nous-portal-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@nous-portal-mcpcheck my nous portal status"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Nous Portal MCP
Portable, read-only first adapter for selected Nous Portal capabilities.
Status: early review scaffold. It is not yet authenticated and cannot invoke paid tools.
The first slice exposes:
nous_portal_status— local configuration status without credential output;nous_portal_routes— local derivation of the vendor-specific managed gateway origins with an explicit no-effect receipt.nous_portal_auth_start— request a device code without opening a browser;nous_portal_auth_poll— poll once and atomically persist approved OAuth state without returning token values.
It does not invoke paid tools, copy Hermes credentials, depend on Dione, or send private data. Merely installing the adapter does not start authentication.
The auth library stores each seat's OAuth state outside the plugin directory,
uses mode 0600, and holds an exclusive lock across refresh-token exchange and
atomic replacement. Nous refresh tokens are single-use; copying one into
multiple seats or refreshing it without persisting the rotated token will
invalidate the session.
Configuration
Each adopting seat supplies its own credentials:
NOUS_PORTAL_STATE_DIR=<required private local per-seat state directory>
NOUS_PORTAL_CLIENT_ID=<required Portal OAuth client ID>
NOUS_PORTAL_SPEND_LIMIT_USD=<future paid-call ceiling>
TOOL_GATEWAY_DOMAIN=nousresearch.com
TOOL_GATEWAY_SCHEME=https
FIRECRAWL_GATEWAY_URL=<optional vendor-specific override>NOUS_PORTAL_STATE_DIR has no shared fallback. The adapter refuses auth
configuration until the adopting seat supplies an explicit path. The path
must be on a local filesystem owned by exactly one seat: POSIX advisory locks
are not a safe coordination mechanism across NFS or other shared/network
filesystems. Do not distribute access or refresh tokens through a shared
.env.
Device login is deliberately two-step. nous_portal_auth_start returns the
verification URL and user-facing code only to the adopting MCP client while
keeping the private device code in the seat's mode-0600 state. It never opens
a browser or sends the code to Discord. After the operator authorizes the
request, nous_portal_auth_poll performs one poll; pending authorization
returns a retry hint, and success atomically stores tokens without disclosing
them in the tool result.
Hermes derives managed origins as
<vendor>-gateway.<TOOL_GATEWAY_DOMAIN>, with an optional vendor-specific
override. The current server reproduces that topology without making a
network request. Until a private state directory is configured, status returns
configuration_required; until that store contains OAuth state, it returns
authentication_required.
Related MCP server: SkyStage MCP Test Server
Installation surfaces
The same dependency-free Python stdio server supports all clients. Packaging is deliberately separate from credentials: every adopting seat supplies its own OAuth state and spending authority.
Python / generic MCP
Install from a pinned Git commit:
python3 -m pip install \
"nous-portal-mcp @ git+https://github.com/callisto-syn/nous-portal-mcp@<commit>"The installed stdio command is:
nous-portal-mcpSee examples/generic-stdio.json.
Claude Code
Install the Python artifact in the construct's image or environment, then add
the server entry from examples/claude-code.mcp.json. Each construct must use
its own private state directory and receive its own adoption and spending
clearance. Do not copy another seat's OAuth store: Nous refresh tokens rotate
and are single-use.
For image-based deployments, examples/Dockerfile builds from the reviewed
checkout supplied as its build context. Pin the checkout before building.
Codex
The repository is also a Codex plugin. Its .codex-plugin/plugin.json points
to the repository-local .mcp.json, which launches the same server source.
Portability acceptance
Portability is not considered proven until a clean environment can:
install a pinned artifact;
start
nous-portal-mcpover stdio;complete an MCP initialize and tools/list handshake;
keep credentials and state outside the installed artifact;
uninstall without removing or exposing another seat's state.
Development
python3 -m unittest discover -s testsThe design and prior-art record lives in docs/step0.md.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityBmaintenanceRead-only MCP server for Google Search Console, with browser-based OAuth flow and local token storage, enabling querying search analytics, site lists, and URL inspection.Last updated8MIT
- Flicense-qualityCmaintenanceMinimal MCP server for testing SkyStage's self-auth auto-detection feature. It includes tools like ping, echo, server_info, and read_secret, and uses a mock OAuth provider for login.Last updated
- AlicenseAqualityBmaintenanceRead-only MCP server for the RareCloud API, enabling AI agents to list servers, browse the catalog, check billing, and plan deployments.Last updated10021MIT
- Alicense-qualityCmaintenanceProvides a sovereign, MIT-licensed MCP server for professional-service workflows, running entirely on your infrastructure with Ed25519 cryptographic signing for every action.Last updatedMIT
Related MCP Connectors
Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
Streamable HTTP MCP server for Google Calendar and Sheets with OAuth login.
Read-only MCP server for ClassQuill, a tutoring-business-management platform.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/callisto-syn/nous-portal-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server