Skip to main content
Glama
kevin-rieck

Managed OPC UA MCP Server

by kevin-rieck

Managed OPC UA MCP Server

A TypeScript MCP server that exposes OPC UA read access through server-side authorization and Operator-defined Semantic Controls for safe agent interaction.

See docs/plan.md, docs/operator-guide.md, and CONTEXT.md.

Security posture

  • No arbitrary OPC UA writes.

  • Reads rely on OPC UA Server credentials and roles for authorization.

  • Optional Read Entry Points guide agent discovery.

  • Native browse_node, inspect_node(s), read_node(s), and opcua://model-context expose qualified, source-grounded inspection.

  • Writes use Operator-defined Semantic Controls only.

  • High-risk controls are rejected in v1.

  • Control attempts are audited.

  • Secrets must be provided through environment variables, not literal YAML values.

Related MCP server: MCP Starter

Development

npm install
npm run typecheck
npm test

Local use

Read the Operator safety guide before enabling controls.

Copy examples/local.config.yaml to a non-committed local config and edit it for your OPC UA Server. Validate locally, run online diagnostics, and generate commissioning review artifacts before serving:

cp examples/local.config.yaml opcua-mcp.local.yaml
npm run dev -- validate --config opcua-mcp.local.yaml
npm run dev -- doctor --config opcua-mcp.local.yaml --format json
npm run dev -- setup --config opcua-mcp.local.yaml \
  --out opcua-mcp.draft.local.yaml \
  --report commissioning-report.local.md
npm run dev -- validate --config opcua-mcp.draft.local.yaml
npm run dev -- doctor --config opcua-mcp.draft.local.yaml --format json
npm run dev -- serve --config opcua-mcp.draft.local.yaml

setup performs bounded metadata-only discovery. Generated Semantic Control candidates remain comments and cannot execute until an Operator reviews and manually promotes them into the Control Catalog. See the commissioning workflow for report interpretation, exit codes, redaction, and safety boundaries.

Write examples and integration write tests must only target simulator, test, or otherwise safe Nodes approved by an Operator.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    A demonstration MCP server built in TypeScript that shows how to implement stdio-based communication for integration with MCP clients. Serves as a template for building custom MCP servers with strong typing and maintainability.
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    An agent-ready TypeScript template for building Model Context Protocol (MCP) servers with standardized discovery flows and permission-aware tools. It provides pre-configured core and operable profiles to help developers quickly implement, test, and distribute production-ready MCP services.
    37 npm
    MIT
  • F
    license
    B
    quality
    D
    maintenance
    TypeScript MCP server for accessing Department of Labor enforcement data, OSHA inspections, and SAM.gov contract opportunities via natural language queries.
    28
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    An MCP server that provides TypeScript 7 native language server capabilities (go to definition, find references, hover types, diagnostics) to coding agents, using the Go-based tsc compiler for fast and accurate semantic analysis.
    127 npm
    1
    MIT