koba-mcp-bridge
Planned integration for Git workflows, enabling agents to manage repositories, branches, commits, and other version control operations.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@koba-mcp-bridgestart a Ghidra analysis on the firmware binary and save the findings"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-bridge
Modular MCP platform with one public gateway, one central OAuth authorization service, and isolated private provider runtimes managed as one Docker Compose stack.
Architecture
ChatGPT / MCP clients
|
| HTTPS
v
gateway
| \
| \-- OAuth routes ----------> auth
| |
| +-- GitHub OAuth / DCR / token state
|
+-- /github/mcp -------------> github
+-- /gitlab/mcp -------------> gitlab
+-- /files/mcp -------------> files
+-- /web/mcp -------------> curl
+-- /analysis/mcp -------------> analysis ---> ghidra (private)
+-- /admin -------------> managementThe public domain is mcp.koba-nexus.ru. Gateway is the only process assigned that
public domain. Auth and all provider runtimes remain private on the Compose network.
Related MCP server: production-grade-mcp-agentic-system
Public MCP surfaces
/mcp
/github/mcp
/gitlab/mcp
/files/mcp
/web/mcp
/analysis/mcp
/adminNative Ghidra is not a public MCP surface. Analysis is the external structured-analysis contract; Ghidra is an implementation backend.
OAuth boundary
There is one OAuth authorization server:
https://mcp.koba-nexus.ruand one GitHub OAuth callback:
https://mcp.koba-nexus.ru/auth/callbackEvery MCP endpoint is an independent RFC 8707 resource audience under that issuer. Examples:
https://mcp.koba-nexus.ru/mcp
https://mcp.koba-nexus.ru/files/mcp
https://mcp.koba-nexus.ru/analysis/mcpThe auth runtime owns GitHub OAuth credentials, DCR registrations, authorization
transactions, refresh state and audience-bound FastMCP tokens. Gateway owns public
routing, protected-resource metadata and local verification of already-issued signed
tokens. GitHub OAuth credentials are never configured on provider runtimes or management.
Repository layout
src/
├── auth_service/
├── bridge/
├── common/
├── management/
└── modules/
├── github/
├── gitlab/
├── files/
├── curl/
├── analysis/
└── ghidra/Runtime and deployment isolation
Production is one Git-backed Coolify Docker Compose application. The Compose file is the
topology authority and starts separate containers for auth, gateway, management,
github, gitlab, files, curl, analysis, and ghidra.
Deployments may rebuild or recreate the stack. Runtime correctness does not depend on selective-restart scripts. Each service has its own restart policy, and Compose dependencies exist only where a runtime cannot perform its primary job without another service: GitHub and GitLab require Management for account resolution, while Analysis requires Ghidra. Gateway is deliberately not health-gated on provider availability, so one broken provider does not prevent the remaining MCP surfaces from starting and being used to repair the system.
The multi-stage Dockerfile keeps rebuilds fast by installing locked dependencies before copying runtime-specific source trees, so unchanged stages reuse the local Docker cache.
See deploy/coolify/README.md for production configuration and failure-isolation rules.
Locked Python dependencies
Production and CI install dependencies from committed uv.lock:
uv sync --frozen --no-dev --no-install-projectThis prevents clean deployments from resolving a different dependency graph.
Files
Files are immutable and content-addressed. Public file identifiers are content IDs; physical storage paths stay internal. Files, Web/curl and other consumers use the same canonical object store contract.
Analysis
Analysis dynamically adapts the internal analysis backend catalog into the project terminology and validates/normalizes arguments before dispatch. Internal backend naming is not part of the external ChatGPT contract.
Management
Management owns provider accounts, encrypted credentials, invocation telemetry, settings, Files administration and the Admin UI. Provider runtimes resolve account data through the private management API rather than opening the management database directly.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
MCP server for building and testing AI agents with multi-model experimentation and insights.
A registry of AI agent tools — MCP servers, APIs, CLIs, SDKs — kept current by automated ingestion.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Related MCP Servers
- AlicenseBqualityDmaintenanceProduction-grade MCP server that gives AI agents safe access to your local dev environment: filesystem, databases, processes, and OpenAPI specs.1543 npm3MIT
- AlicenseNot gradedqualityDmaintenanceA production-grade MCP server designed for multi-tenant, authenticated, and observable AI agent systems, enabling secure tool execution across heterogeneous data sources.66MIT
- FlicenseNot gradedqualityDmaintenanceExposes MCP tools that enable remote LLMs to query local Docker containers, OS processes, and system services in real time.-
- AlicenseNot gradedqualityAmaintenanceEnables AI clients to securely control and interact with a local Windows machine through 218 configurable tools for files, Git, processes, Windows UI, browser automation, WSL, Office, recovery, skills, and child MCP servers.11 npmMIT