Skip to main content
Glama

SentinelX Core MCP

SentinelX Core用MCP/OAuthブリッジ。サーバーエージェントをOIDCトークン検証付きのMCPツールとして公開します。

SentinelX Core MCPは、MCPクライアント(Claude、ChatGPT、Cursor、またはその他のMCP互換エージェント)と、実行中のSentinelX Coreインスタンスの間に位置します。受信したOAuth BearerトークンをJWKSエンドポイントに対して検証し、ツール呼び出しをアップストリームのエージェントに転送します。


アーキテクチャ

Claude / ChatGPT / Cursor / any MCP client
        │
        │  MCP  +  OAuth Bearer token
        ▼
  sentinelx-core-mcp   (public, port 8098)
        │  validates token via OIDC/JWKS
        │  HTTP  +  internal Bearer token
        ▼
  sentinelx-core        (local only, port 8091)
        │
        └─ command allowlist, structured editing, uploads, services

2つの独立した認証レイヤー:

レイヤー

検証方法

トークンタイプ

外部 (MCP)

sentinelx-core-mcp (OIDC/JWKS経由)

OAuthアクセストークン (IDプロバイダー発行)

内部 (エージェント)

sentinelx-core

静的ベアラートークン (SENTINELX_TOKEN)


Related MCP server: mcp_sdk_eyra_accelerator_v19

公開されるMCPツール

ツール

機能

必要なスコープ

ping

ヘルスチェック

public

sentinel_state

エージェントの実行状態

sentinelx:state

sentinel_exec

許可されたコマンドの実行

sentinelx:exec

sentinel_service

サービス操作 (開始/停止/再起動/リロード/ステータス)

sentinelx:service

sentinel_restart

登録済みサービスの再起動

sentinelx:restart

sentinel_edit

構造化ファイル編集 (シェルクォーティング不要)

sentinelx:edit

sentinel_edit_upload_init

大規模編集アップロードの初期化

sentinelx:edit

sentinel_edit_upload_file

編集用ロールファイルのアップロード

sentinelx:edit

sentinel_edit_upload_complete

大規模編集の完了

sentinelx:edit

sentinel_upload_file

ファイルのアップロード (URLまたはbase64)

sentinelx:upload

sentinel_upload_init

チャンクアップロードの初期化

sentinelx:upload

sentinel_upload_chunk

チャンクのアップロード

sentinelx:upload

sentinel_upload_complete

チャンクアップロードの完了

sentinelx:upload

sentinel_script_run

一時的なbash/python3スクリプトの実行

sentinelx:script

sentinel_capabilities

許可されたコマンド、サービス、場所、プレイブック

sentinelx:capabilities

sentinel_help

エージェントからの埋め込みヘルプ

sentinelx:capabilities


要件

  • 実行中のSentinelX Coreインスタンス

  • OIDC互換のIDプロバイダー (Keycloak、Auth0、Authentik、Zitadel、またはJWKSエンドポイントを持つプロバイダー)

  • Python 3.11以上


クイックスタート

サーバーへのインストール

git clone https://github.com/pensados/sentinelx-core-mcp.git
cd sentinelx-core-mcp
sudo bash install.sh

次に設定を行います:

sudo nano /etc/sentinelx-core-mcp/sentinelx-core-mcp.env

最低限必要な設定:

MCP_PORT=8098
SENTINELX_URL=http://127.0.0.1:8091
SENTINELX_TOKEN=your_internal_agent_token

OIDC_ISSUER=https://auth.example.com/realms/sentinelx
OIDC_JWKS_URI=https://auth.example.com/realms/sentinelx/protocol/openid-connect/certs
OIDC_EXPECTED_AUDIENCE=

RESOURCE_URL=https://sentinelx.example.com
AUTH_DEBUG=false

再起動して確認します:

sudo systemctl restart sentinelx-core-mcp
sudo systemctl status sentinelx-core-mcp
sudo journalctl -u sentinelx-core-mcp -n 50 --no-pager

ローカル開発

python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
./run.sh

ローカルのデフォルト値:

  • MCPポート: 8099

  • アップストリーム SentinelX Core: http://127.0.0.1:8092


インストールパス

パス

内容

/opt/sentinelx-core-mcp

アプリケーションコード

/etc/sentinelx-core-mcp/sentinelx-core-mcp.env

環境設定

/var/log/sentinelx-mcp

ログ

sentinelx-core-mcp.service

systemdユニット


リバースプロキシの接続

/mcpのMCPエンドポイントはHTTPS経由で公開する必要があります。Nginx設定例:

server {
    listen 443 ssl http2;
    server_name sentinelx.example.com;

    ssl_certificate     /path/to/fullchain.pem;
    ssl_certificate_key /path/to/privkey.pem;

    location = /mcp {
        proxy_pass http://127.0.0.1:8098/mcp;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header Authorization $http_authorization;
        proxy_buffering off;
        proxy_request_buffering off;
        proxy_read_timeout 3600s;
        add_header Cache-Control "no-cache";
    }
}

Claudeへの接続

Claudeの設定にMCPサーバーを追加します:

https://sentinelx.example.com/mcp

初回使用時にClaudeがOAuthログインを求めます。認証後、トークンのスコープで許可されたすべてのツールにアクセスできるようになります。


ChatGPTへの接続

MCPサーバーのURLをGPT Actionとして、またはChatGPTコネクタ設定に登録します。OAuthフローは、認可コードフローをサポートする任意のOIDCプロバイダーで動作します。


MCPスモークテスト (curl)

MCPエンドポイントはHTTP上のJSON-RPCを使用します。最小限のセッション例:

1. 初期化

SESSION=$(curl -si -X POST https://sentinelx.example.com/mcp \
  -H "Accept: application/json, text/event-stream" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc":"2.0","id":"1","method":"initialize",
    "params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"curl","version":"0.1"}}
  }' | grep -i mcp-session-id | awk '{print $2}' | tr -d '\r')

2. 初期化通知

curl -s -X POST https://sentinelx.example.com/mcp \
  -H "Content-Type: application/json" \
  -H "mcp-session-id: $SESSION" \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

3. pingの呼び出し (公開)

curl -s -X POST https://sentinelx.example.com/mcp \
  -H "Content-Type: application/json" \
  -H "mcp-session-id: $SESSION" \
  -d '{"jsonrpc":"2.0","id":"2","method":"tools/call","params":{"name":"ping","arguments":{}}}' \
  | sed -n 's/^data: //p' | jq

4. 保護されたツールの呼び出し

curl -s -X POST https://sentinelx.example.com/mcp \
  -H "Content-Type: application/json" \
  -H "mcp-session-id: $SESSION" \
  -H "Authorization: Bearer YOUR_OAUTH_ACCESS_TOKEN" \
  -d '{"jsonrpc":"2.0","id":"3","method":"tools/call","params":{"name":"sentinel_exec","arguments":{"cmd":"uptime"}}}' \
  | sed -n 's/^data: //p' | jq

IDプロバイダーの設定

OIDC互換のプロバイダーであれば何でも動作します: Keycloak、Auth0、Authentik、Zitadelなど。必要なもの:

  1. 認可コードフロー(対話型)またはクライアントクレデンシャル(マシン間)用に設定されたクライアント

  2. 公開したいツールと一致するカスタムスコープ (sentinelx:exec, sentinelx:edit など)

  3. プロバイダーのJWKS URI

  4. ClaudeおよびChatGPT用: クライアントに登録された正しいリダイレクトURI

これらを環境変数ファイルに設定します:

OIDC_ISSUER=https://your-provider.example.com/realms/your-realm
OIDC_JWKS_URI=https://your-provider.example.com/realms/your-realm/protocol/openid-connect/certs
OIDC_EXPECTED_AUDIENCE=   # set to your client ID, or leave empty to skip audience validation

OIDC_EXPECTED_AUDIENCE について

  • プロバイダーが aud クレームにクライアントIDを含める場合(機密クライアントで一般的)、クライアントIDを設定してください

  • 不明な場合は空のままにしてください — サーバーはオーディエンス検証をスキップします

  • トークンが拒否される場合は、トークンをデコード (echo $TOKEN | cut -d. -f2 | base64 -d | jq) して aud クレームを確認してください

Claudeへの接続

Claudeの設定にMCPサーバーを追加します:

https://sentinelx.example.com/mcp

初回使用時にClaudeはIDプロバイダーにリダイレクトします。以下を確認してください:

  • リダイレクトURI https://claude.ai/api/mcp/auth_callback がOIDCクライアントに登録されていること

  • サーバーが正しい authorization_servers 値を持つ /.well-known/oauth-protected-resource を公開していること

ChatGPTへの接続

MCP URLをGPT Actionとして登録します。クライアントのリダイレクトURIに https://chatgpt.com/aip/g-*/oauth/callback を追加してください。

Keycloakを使用した完全なエンドツーエンドのチュートリアル(トークン取得、Claude設定、スモークテスト、トラブルシューティングを含む)については、docs/keycloak-example.md を参照してください。

Keycloakを使用していない場合は、Authentik、Zitadel、Zitadel Cloudのクイックスタートガイドである docs/oidc-alternatives.md を参照してください。


トラブルシューティング

ツールが Missing Authorization header で失敗する MCPクライアントがOAuthトークンを送信していません。認証フローが正常に完了したか確認してください。

Invalid access token OIDC_ISSUER と OIDC_JWKS_URI がIDプロバイダーと完全に一致しているか確認してください。一時的に AUTH_DEBUG=true を有効にして、ログでトークン検証の詳細を確認してください。

Missing required scope トークンにそのツールが必要とするスコープが含まれていません。OIDCクライアント設定にスコープを追加し、再認証してください。

ping は動作するが他のツールがすべて失敗する 通常は認証の問題です。ping は公開されていますが、他のすべてのツールには適切なスコープを持つ有効なトークンが必要です。

MCPは起動するがSentinelX Coreに到達できない SENTINELX_URL が実行中のコアインスタンスを指していること、および SENTINELX_TOKEN がコアの SENTINEL_TOKEN と一致していることを確認してください。


セキュリティ上の注意

  • MCPサービスをHTTPSおよびリバースプロキシの背後に配置してください

  • 必要なスコープのみを持つ専用のOIDCクライアントを使用してください

  • SENTINELX_TOKEN とOIDCクライアントのクレデンシャルを定期的にローテーションしてください

  • 実行監査ログ (/var/log/sentinelx/exec.log) を定期的に確認してください

  • AUTH_DEBUG=true はトークンのクレームをログに記録するため、本番環境では無効にしてください


関連

  • sentinelx-core — 基盤となるHTTPエージェント: コマンド実行、構造化編集、アップロード、サービス管理。


ライセンス

MIT

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    A standalone MCP server that exposes API endpoints as tools for AI assistants by proxying requests to a target API defined in an OpenAPI specification. It supports various authentication methods and utilizes Server-Sent Events (SSE) to facilitate integration with clients like Claude and ChatGPT.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    A production-ready MCP server that authenticates agents via OAuth 2.1 Bearer tokens, validates JWTs with JWKS, enforces tool-level scopes and roles, and logs the full delegation chain.
    -
  • F
    license
    A
    quality
    D
    maintenance
    Standalone MCP server that proxies tool calls to Ottoauth HTTP endpoints, enabling account creation and dynamic service interaction.
    7
    -