SentinelX Core MCP
SentinelX Core MCP
SentinelX Core用MCP/OAuthブリッジ。サーバーエージェントをOIDCトークン検証付きのMCPツールとして公開します。
SentinelX Core MCPは、MCPクライアント(Claude、ChatGPT、Cursor、またはその他のMCP互換エージェント)と、実行中のSentinelX Coreインスタンスの間に位置します。受信したOAuth BearerトークンをJWKSエンドポイントに対して検証し、ツール呼び出しをアップストリームのエージェントに転送します。
アーキテクチャ
Claude / ChatGPT / Cursor / any MCP client
│
│ MCP + OAuth Bearer token
▼
sentinelx-core-mcp (public, port 8098)
│ validates token via OIDC/JWKS
│ HTTP + internal Bearer token
▼
sentinelx-core (local only, port 8091)
│
└─ command allowlist, structured editing, uploads, services2つの独立した認証レイヤー:
レイヤー | 検証方法 | トークンタイプ |
外部 (MCP) |
| OAuthアクセストークン (IDプロバイダー発行) |
内部 (エージェント) |
| 静的ベアラートークン ( |
Related MCP server: mcp_sdk_eyra_accelerator_v19
公開されるMCPツール
ツール | 機能 | 必要なスコープ |
| ヘルスチェック | public |
| エージェントの実行状態 |
|
| 許可されたコマンドの実行 |
|
| サービス操作 (開始/停止/再起動/リロード/ステータス) |
|
| 登録済みサービスの再起動 |
|
| 構造化ファイル編集 (シェルクォーティング不要) |
|
| 大規模編集アップロードの初期化 |
|
| 編集用ロールファイルのアップロード |
|
| 大規模編集の完了 |
|
| ファイルのアップロード (URLまたはbase64) |
|
| チャンクアップロードの初期化 |
|
| チャンクのアップロード |
|
| チャンクアップロードの完了 |
|
| 一時的なbash/python3スクリプトの実行 |
|
| 許可されたコマンド、サービス、場所、プレイブック |
|
| エージェントからの埋め込みヘルプ |
|
要件
実行中のSentinelX Coreインスタンス
OIDC互換のIDプロバイダー (Keycloak、Auth0、Authentik、Zitadel、またはJWKSエンドポイントを持つプロバイダー)
Python 3.11以上
クイックスタート
サーバーへのインストール
git clone https://github.com/pensados/sentinelx-core-mcp.git
cd sentinelx-core-mcp
sudo bash install.sh次に設定を行います:
sudo nano /etc/sentinelx-core-mcp/sentinelx-core-mcp.env最低限必要な設定:
MCP_PORT=8098
SENTINELX_URL=http://127.0.0.1:8091
SENTINELX_TOKEN=your_internal_agent_token
OIDC_ISSUER=https://auth.example.com/realms/sentinelx
OIDC_JWKS_URI=https://auth.example.com/realms/sentinelx/protocol/openid-connect/certs
OIDC_EXPECTED_AUDIENCE=
RESOURCE_URL=https://sentinelx.example.com
AUTH_DEBUG=false再起動して確認します:
sudo systemctl restart sentinelx-core-mcp
sudo systemctl status sentinelx-core-mcp
sudo journalctl -u sentinelx-core-mcp -n 50 --no-pagerローカル開発
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
./run.shローカルのデフォルト値:
MCPポート: 8099
アップストリーム SentinelX Core:
http://127.0.0.1:8092
インストールパス
パス | 内容 |
| アプリケーションコード |
| 環境設定 |
| ログ |
| systemdユニット |
リバースプロキシの接続
/mcpのMCPエンドポイントはHTTPS経由で公開する必要があります。Nginx設定例:
server {
listen 443 ssl http2;
server_name sentinelx.example.com;
ssl_certificate /path/to/fullchain.pem;
ssl_certificate_key /path/to/privkey.pem;
location = /mcp {
proxy_pass http://127.0.0.1:8098/mcp;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Authorization $http_authorization;
proxy_buffering off;
proxy_request_buffering off;
proxy_read_timeout 3600s;
add_header Cache-Control "no-cache";
}
}Claudeへの接続
Claudeの設定にMCPサーバーを追加します:
https://sentinelx.example.com/mcp初回使用時にClaudeがOAuthログインを求めます。認証後、トークンのスコープで許可されたすべてのツールにアクセスできるようになります。
ChatGPTへの接続
MCPサーバーのURLをGPT Actionとして、またはChatGPTコネクタ設定に登録します。OAuthフローは、認可コードフローをサポートする任意のOIDCプロバイダーで動作します。
MCPスモークテスト (curl)
MCPエンドポイントはHTTP上のJSON-RPCを使用します。最小限のセッション例:
1. 初期化
SESSION=$(curl -si -X POST https://sentinelx.example.com/mcp \
-H "Accept: application/json, text/event-stream" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc":"2.0","id":"1","method":"initialize",
"params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"curl","version":"0.1"}}
}' | grep -i mcp-session-id | awk '{print $2}' | tr -d '\r')2. 初期化通知
curl -s -X POST https://sentinelx.example.com/mcp \
-H "Content-Type: application/json" \
-H "mcp-session-id: $SESSION" \
-d '{"jsonrpc":"2.0","method":"notifications/initialized"}'3. pingの呼び出し (公開)
curl -s -X POST https://sentinelx.example.com/mcp \
-H "Content-Type: application/json" \
-H "mcp-session-id: $SESSION" \
-d '{"jsonrpc":"2.0","id":"2","method":"tools/call","params":{"name":"ping","arguments":{}}}' \
| sed -n 's/^data: //p' | jq4. 保護されたツールの呼び出し
curl -s -X POST https://sentinelx.example.com/mcp \
-H "Content-Type: application/json" \
-H "mcp-session-id: $SESSION" \
-H "Authorization: Bearer YOUR_OAUTH_ACCESS_TOKEN" \
-d '{"jsonrpc":"2.0","id":"3","method":"tools/call","params":{"name":"sentinel_exec","arguments":{"cmd":"uptime"}}}' \
| sed -n 's/^data: //p' | jqIDプロバイダーの設定
OIDC互換のプロバイダーであれば何でも動作します: Keycloak、Auth0、Authentik、Zitadelなど。必要なもの:
認可コードフロー(対話型)またはクライアントクレデンシャル(マシン間)用に設定されたクライアント
公開したいツールと一致するカスタムスコープ (
sentinelx:exec,sentinelx:editなど)プロバイダーのJWKS URI
ClaudeおよびChatGPT用: クライアントに登録された正しいリダイレクトURI
これらを環境変数ファイルに設定します:
OIDC_ISSUER=https://your-provider.example.com/realms/your-realm
OIDC_JWKS_URI=https://your-provider.example.com/realms/your-realm/protocol/openid-connect/certs
OIDC_EXPECTED_AUDIENCE= # set to your client ID, or leave empty to skip audience validationOIDC_EXPECTED_AUDIENCE について
プロバイダーが
audクレームにクライアントIDを含める場合(機密クライアントで一般的)、クライアントIDを設定してください不明な場合は空のままにしてください — サーバーはオーディエンス検証をスキップします
トークンが拒否される場合は、トークンをデコード (
echo $TOKEN | cut -d. -f2 | base64 -d | jq) してaudクレームを確認してください
Claudeへの接続
Claudeの設定にMCPサーバーを追加します:
https://sentinelx.example.com/mcp初回使用時にClaudeはIDプロバイダーにリダイレクトします。以下を確認してください:
リダイレクトURI
https://claude.ai/api/mcp/auth_callbackがOIDCクライアントに登録されていることサーバーが正しい
authorization_servers値を持つ/.well-known/oauth-protected-resourceを公開していること
ChatGPTへの接続
MCP URLをGPT Actionとして登録します。クライアントのリダイレクトURIに https://chatgpt.com/aip/g-*/oauth/callback を追加してください。
Keycloakを使用した完全なエンドツーエンドのチュートリアル(トークン取得、Claude設定、スモークテスト、トラブルシューティングを含む)については、docs/keycloak-example.md を参照してください。
Keycloakを使用していない場合は、Authentik、Zitadel、Zitadel Cloudのクイックスタートガイドである docs/oidc-alternatives.md を参照してください。
トラブルシューティング
ツールが Missing Authorization header で失敗する
MCPクライアントがOAuthトークンを送信していません。認証フローが正常に完了したか確認してください。
Invalid access token
OIDC_ISSUER と OIDC_JWKS_URI がIDプロバイダーと完全に一致しているか確認してください。一時的に AUTH_DEBUG=true を有効にして、ログでトークン検証の詳細を確認してください。
Missing required scope
トークンにそのツールが必要とするスコープが含まれていません。OIDCクライアント設定にスコープを追加し、再認証してください。
ping は動作するが他のツールがすべて失敗する
通常は認証の問題です。ping は公開されていますが、他のすべてのツールには適切なスコープを持つ有効なトークンが必要です。
MCPは起動するがSentinelX Coreに到達できない
SENTINELX_URL が実行中のコアインスタンスを指していること、および SENTINELX_TOKEN がコアの SENTINEL_TOKEN と一致していることを確認してください。
セキュリティ上の注意
MCPサービスをHTTPSおよびリバースプロキシの背後に配置してください
必要なスコープのみを持つ専用のOIDCクライアントを使用してください
SENTINELX_TOKENとOIDCクライアントのクレデンシャルを定期的にローテーションしてください実行監査ログ (
/var/log/sentinelx/exec.log) を定期的に確認してくださいAUTH_DEBUG=trueはトークンのクレームをログに記録するため、本番環境では無効にしてください
関連
sentinelx-core — 基盤となるHTTPエージェント: コマンド実行、構造化編集、アップロード、サービス管理。
ライセンス
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA standalone MCP server that exposes API endpoints as tools for AI assistants by proxying requests to a target API defined in an OpenAPI specification. It supports various authentication methods and utilizes Server-Sent Events (SSE) to facilitate integration with clients like Claude and ChatGPT.-
- FlicenseNot gradedqualityDmaintenanceA standalone MCP server that exposes Eyra Accelerator API endpoints as tools for AI assistants via SSE transport. It enables secure interaction with the target API by proxying requests and handling authentication automatically.-
- FlicenseNot gradedqualityDmaintenanceA production-ready MCP server that authenticates agents via OAuth 2.1 Bearer tokens, validates JWTs with JWKS, enforces tool-level scopes and roles, and logs the full delegation chain.-
- FlicenseAqualityDmaintenanceStandalone MCP server that proxies tool calls to Ottoauth HTTP endpoints, enabling account creation and dynamic service interaction.7-