Skip to main content
Glama

MCP Multiagent Bridge

Production-ready Python MCP server for secure multi-agent coordination with comprehensive safeguards.

Overview

Enables multiple LLM agents (Claude, Codex, GPT, etc.) to collaborate safely through the Model Context Protocol without sharing workspaces or credentials. Built with security-first architecture and production-grade safeguards.

Use cases:

  • Backend agent coordinating with frontend agent on different codebases

  • Security review agent validating changes from development agent

  • Specialized agents collaborating on complex multi-step workflows

  • Any scenario requiring isolated agents to communicate securely


Related MCP server: JustClone Coordination MCP Server

Key Features

πŸ”’ Security Architecture

Authentication & Authorization:

  • HMAC-SHA256 session token authentication

  • Automatic secret redaction (API keys, passwords, tokens, private keys)

  • 3-hour session expiration with automatic cleanup

  • SQLite WAL mode for atomic, race-condition-free operations

4-Stage YOLO Guardβ„’: Command execution (optional) requires multiple confirmation layers:

  1. Environment gate - explicit YOLO_MODE=1 opt-in

  2. Interactive typed confirmation phrase

  3. One-time validation code (prevents automation)

  4. Time-limited approval tokens (5-minute TTL, single-use)

Rate Limiting:

  • Token bucket algorithm with configurable windows

  • Default: 10 requests/minute, 100/hour, 500/day

  • Per-session tracking with automatic reset

  • Prevents abuse while allowing legitimate bursts

Audit Trail:

  • Comprehensive JSONL logging of all operations

  • Timestamps, session IDs, actions, results

  • Tamper-evident sequential logging

  • Supports compliance and forensic analysis

πŸ—οΈ Production-Ready Architecture

  • Message-only bridge - No auto-execution, returns proposals only

  • Schema validation - Strict JSON schemas for all MCP tools

  • Command validation - Configurable whitelist/blacklist patterns

  • Comprehensive error handling - Graceful degradation, informative errors

  • Extensible design - Plugin architecture for future backends

πŸ“¦ Platform Support

Works with any MCP-compatible LLM:

  • Claude Code, Claude Desktop, Claude API

  • OpenAI models (via MCP adapters)

  • Anthropic API models

  • Custom/future models (not tied to specific backend)


Installation

# Clone repository
git clone https://github.com/dannystocker/mcp-multiagent-bridge.git
cd mcp-multiagent-bridge

# Install dependencies
pip install mcp>=1.0.0

# Run tests
python test_security.py

Full setup: See QUICKSTART.md


Documentation

Getting Started:

Production Hardening:

Security & Compliance:

  • SECURITY.md - Threat model, responsible disclosure policy

  • YOLO_MODE.md - Command execution safety guide

  • Policy compliance: Anthropic AUP, OpenAI Usage Policies

Contributing:


Technical Stack

  • Python 3.11+ - Modern Python with type hints

  • SQLite - Atomic operations with WAL mode

  • MCP Protocol - Model Context Protocol integration

  • pytest - Comprehensive test suite

  • CI/CD - GitHub Actions (tests, security scanning, linting)


Project Statistics

  • Lines of Code: ~6,700 (including tests, production scripts + documentation)

  • Test Coverage: βœ… Core security validated (482 operations, zero failures)

  • Documentation: 3,500+ lines across 11 markdown files

  • Dependencies: 1 (mcp>=1.0.0, pinned for reproducibility)

  • License: MIT

Production Test Results (November 2025)

10-Agent Stress Test:

  • βœ… 1.7ms average latency (58x better than 100ms target)

  • βœ… 100% message delivery (zero failures)

  • βœ… 482 concurrent operations (zero race conditions)

  • βœ… Perfect data integrity (SQLite WAL validated)

9-Agent SΒ² Production Hardening:

  • βœ… 90-minute test (idle recovery, keep-alive, watchdog)

  • βœ… <5 min task reassignment (automated worker failure recovery)

  • βœ… 100% keep-alive delivery (30-minute validation)

  • βœ… <50ms push notifications (filesystem watcher, 428x faster than polling)

Full Report: See PRODUCTION.md


Development

# Install dev dependencies
pip install -r requirements.txt

# Install pre-commit hooks
pip install pre-commit
pre-commit install

# Run test suite
pytest

# Run security tests
python test_security.py

See CONTRIBUTING.md for complete development workflow.


Production Status

βœ… Production-Ready (Validated November 2025)

Successfully tested with:

  • βœ… 10-agent stress test (94 seconds, 100% reliability)

  • βœ… 9-agent production deployment (90 minutes, full hardening)

  • βœ… 1.7ms average latency (58x better than target)

  • βœ… Zero data corruption in 482 concurrent operations

  • βœ… Automated recovery from worker failures (<5 min)

Recommended for:

  • Production multi-agent coordination

  • Development and testing workflows

  • Isolated workspaces (recommended)

  • Human-supervised operations

  • 24/7 autonomous agent systems (with production scripts)

Production deployment:


Support


License

MIT License - Copyright Β© 2025 Danny Stocker

See LICENSE for full terms.


Acknowledgments

Built with Claude Code and Model Context Protocol.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables agentic coordination by connecting humans and AI agents through group messaging, project tracking, and milestone management. It provides tools for consensus voting, progress checkpoints, and multi-session collaboration across various agentic platforms.
    32
    1
    MIT
  • F
    license
    Not graded
    quality
    Not graded
    maintenance
    A production-grade coordination hub that enables AI agents and human teams to work as a single organism by sharing tasks, context, decisions, and persistent memory across projects. It features two-tier agentic memory with per-agent hot caches, inter-agent messaging, and multi-agent authorship tracking for seamless collaboration.
    2
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables multiple LLM agents across devices to form teams, share knowledge, memory, and tasks with live status via a web dashboard and distributed-systems reliability.
    Apache 2.0