & HITL UI, In-Process Embedded Task API
Control Deck Tasks & Approvals Hub (
ui/src/components/tasks.ts): Upgraded the review queue into a unified Tasks & Approvals dashboard (data-tab="tasks") with live status KPIs (input_required,working,completed,cancelled/failed), interactive action cards with inlined MRTR input resolution forms (booleans, JSON editors, text fields), TTL countdown timers, and cooperative cancellation controls.MCP Playground Async Execution Mode: Added "⚡ Async Task Mode" toggle in the tool testing playground and an interactive
202 Acceptedtask card preview with 1-click navigation to the Tasks & Approvals review deck.Embedded Rust Task Management API (
ControlPlaneHandle): Exposed direct task management methods on the in-processControlPlaneHandle(list_tasks,get_task,update_task,cancel_task), allowing embedding applications to manage asynchronous SEP-2663 tasks without HTTP or JSON-RPC serialization overhead.Overview Cockpit & Badge Integration: Added "Tasks & HITL State" telemetry card in the Overview Cockpit and linked real-time sidebar badges to outstanding
input_requiredtasks.
v0.24.0 — SEP-2663 Tasks Extension, Unified HITL Execution & MCP Roadmap Alignment
SEP-2663 Tasks Extension Implementation (
src/tasks.rs): Implemented the officialio.modelcontextprotocol/taskscapability with atomic persistent storage (tasks.json), safe TTL expiration detection, and oneshot input response channels (TaskWaitSender/TaskWaitReceiver).Unified HITL Approval & Asynchronous Task State Machine: Unified Human-in-the-Loop approval workflows and asynchronous tool executions directly onto the SEP-2663 lifecycle. Tool executions requiring operator gate approval or requested with
async_task: true/Prefer: respond-asyncreturn202 AcceptedwithresultType: "task"andstatus: "input_required", inlining MRTRinputRequests.HTTP REST Task API (
/v1/tasks/*): Added comprehensive REST endpoints for task inspection and control:GET /v1/tasks(list),GET /v1/tasks/:id(poll status/result),POST /v1/tasks/:id/update(submitinputResponsesto wake up worker), andPOST /v1/tasks/:id/cancel(cooperative cancellation).MCP Facade Server Integration: Exposed
task_get,task_update, andtask_canceltools on the MCP facade server for direct agent orchestration.CLI Tasks Subcommands & Async Execution Flag: Added
warmplane tasks list,warmplane tasks get <id>,warmplane tasks update <id> -r '<json>',warmplane tasks cancel <id>, and the--async-taskflag towarmplane call-capability.MCP Protocol Roadmap Strategic Analysis: Published
docs/MCP_ROADMAP_REPORT.mdanalyzing the official MCP roadmap and Warmplane's architectural alignment across stateless transports, sessionless routing, and progressive capability discovery.
v0.23.0 — Embedded Rust Engine, In-Process Control Plane & Facade Adapter Refactoring
In-Process Embedded Rust Library Engine (
EmbeddedWarmplane,ControlPlaneHandle): Exposed Warmplane as a pure in-process library without HTTP, daemon child process, or JSON-RPC serialization overhead. Callers spawn the engine directly on their own Tokio runtime viaEmbeddedWarmplane::start(config)orEmbeddedWarmplane::start_from_path(path)and interact via typedControlPlaneHandlemethods (list_capabilities,describe_capability,search_capabilities,call_capability,batch_call,read_resource,get_prompt,health_status).Strongly Typed Generic Envelopes & Error Models: Added
Envelope<T>,WarmplaneError,CapabilitySummary,CapabilityDetail,ExecutionOptions,ReadResourceOptions,GetPromptOptions, andEngineHealthStatusinwarmplane::engine::types, preserving structured diagnostics (request_id,trace_id,retry,operator) for programmatic orchestration.MCP Stdio Server Facade Adapter Refactoring: Refactored
mcp_server.rsto delegate all tool call execution, search, descriptions, batch execution, and resource/prompt dispatch directly toControlPlaneHandle, eliminating duplicated logic and unifying execution pipelines.Embedded Engine Integration Test Suite: Added dedicated integration tests in
tests/embedded_tests.rscovering embedded lifecycle startup, degraded server handling, health status inspection, and graceful cancellation.
v0.22.0 — Streamable HTTP/SSE MCP Transport, Interactive Playground & UI Polish
Streamable HTTP/SSE MCP Server Transport (
mcp-http-server): Built standalone and daemon-co-hosted HTTP/SSE MCP server endpoints (/mcp/sse,/mcp/messages), allowing remote AI agents and IDEs (Cursor, Windsurf, Claude Desktop) to connect over standard HTTP/SSE networks with automatic keep-alives and zero client drift.Daemon Co-hosting & Configuration (
mcpHttpServer): Added first-class configuration support (mcpHttpServer) enabling automatic background initialization of HTTP/SSE MCP server instances directly alongside the core/v1HTTP daemon.Profile Restriction & Bound Auth Gate: Integrated profile restriction (
profile) on the MCP server transport, strictly isolating tools and resources exposed to remote clients. Automatically enforced bearer token authentication when binding to public non-loopback network interfaces (0.0.0.0/ external IPs).Interactive MCP Playground Ergonomics: Added sample template injection, dynamic format switching, schema-driven argument generation, and live parameter validation in the Web Control Deck MCP Playground.
UI Transitions, Collision Checks & Polish: Deduplicated page headers across dashboard tabs, introduced buttery-smooth CSS cubic-bezier transitions, animated modal backdrops with
prefers-reduced-motionaccessibility support, and added collision guards with automatic unique server ID derivation.
v0.21.0 — Named Server Constellations (Profiles), Signal Lifecycle & Integrator Ecosystem
Named Server Constellations (Profiles): Added first-class profile support (
ProfileConfig) allowing task-relevant subsets of upstream MCP servers to be grouped into named constellations (e.g.coding,research,data_science).Dynamic Profile Selection & Scoped ETag Partitioning: Supported per-request profile scoping via
X-Warmplane-Profileheaders and?profile=query parameters. Catalog endpoints (/v1/capabilities,/v1/resources,/v1/prompts) and search (/v1/capabilities/search) dynamically prune items outside the active profile and maintain deterministic profile-partitioned ETags (sha256:...-p:<profile_id>).MCP Facade Stdio Profile Filtering: Added
--profile <name>CLI option towarmplane mcp-serverandwarmplane list-capabilities, providing agent hosts with a strictly scoped MCP tool and resource surface.Web Control Deck Profile Hub: Added interactive visual profile manager in the Web UI dashboard with 1-click active constellation switching, server toggles, and live catalog filtering.
Signal Handling & Process Teardown Hardening: Integrated immediate
tokio_util::sync::CancellationTokendispatch onSIGINT(Ctrl-C) /SIGTERM, unblocked SSE stream draining, added child process orphan prevention viakill_on_drop(true), and enforced a 3-second bounded safety shutdown timeout.Developer & Integrator Ecosystem Guides: Published official Rust Integrators Guide, TypeScript Integrators Guide, and Idempotency Architecture Editorial.
v0.20.0 — Multi-Tenant RBAC & Deterministic Catalog Partitioning
Multi-Tenant RBAC Engine (
src/rbac): Built role-based access control engine with support for static API tokens, token-to-role mappings in configuration (rbac.tokens), and cryptographic HMAC-SHA256 symmetric JWT signature verification with configurable secret key (rbac.jwt_secret).Deterministic Catalog Partitioning & Scope Pruning: Restructured
/v1/capabilities,/v1/resources,/v1/prompts, and/v1/capabilities/searchto dynamically filter items by caller role and effective policy. Unauthorized items are completely invisible in catalog listings and search queries.Tenant Context Injection & Non-Repudiation Audit: Injected resolved
TenantContext(tenant_id,role,actor_id,grant_id,effective_policy) into request extensions via RBAC guard middleware (src/rbac/middleware.rs). Bound verified tenant/actor metadata automatically into WORM audit events.Role Policy Overrides & HITL Delegation: Supported fine-grained role definitions (
RolePolicyConfig) with customallow,deny,require_approval, andredact_keysrules, overriding or intersecting with base system policy.Integration Test Suite: Added dedicated RBAC integration tests (
tests/rbac_integration.rs) covering token authentication, search filtering, catalog isolation, policy boundary enforcement, and multi-tenant audit verification.
v0.19.0 — Client-Delegated MCP Sampling, HTTP/SSE Supervisor Loop & Hardening
Client-Delegated MCP Sampling (
sampling/createMessage): Implemented client-delegated LLM completion reverse RPC handling (src/sampling.rs). Upstream servers or agents submit sampling requests, generating tracked tickets (samp_<timestamp>_<seq>) with synchronous long-polling or asynchronous lifecycle endpoints (POST /v1/sampling/create_message,GET /v1/sampling/requests,GET /v1/sampling/requests/:id,POST /v1/sampling/requests/:id/respond).Persistent Sampling State: Added atomic, restart-resilient disk storage (
sampling.json) viaAtomicFile<HashMap<String, PendingSamplingRequest>>with automated expiration reaper tasks.Self-Healing Streamable HTTP/SSE Supervisor: Integrated remote HTTP/SSE MCP servers into the supervisor loop with automated reconnection backoff, catalog reconciliation, and degraded boot status reporting.
Security & DoS Hardening: Capped candidate capability embeddings for semantic vector search to
MAX_VECTOR_SEARCH_CANDIDATES = 250; bounded audit export queries toMAX_IN_MEMORY_AUDIT_EVENTS(20,000); enforced Host header and loopback Origin checks on OAuth proxy requests.CI Gating & TypeScript Typechecking: Added automated TypeScript typechecking (
tsc --noEmit) to Web UI CI pipeline and restricted push triggers tomainto eliminate duplicate runs.Pragmatic Rust Compliance: Achieved 100% adherence across all 51 source files with standard compliance headers (
// Rust guideline compliant YYYY-MM-DD).
v0.18.0 — Persistent State Subsystem, Graceful Teardown, CI UI Automation & E2E Test Suite
Persistent State Subsystem: Added atomic, restart-resilient disk storage (
AtomicFile<T>andStateDirectory) for Human-in-the-Loop pending approvals (approvals.json), idempotent execution records (idempotency.json), OAuth2 tokens (oauth_tokens.json), and catalog mutation events (catalog_events.json). Addedstateblock inMcpConfigandwarmplane config state show/setCLI commands.Graceful Signal Handling & Subsystem Teardown: Added robust
SIGINT(Ctrl+C) andSIGTERMsignal capture on Unix and Windows, integrated graceful HTTP server draining, async audit worker flushes (AuditWorkerMsg::FlushAndShutdown), and clean stdio subprocess process termination on shutdown.Pragmatic Rust Compliance: Achieved 100% adherence across all 51 source files with standard compliance headers (
// Rust guideline compliant YYYY-MM-DD).CI Automated Web UI Build & Drift Gate: Integrated Bun into GitHub Actions CI (
ci.yml) and release pipelines (release-artifacts.yml), with automated build steps and strictgit diff --exit-code ui/dist/index.htmldrift detection.Comprehensive End-to-End Integration Suite: Implemented dedicated E2E test harness (
tests/e2e_tests.rs) exercising stdio MCP protocol handshakes, live TCP SSE streaming, config hot-reloading, mock OAuth2 RFC 8414 provider round-trips with silent 401 token refresh, and supervisor recovery.
v0.17.0 — 360° MCP Explorer, Visual Batch Pipeline Builder & WORM Audit Pagination
WORM Audit Multi-Field Search & Pagination: Added case-insensitive substring search across 11 metadata fields, outcome status and server filters, offset/limit pagination slicing (
/v1/audit/events), and context-aware CSV and JSONL export downloads (/v1/audit/export).MCP Resources Explorer & Live Content Reader: Added 360° resource discovery browser with protocol scheme badges (
file://,postgres://,github://,memory://,sqlite://, etc.), metadata/MIME viewer, and live content reader supporting context distillation (_jsonpath,_limit_lines,_truncate_bytes).MCP Prompt Template Studio: Added dynamic prompt template browsing and argument form generation with
REQUIREDvalidation badges, rendering resolved system/user prompt envelopes (/v1/prompts/get).In-Flight Operation Cancellation: Added interactive UI execution cancellation controls with live execution timers and instant cooperative abort (
POST /v1/operations/:id/cancel).Visual Multi-Step Batch Pipeline Builder: Added interactive modal pipeline editor for chaining tools with parameter variable interpolation (
${steps[0].result.id}) and per-node fault tolerance (POST /v1/tools/batch_call).Realtime SSE State Synchronization: Connected
/v1/resources/updatesSSE stream to automatically refresh resources, prompts, and catalog feeds on the Control Deck.
v0.16.0 — Enterprise Security Hardening, Audit Cryptographic Integrity & Lifecycle Resilience
API Token Authentication & Middleware Guarding: Added
--auth-tokenCLI parameter,McpConfig.auth_tokenconfiguration field, andWARMPLANE_AUTH_TOKENenvironment variable support to securely protect daemon endpoints with Bearer/X-Warmplane-Key authentication.OAuth Proxy Security & Secret Masking: Hardened the OAuth proxy listener with Host validation and cross-origin browser blocking; masked
stateand PKCEcode_challengesecrets in log output.Cryptographic WORM Audit Integrity & HMAC Signing: Included all 20 persisted metadata fields in hash chain digests (
work_item_id,client_ip,resource_uri,execution_latency_us,error_message); added HMAC-SHA256 keyed digest calculations and checkpoint generation for external cryptographic anchoring.Secret Sanitization & Redaction: Enhanced case-insensitive redaction matching with built-in default sensitive key list (
token,secret,password,key,authorization, etc.); restricted external HITL webhook events to only transmitsanitized_args; sanitized secrets before printing in CLI commands.Supervisor & Circuit Breaker Coordination: Automatically reset circuit breakers on successful supervisor reconnection; added single-flight probe limits in
HalfOpencircuit breaker state; implemented 60-second sliding-window restart backoff; pruned removed items during catalog reconciliation; cleaned up circuit breakers on server unmount.Resource Caps & Safety Controls: Enforced
MAX_BATCH_STEPS = 50andDEFAULT_BATCH_TIMEOUT_MS = 60_000execution budget; capped wildcard JSONPath output expansion to 10,000 items and search results to 100; returnedPOLICY_DENIED(HTTP 403) and 404 for unknown operation cancellation; sanitized CSV audit exports against formula injection.CI Quality Gates & Dependency Audits: Integrated native
cargo-auditscanning in GitHub Actions CI; updated dependencies resolving all reported advisories.CLI Version Flag: Enabled standard
--versionand-Vflags in thewarmplanebinary parser.
v0.15.0 — Fault Tolerance, Boot Resilience & Control Deck Feature Parity
Boot Resilience & Degraded Startup: Graceful daemon boot when upstream servers (such as Docker, remote SSE endpoints, or unconfigured tools) fail or timeout. Failed servers are flagged as
degradedwithout crashing the daemon or blocking other healthy upstreams.Process Supervisor & Circuit Breakers: Per-server and global circuit breakers (
failureThreshold,cooldownMs,autoRestart,maxRestarts) with state tracking (CLOSED,OPEN,HALF-OPEN) and exponential backoff restart supervision.Full Web UI Feature Parity:
Server Hub: Server card edit workflow (
✏️ Edit), live circuit breaker telemetry badges, and server resilience indicators.Template Wizard: Fault tolerance and supervisor configuration accordion directly inside 1-click curated server setup.
Interactive Playground: Context distillation controls (
_jsonpath,_limit_lines,_truncate_bytes) and execution latency measurements.Responsive Bento-Grid overview cards with real-time health indicator dots (
connected🟢,degraded🟡,error🔴).
CLI Resilience Configuration:
warmplane config resilience setandwarmplane config resilience showfor headless circuit breaker management.
v0.14.0 — Agent Enrichment Suite: Facade Search, Context Distillation & Multi-Step Batching
MCP Facade Hybrid Search: Exposed
capability_searchtool over MCP stdio facade with keyword, tag, server ID, and execution mode filters.Context Distillation & Truncation: Added
_jsonpath,_limit_lines, and_truncate_bytesmodifiers to/v1/tools/callandcapability_callto protect LLM context windows from oversized outputs.Multi-Step Chained Batch Calls: Added
POST /v1/tools/batch_callandcapabilities_batch_callfor single-roundtrip dependent tool executions with$step.fieldreference interpolation.
v0.13.0 — Human-in-the-Loop (HITL) Approval Engine & Signed Webhooks
Approval Interceptor: Policy-driven suspension for sensitive capability calls (
requireApproval).Operator REST API: Endpoints to list (
/v1/approvals), inspect, approve with modified arguments (/v1/approvals/:id/approve), or reject (/v1/approvals/:id/reject).Signed HMAC Webhooks: Real-time webhook dispatch with SHA-256 HMAC signature headers on approval lifecycle events.
Configurable TTL Expiration: Automatic timeout expiration (
approvalTimeoutSecs) returning structured cancellation envelopes.
v0.12.0 — Cryptographic WORM Audit Log & SIEM Streaming
Append-only linear SHA-256 hash chaining over tool execution and HITL decision events.
Audit verification and export endpoints (
/v1/audit/...), Splunk HEC and generic Webhook ingestion.
v0.11.0 — Control Deck Web UI & Dynamic Upstream Hot-Reloading
Control Deck Web UI: Embedded zero-dependency web dashboard at
/uiand/with live telemetry, server manager, interactive tool playground, policy/redaction manager, and alias registry.Zero-Downtime Dynamic Upstream Mounting: Dynamically mount and unmount stdio, HTTP, and OAuth2 upstream workers via REST/UI/CLI without restarting the daemon process.
Dynamic Catalogs & ETags: Concurrency-safe state management with automatic SHA256 ETag recomputation and SSE resource notifications on server changes.
Explicit Config Hot-Reload: Added
warmplane reloadCLI command andPOST /v1/config/reloadendpoint to cleanly reconcile in-memory workers against manual edits tomcp_servers.json.
v0.10.0 — CLI Configuration Management & Ecosystem Importers
Added
warmplane server(add,remove,list,get,test) commands with interactiveinquirewizards and flag-driven headless automation.Added
warmplane config(init,show,import,alias,policy) for safe, transactional configuration mutations.Added auto-discovery and import from Claude Desktop, Cursor, and Zed settings.
Added atomic configuration file writes (
fs::rename) preventing JSON corruption.
v0.9.0 — MCP 2026-07-28 Spec Compliance, MRTR & Subscriptions
Upgraded to official MCP Rust SDK
rmcp 3.1.2andreqwest 0.13.Set default protocol version to
"2026-07-28"with backward compatibility for"2025-11-25".Added Multi Round-Trip Requests (MRTR) support (
input_responsesandrequest_state) across HTTP REST, stdio facade, and upstream workers.Added cache hints (
ttl_ms: 300000,cache_scope: "public") and deterministic alphabetical sorting on catalog listings.Added
subscriptions_listentool to stdio facade and/v1/resources/updatesSSE stream for real-time notifications.Validated RFC 9207 / SEP-2468
isscallback verification for OAuth 2.0 flows.
v0.8.0 — Semantic Vector Embeddings & FastEmbed ONNX Pipeline
Integrated FastEmbed ONNX embedding pipeline with dense cosine vector similarity under optional
--features semantic-search.Hybrid reciprocal rank fusion combining BM25 keyword matching and dense vector search.
v0.7.0 — Pragmatic Rust Modernization & Builder Patterns
Full adoption of Microsoft's Pragmatic Rust Guidelines (AGENTS.md). Implemented Builder Pattern (M-INIT-BUILDER) for core state (AppStateBuilder), search filters (SearchFilterBuilder), and request context (RequestContextBuilder). Enhanced error safety (M-PANIC-IS-STOP), structured logging (M-LOG-STRUCTURED), canonical documentation (M-CANONICAL-DOCS), and flexible trait interop (M-IMPL-ASREF).
v0.6.0 — Idempotency, Cancellation & Retry Metadata
Pass Idempotency-Key / X-Idempotency-Key to deduplicate concurrent tool calls. Abort any in-flight request via cancel endpoint or CLI. Every response envelope now includes structured "retry" metadata (classification + state) for orchestrator-aware retry logic.
v0.5.0 — Request Context & Correlation
Structured RequestContext (operation_id, work_item_id, actor_id, grant_id) threaded through all execution envelopes and tracing spans. HTTP header fallback (X-Request-ID, X-Operation-ID, X-Actor-ID, X-Grant-ID).
v0.4.0 — Catalog Versioning & Cache Validation
SHA-256 catalog version. ETag headers on all catalog reads, If-None-Match conditional requests returning 304 Not Modified. GET /v1/catalog/events change feed with cursor-based pagination.
v0.3.0 — Hybrid Search
POST /v1/capabilities/search with BM25 scoring, optional FastEmbed vector embeddings, tag/server-ID filters, and ranked results.
POST /v1/capabilities/search with BM25 scoring, optional FastEmbed vector embeddings, tag/server-ID filters, and ranked results.
Docs
Document | Description |
Complete usage guide: config, modes, all CLI commands, auth, policy | |
Benchmark methodology, latency percentiles, and profiling results | |
OpenAPI 3.1 spec | |
JSON Schema for | |
Structured logs, OTLP config, trace correlation | |
Build variants, distribution notes | |
Production deployment runbook |
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceAggregates multiple child MCP servers into a single MCP server endpoint, enabling clients to use various tools (e.g., filesystem, Brave Search) through one interface.34
- AlicenseNot gradedqualityDmaintenanceAggregates multiple MCP servers into a single endpoint, enabling LLM clients to access tools, resources, and prompts from various backends through one connection.15MIT
- AlicenseNot gradedqualityBmaintenanceCentralized MCP control plane that proxies multiple upstream MCP servers with tool namespacing, filtering, policy enforcement, audit logging, and health checks.16MIT
- FlicenseNot gradedqualityAmaintenanceActs as a gating proxy for MCP servers, merging tools and applying policy, verification, and audit layers.
Related MCP Connectors
Hosted AgentLux MCP server for marketplace, identity, creator, services, and social flows.
Agent-native collaboration network: orchestrate a team of long-running agents from any MCP client.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Warmplane/warmplane'
If you have feedback or need assistance with the MCP directory API, please join our Discord server