Skip to main content
Glama

Nexus-MCP ⚔


Overview

Nexus-MCP is an enterprise-grade Model Context Protocol (MCP) gateway and security router that gives AI agents (Claude Desktop, Cursor, LangGraph) secure, observable access to internal corporate knowledge.

Raw MCP implementations lack multi-tenancy, dynamic RBAC, tool injection protection, and audit logs. Nexus-MCP bridges this gap by acting as a zero-trust security router and document intelligence server.


Related MCP server: MCPGuard

šŸ” The Enterprise Golden Path

MCP Client ──> Authentication & Tenant Context ──> RBAC Scope Check
                                                          │
                                                          ā–¼
Prometheus & OTel ◄── Response ◄── Schema Extraction ◄── Hybrid RAG (Vector+BM25)

Key Features

  • ⚔ Official Anthropic MCP SDK Integration: Built natively on Anthropic's mcp specification supporting STDIO & SSE JSON-RPC transports.

  • šŸ”’ Multi-Tenant & ACL Isolation: Strictly isolates document search and schema extraction per tenant_id and user acl_groups.

  • šŸ›”ļø Security Router & Prompt Injection Sanitizer: Prevents prompt/tool injection attacks (DROP TABLE, IGNORE INSTRUCTIONS).

  • šŸ” Hybrid Vector + BM25 Retrieval: Reciprocal Rank Fusion (RRF) combining dense vector similarity and BM25 term frequency.

  • šŸ“Š Prometheus & OpenTelemetry Observability: Tracks tool execution counts, p95/p99 latency, and token expenditure.


Quick Start

Installation

pip install nexus-mcp

Or install locally for development:

git clone https://github.com/JasleenSingh/nexus-mcp.git
cd nexus-mcp
pip install -e .

Code Example: Golden Path Demo

Run the included commercial contract intelligence demo:

python examples/contract_intelligence_demo.py

Output:

šŸš€ Starting Nexus-MCP Enterprise Golden Path Demo...
āœ… Ingested document into 4 hierarchical chunks for tenant 'tenant-acme-corp'.

šŸ” Executing Tool [doc_hybrid_search]...
  Found 1 matching chunks with Hybrid Vector + BM25 search.

šŸ“‹ Executing Tool [doc_extract_schema]...
  Extracted Agreement Schema (3 fields):
   • payment_terms: Net 30 days (confidence: 0.92)
   • total_contract_value: $3,500,000.00 (confidence: 0.88)
   • governing_law: State of Delaware (confidence: 0.90)

šŸ“Š Executing Tool [system_health_telemetry]...
  System Health: healthy

✨ Nexus-MCP Golden Path Execution Completed Successfully!

Running Server & CLI

# Start Nexus-MCP server over STDIO transport
nexus-mcp serve --transport stdio

Running Tests & Benchmarks

# Run complete unit, integration, and security test suite
pytest tests/

# Run retrieval accuracy benchmarks (Recall@K & MRR)
pytest tests/integration/test_retrieval_benchmarks.py -v

Project Structure

nexus-mcp/
ā”œā”€ā”€ src/nexus_mcp/
│   ā”œā”€ā”€ models/             # Pydantic v2 domain schemas (TenantContext, DocumentChunk, SearchQuery)
│   ā”œā”€ā”€ document_processor/ # Hierarchical chunker, schema extractor, and Hybrid RAG retriever
│   ā”œā”€ā”€ security/           # RBAC scope validator and input injection sanitizer
│   ā”œā”€ā”€ observability/      # Prometheus metrics and OpenTelemetry trace span exporters
│   ā”œā”€ā”€ mcp_server/         # Official Anthropic MCP Server & tool registrations
│   └── cli/                # Rich CLI interface (nexus-mcp serve)
ā”œā”€ā”€ tests/
│   ā”œā”€ā”€ unit/               # Unit tests (chunker, retriever, schemas, observability)
│   ā”œā”€ā”€ integration/        # MCP JSON-RPC protocol & retrieval benchmarks
│   └── security/           # Adversarial security tests (cross-tenant & prompt injection)
ā”œā”€ā”€ examples/               # Contract intelligence demo & sample commercial agreements
ā”œā”€ā”€ docs/                   # System architecture & tool specs
ā”œā”€ā”€ pyproject.toml
└── README.md

License

Distributed under the MIT License.

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

–Maintainers
–Response time
–Release cycle
–Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    An enterprise infrastructure layer for the Model Context Protocol that provides authentication, RBAC, audit logging, and rate limiting for tool calls. It acts as a secure proxy between AI agents and MCP servers to ensure security and compliance in production environments.
    30
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    A security gateway that enforces policies, tracks data taints, and sandboxes tool calls between AI agents and MCP servers. It provides a secure chokepoint to prevent prompt injection and ensure OWASP ASI compliance through audit logging and deterministic execution.
    1
    Apache 2.0
  • F
    license
    -
    quality
    B
    maintenance
    A zero-trust gateway for securely brokering interactions between AI models and internal tools via the Model Context Protocol, with DLP, prompt injection defense, and LLM-as-a-Judge.
  • A
    license
    -
    quality
    B
    maintenance
    Governed MCP gateway that lets AI agents call tools with policy enforcement, prompt-injection screening, a kill-switch, and tamper-evident signed audit logs.
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Your company's brain for AI agents. Cited, permission-aware knowledge across every system.

  • Shared, permission-aware company context for AI agents, with provenance, approvals and audit.

  • Multi-engine search for AI agents. Trust scoring, local corpus, MCP-native. Self-hostable, BYOK.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/jasleen27/nexus-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server