mock-mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mock-mcp-serverWhat's the weather in Tokyo?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Mock MCP Server with Kuadrant Gateway
This project demonstrates an MCP (Model Context Protocol) server protected by Kuadrant API gateway with token separation — the gateway and backend use different tokens for authentication.
Architecture
┌─────────────────────────────────────────────────────────────────────────────┐
│ Client │
│ Bearer gateway-api-key-xyz │
└─────────────────────────────────────┬───────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ Kuadrant Gateway │
│ ┌─────────────────────────────────────────────────────────────────────┐ │
│ │ AuthPolicy (API Key validation via Authorino) │ │
│ │ allNamespaces: true + selector: authorino.kuadrant.io/managed │ │
│ └─────────────────────────────────────────────────────────────────────┘ │
│ │ │
│ ┌─────────────────────────────────────────────────────────────────────┐ │
│ │ HTTPRoute + RequestHeaderModifier (SET Authorization header) │ │
│ │ set: Authorization = "Bearer backend-mcp-secret-abc123" │ │
│ └─────────────────────────────────────────────────────────────────────┘ │
└─────────────────────────────────────┬───────────────────────────────────────┘
│
▼ (with replaced header)
┌─────────────────────────────────────────────────────────────────────────────┐
│ MCP Backend (mock-mcp-server) │
│ Validates: Bearer backend-mcp-secret-abc123 │
└─────────────────────────────────────────────────────────────────────────────┘Related MCP server: build_club_mcp
Token Flow
Stage | Token | Purpose |
Client → Gateway |
| Authenticates to Kuadrant/Authorino |
Gateway → Backend |
| Backend validates request |
Key Configuration Files
File | Description |
| HTTPRoute + AuthPolicy + Secrets |
| Integration test script |
Quick Start
1. Apply Configuration
# Apply the Kuadrant gateway configuration
oc apply -f kuadrant-mcp-gateway-api-key-injection.yaml
# Update backend to use backend token
oc set env deployment/mock-mcp-server -n ai501 --overwrite MCP_BEARER_TOKEN=backend-mcp-secret-abc123
oc rollout restart deployment/mock-mcp-server -n ai5012. Run Tests
./test-mcp-gateway.sh [gateway_host]Example output:
==============================================
Kuadrant MCP Gateway Test
==============================================
Gateway Host: a4bf32c33d79e4f92b3721393a6c3202-953674145.us-east-2.elb.amazonaws.com
Gateway Token: gateway-ap...
Backend Token: backend-mc...
=== Basic Connectivity Tests ===
Testing: Health check ... PASS (HTTP 200)
=== MCP Protocol Tests ===
Testing: MCP capabilities ... PASS (HTTP 200)
Testing: MCP tools list ... PASS
Testing: MCP tool call (calculate) ... PASS
=== Token Replacement Tests ===
Testing: Authorization header replaced ... PASS
Backend received: Authorization: Bearer backend-mcp-secret-abc123
=== Security Tests ===
Testing: Invalid gateway token rejection ... PASS (HTTP 401 - rejected)
==============================================
Test Summary: Passed=6 Failed=0
==============================================HTTPRoute with RequestHeaderModifier
Important: Use set (not replace) per Gateway API spec:
spec:
rules:
- matches:
- path:
type: PathPrefix
value: /mcp
filters:
- type: RequestHeaderModifier
requestHeaderModifier:
set:
- name: Authorization
value: "Bearer backend-mcp-secret-abc123"
backendRefs:
- kind: Service
name: mock-mcp-server
port: 8080AuthPolicy with API Key Validation
apiVersion: kuadrant.io/v1
kind: AuthPolicy
metadata:
name: mock-mcp-auth-dedicated
namespace: ai501
spec:
targetRef:
group: gateway.networking.k8s.io
kind: HTTPRoute
name: mock-mcp-server-route
rules:
authentication:
"api-key-valid":
apiKey:
allNamespaces: true # Required to find secrets in kuadrant-system
selector:
matchLabels:
authorino.kuadrant.io/managed: "true"
credentials:
in: authorization_header
keySelector: Bearer
priority: 0Secrets
Gateway API Key (in kuadrant-system namespace):
apiVersion: v1
kind: Secret
metadata:
name: api-key-secret
namespace: kuadrant-system
labels:
authorino.kuadrant.io/managed: "true"
type: Opaque
stringData:
key: gateway-api-key-xyzBackend Bearer Token (in ai501 namespace):
apiVersion: v1
kind: Secret
metadata:
name: mock-mcp-secret
namespace: ai501
type: Opaque
stringData:
bearer-token: backend-mcp-secret-abc123MCP Server Endpoints
Endpoint | Method | Description |
| GET | Health check (no auth) |
| GET | MCP protocol capabilities |
| GET | List available tools |
| POST | Call a tool |
| GET | List resources |
| GET | Debug endpoint showing received headers |
MCP Tools
Tool | Description | Parameters |
| Get weather for a location |
|
| Basic arithmetic |
|
| Get current time |
|
Debugging
Check AuthPolicy Status
oc get authpolicy mock-mcp-auth-dedicated -n ai501 -o yaml | grep -A5 "status:"Check Authorino Logs
oc logs -n kuadrant-system -l app=authorino --tail=50Test Header Replacement
curl -s http://<gateway-host>/debug-headers \
-H "Host: mock-mcp.ai501.example.com" \
-H "Authorization: Bearer gateway-api-key-xyz" | jq .AuthorizationFiles Overview
File | Description |
| Python/FastAPI MCP server |
| Container build |
| Kuadrant + HTTPRoute + Secrets |
| Integration test script |
| This file |
Cleanup
oc delete -f kuadrant-mcp-gateway-api-key-injection.yamlThis server cannot be deployed
Maintenance
Related MCP Connectors
Hosted MCP server for Xweather weather data: conditions, forecasts, alerts, and more.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Hosted MCP endpoint with realistic fake data for prototyping agents. 12 tools, no setup.
MCP server for progressive tool usage at any scale (see https://klavis.ai)
Related MCP Servers
- FlicenseBqualityDmaintenanceA demonstration server showcasing MCP capabilities with basic tools including addition calculations and weather API integration for fetching city weather data.2-
- FlicenseNot gradedqualityDmaintenanceMCP server with example tools for arithmetic and greeting, designed for deployment on Amazon Bedrock AgentCore Runtime with OAuth authentication.4-
- AlicenseNot gradedqualityDmaintenanceThis MCP server provides tools like weather lookup and follows the Model Context Protocol for tool calling, resource sharing, and prompt templates.261 npmMIT
- FlicenseNot gradedqualityDmaintenanceA demonstration MCP server using FastMCP and streamable-http transport. It provides tools like weather and Kusto queries, secured by Microsoft Entra ID OAuth.-