Skip to main content
Glama
terrorgeek

Navi Candidates MCP

by terrorgeek
README.md
# Navi Candidates MCP

Remote MCP server for Pickaxe's Scout Navi agent. It exposes a read-only `search_candidates` tool that calls Navi's existing candidate search Cloud Function and returns safe candidate summaries.

## Endpoints

- `GET /health`
- `POST /mcp`

## Environment

```text
NAVI_MCP_API_KEY=replace-with-a-long-random-token
CANDIDATE_SEARCH_FUNCTION_URL=https://us-central1-navi-ai-f1306.cloudfunctions.net/searching_candidates
PORT=8080
NODE_ENV=production
```

## Local Development

```bash
npm install
npm test
npm run build
NAVI_MCP_API_KEY=dev-secret npm start
curl http://127.0.0.1:8080/health
```

## Deploy To Cloud Run

```bash
gcloud auth login
gcloud config set project navi-ai-f1306
gcloud config set run/region us-central1
gcloud services enable run.googleapis.com cloudbuild.googleapis.com artifactregistry.googleapis.com secretmanager.googleapis.com
```

Create the bearer token secret:

```bash
printf "replace-with-a-long-random-token" | gcloud secrets create navi-mcp-api-key --data-file=-
```

Deploy:

```bash
gcloud run deploy navi-candidates-mcp \
  --source . \
  --region us-central1 \
  --allow-unauthenticated \
  --set-env-vars CANDIDATE_SEARCH_FUNCTION_URL=https://us-central1-navi-ai-f1306.cloudfunctions.net/searching_candidates,NODE_ENV=production \
  --update-secrets NAVI_MCP_API_KEY=navi-mcp-api-key:latest
```

Cloud Run must be public because Pickaxe calls it externally. The MCP endpoint itself is protected by `Authorization: Bearer <NAVI_MCP_API_KEY>`.

After deployment, configure Pickaxe with:

```text
https://<cloud-run-service-url>/mcp
```