herdmcp
Built-in Cloudflare Tunnel support: the server can publish its Streamable HTTP endpoint over a free quick tunnel (a random *.trycloudflare.com URL) or a named Cloudflare Tunnel with a stable hostname via a CLOUDFLARE_TUNNEL_TOKEN, downloading the cloudflared binary automatically if it is not installed and managing the tunnel lifecycle.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@herdmcpsplit a new pane, start an agent there, and report back"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
herdmcp
Rope in your herd. An MCP server for herdr. It lets any MCP client (Claude Code, Claude.ai, Cursor, …) see and drive your herdr workspaces, panes and coding agents.
TypeScript + Effect 4. The herdr client is an Effect service. The tools are an
effect/aiToolkit, served by Effect's nativeMcpServer.better-auth acts as the OAuth 2.1 authorization server: dynamic client registration, PKCE, and JWT access tokens scoped to
/mcp.Cloudflare Tunnels are built in. Use a free quick tunnel or a named tunnel.
cloudflaredis downloaded automatically if it isn't installed.No Docker, nothing to install. It's a single bundled file with no dependencies, run with
npx herdmcpon Node 22.13 or newer.
It talks to herdr over herdr's own local socket API (newline-delimited JSON on herdr.sock), so it runs on the machine where herdr runs. To reach several machines, run one instance on each.
Quick start
# Local client on the same machine: stdio, no auth
claude mcp add herdr -- npx -y herdmcp stdio
# Remote: create an account, then serve through a Cloudflare quick tunnel
npx herdmcp user add you@example.com # prints a generated password
npx herdmcp serve --tunnel quick # prints https://<random>.trycloudflare.com/mcp
claude mcp add --transport http herdr https://<random>.trycloudflare.com/mcpFor other clients, use the same stdio command (npx -y herdmcp stdio) or the remote URL. If you'll run it often, install it globally with npm i -g herdmcp.
When the client connects, it opens a browser window. Sign in, click Allow, and you're connected.
Related MCP server: OpenCode MCP Gateway
Modes
Command | What it does |
| MCP over stdin/stdout. For local clients. It's unauthenticated because it's your own process. |
| Streamable HTTP at |
| Same, published at a random |
| A named Cloudflare Tunnel ( |
| Creates a user, or resets their password. Public sign-up is disabled. |
Named tunnel setup (stable URL)
In the Cloudflare dashboard, go to Zero Trust → Networks → Tunnels → Create tunnel (type cloudflared) and copy the token.
Add a public hostname, e.g.
herdr.example.com→ servicehttp://127.0.0.1:8787.Run:
CLOUDFLARE_TUNNEL_TOKEN=… herdmcp serve --tunnel token --public-url https://herdr.example.com
Use one tunnel and hostname per machine, for example herdr-laptop.example.com and herdr-vps.example.com.
Configuration
Every flag can also be set with an environment variable (see .env.example):
Env | Default | |
|
| Holds |
|
| Bind address |
| tunnel URL, or | The OAuth issuer and resource origin. It must match the URL clients use. |
|
|
|
| Required for | |
| generated into | better-auth signing secret |
|
| herdr sets this inside its panes. Point it at another session's socket to target that session. |
| unset | Set |
| Path to a specific |
Tools
Read-only | Mutating |
|
|
|
|
|
|
|
|
|
A typical delegation loop runs herdr_pane_split, then herdr_agent_start, then herdr_agent_prompt with wait: true, then herdr_agent_read.
Running it permanently (no Docker)
Install it once with npm i -g herdmcp. On machines without Node, use bun run build:binary instead; it builds a self-contained ~85 MB executable that includes the runtime. Add --target=bun-darwin-arm64 etc. to cross-compile.
Linux (systemd user service), in ~/.config/systemd/user/herdmcp.service:
[Unit]
Description=herdr MCP server
After=network-online.target
[Service]
ExecStart=/usr/bin/env herdmcp serve --tunnel token --public-url https://herdr.example.com
Environment=CLOUDFLARE_TUNNEL_TOKEN=...
Restart=on-failure
[Install]
WantedBy=default.targetThen run systemctl --user enable --now herdmcp (and loginctl enable-linger $USER so it keeps running after you log out).
macOS: use a launchd agent with the same command, or simply run npx herdmcp serve … in a herdr pane.
Security notes
Only accounts you create with
user addcan authorize clients. Each client also needs an explicit consent click.Access tokens are short-lived JWTs (1 h, refreshable). Their audience is
<public-url>/mcp, and they're verified locally against better-auth's JWKS.Dynamic client registration is open, which MCP clients need. Registering a client grants nothing until a user signs in and consents.
Anyone who can authorize can run arbitrary commands in your terminals. Treat the account like SSH access.
The HTTP server binds to
127.0.0.1by default. The tunnel is the only public path.
Development
bun install
bun run dev # watch mode (Bun runs the TypeScript directly)
bun run typecheck
bun run build # → dist/herdmcp.js, the single Node bundle that gets published
npm publish # runs typecheck + build first (prepack)Layout
src/
cli.ts effect/cli entrypoint: serve | stdio | user add
herdr/Herdr.ts Effect service for herdr's socket API
mcp/tools.ts Tool definitions + handlers (effect/ai Toolkit)
mcp/server.ts McpServer layers (stdio + Streamable HTTP)
auth/auth.ts better-auth: email/password, jwt, oauth-provider (SQLite via node:sqlite)
auth/pages.ts Login / consent / home pages
http.ts Node HTTP router: OAuth metadata, auth routes, bearer-checked /mcp
tunnel.ts Cloudflare quick/named tunnel lifecycleReleasing
Publishing happens from GitHub Actions (.github/workflows/publish.yml) whenever a GitHub release is published:
Bump the version in
package.json, commit, and push.Create a release:
gh release create v0.1.1 --generate-notes.
The first time, add an npm granular access token with publish rights as the repo secret NPM_TOKEN. After the package exists, you can switch to trusted publishing (npmjs.com → herdmcp → Settings → Trusted publisher → GitHub Actions, workflow publish.yml). Then delete the secret.
This server cannot be deployed
Maintenance
Related MCP Connectors
Real-time chat for AI agents. Claude Code, Cursor, Cline and Codex join channels over MCP.
Real-time chat hub for AI agents — Claude Code, Cursor, Cline, Codex over MCP or REST.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Related MCP Servers
- AlicenseAqualityBmaintenanceTerminal multiplexer MCP server for orchestrating parallel AI agents. Manages workspaces, panes, surfaces with send_input/read_screen/spawn_agent/stop_agent tools. Supports Claude Code, Codex, Gemini, Cursor CLI agents with lifecycle management, browser automation, and agent status push via Claude --channels.1028Apache 2.0
- FlicenseNot gradedqualityDmaintenanceExposes local OpenCode instances as remote MCP servers for Claude and ChatGPT, enabling terminal access, session management, and interactive human-in-the-loop workflows. It simplifies deployment for local machines using Cloudflare Tunnels to provide secure public connectivity and OAuth support.-
- AlicenseAqualityAmaintenanceMCP server for hyperpanes terminal workspace app, enabling AI agents to compose and launch workspace layouts, inspect and drive terminal panes, stream output, and orchestrate agent hierarchies.471MIT
- FlicenseAqualityBmaintenanceMCP server that exposes the Herdr terminal API as callable tools, enabling AI agents to manage terminal workspaces, tabs, panes, and agents. It dynamically generates tools from the Herdr API schema and communicates via Unix socket.20-