Twynity MCP Project Template
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Twynity MCP Project Templatecheck my external connection status"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Twynity MCP Project Template
A reusable Python/FastMCP starter for MCP servers deployed in Twynity. It combines verified Twynity JWT authentication, project/persona-scoped external connections stored encrypted in MongoDB, MCP Apps UI scaffolding, and clear extension instructions.
What is included
FastMCP server with account-service JWKS JWT verification.
Project scope from the
Persona-IdHTTP header. Connections are keyed by the exact(user_id, persona_id)pair; there is no user-only fallback.MongoDB startup/index setup and Fernet encryption for stored connector credentials.
Twynity manifest, configuration schema, authenticated configuration GET/POST, connection status, and health routes.
Example
say_helloMCP App, usage reporting, and license watcher.Docker build and automated tests.
Related MCP server: Model Context Protocol Template
Start here
Set
mcp_nameinapp/config.py, rename the Python project inpyproject.toml, and update tool/UI names and URIs.Copy
.env.exampleto.env; fill in account service, license, usage, MongoDB, public URL, and allowed-origin settings. Generate a Fernet key:uv run python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"Back up
ENCRYPTION_KEYsecurely. Losing/changing it prevents decrypting existing connection secrets. Do not commit.env.Install dependencies, build the App bundle, and then run the checks. The resource test intentionally verifies the compiled artifact, so the frontend build must happen before pytest:
uv sync --locked cd app/ui/say_hello npm ci npm run build cd ../../.. uv run pytest -q uv run ruff check app testsRun the server:
uv run uvicorn app.main:app --host 0.0.0.0 --port 8000
See docs/TEMPLATE_GUIDE.md for the full setup,
auth contract, routes, tool/UI workflow, and customization checklist. See
AGENTS.md for repository instructions for coding agents.
Twynity identity contract
Every authenticated request must carry a Twynity bearer JWT and the
Persona-Id header. The server verifies the JWT using the configured account
service JWKS and reads the user ID from verified id (or sub) claims. It
never accepts a persona ID as a tool argument. MongoDB stores one upserted
connection per user/persona pair.
The MCP Apps SDK's app.callServerTool() does not let UI code attach arbitrary
HTTP headers. Twynity's host must therefore forward the authenticated bearer
token and Persona-Id when proxying UI-originated MCP tool calls as well as
model-originated calls. If the host does not forward the header, requests fail
closed with a clear missing-header error; the UI must not ask the user to type
or choose a persona ID.
Configuration routes
GET /api/v1/.well-known/mcp.json— public service manifest; declares the project external connection.GET /api/v1/schema— public schema for the example upstream fields.POST /api/v1/configuration— authenticated upsert for the active(user_id, persona_id)connection; secrets are encrypted.GET /api/v1/configuration— authenticated list-style response with safe metadata only; never returns API keys/secrets.GET /api/v1/external-connection/me— authenticated{"connected": bool}.GET /api/v1/health— public liveness response.
The sample fields (name, base_url, api_key, api_secret) are generic
placeholders. Adapt the schema, validation, and UI to the upstream integration;
retain the identity scoping and secret-handling guarantees.
This server cannot be deployed
Maintenance
Related MCP Connectors
The official MCP Server from Mia-Platform to interact with Mia-Platform Console
FastMCP commerce server starter: product catalog, search, and checkout. Deploy to Vercel in 5 min.
Build multi-tenant apps over MCP. Schemas, CRUD, deploys — access control enforced server-side.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Related MCP Servers
- AlicenseCqualityDmaintenancemcp-starter is a secure, starter framework for building MCP servers with JWT-based authentication, multi-tenant enforcement, and schema validation. Built with Node.js and Docker192 npm1MIT
- AlicenseNot gradedqualityDmaintenanceA production-ready MCP server template that connects LLMs and AI agents to external data, tools, and services with built-in OAuth 2.1 authentication, Redis-backed session management, and a modular tools engine.1MIT
- AlicenseAqualityCmaintenanceA starter template for building single-client MCP servers that expose existing REST APIs, deployable via stdio in customer-controlled environments. It provides a structured foundation with validated config, error handling, write authorization, and a mock upstream for local development.2MIT
- FlicenseNot gradedqualityBmaintenanceProvides a production-shaped FastMCP server with embedded MCP App UIs, including authentication, licensing, usage reporting, manifest and health routes, container setup, and deployment workflows.1-