Skip to main content
Glama

MCP Server - Production Monorepo

A production-grade Model Context Protocol (MCP) server with a beautiful React dashboard, built with security, scalability, and maintainability in mind.

๐Ÿš€ Features

Backend (Node.js + Express + TypeScript)

  • Full MCP Protocol Compliance - Complete implementation of the Model Context Protocol

  • Secure ZIP Processing - Advanced security validation, zip bomb protection, path traversal prevention

  • Context Management - Approval workflow for uploaded content

  • System Snapshots - Comprehensive state snapshots with configurable options

  • Production Security - Rate limiting, CORS, helmet, input validation

  • Structured Logging - Winston-based logging with rotation and levels

  • Health Monitoring - Comprehensive health checks and system statistics

Frontend (React + TypeScript + Tailwind)

  • Modern Dashboard - Beautiful, responsive interface with dark/light mode

  • Real-time Monitoring - Live system stats, logs, and activity feeds

  • Secure File Upload - Drag-and-drop ZIP upload with progress tracking

  • Context Browser - Search, filter, and manage uploaded contexts

  • Log Viewer - Real-time log streaming with filtering and export

  • Tool Management - MCP tool monitoring and configuration

MCP Tools

  • load_zip - Securely extract and process ZIP archives

  • mark_approved - Context approval workflow management

  • snapshot - Create comprehensive system state snapshots

Related MCP server: Filesystem MCP Server

๐Ÿ—๏ธ Architecture

mcp-server/
โ”œโ”€โ”€ backend/           # Node.js + Express API server
โ”‚   โ”œโ”€โ”€ src/
โ”‚   โ”‚   โ”œโ”€โ”€ mcp/      # MCP protocol implementation
โ”‚   โ”‚   โ”œโ”€โ”€ api/      # REST API routes and middleware
โ”‚   โ”‚   โ”œโ”€โ”€ utils/    # Utilities and security
โ”‚   โ”‚   โ””โ”€โ”€ types.ts  # TypeScript definitions
โ”œโ”€โ”€ dashboard/         # React frontend
โ”‚   โ”œโ”€โ”€ src/
โ”‚   โ”‚   โ”œโ”€โ”€ components/ # Reusable UI components
โ”‚   โ”‚   โ”œโ”€โ”€ pages/     # Application pages
โ”‚   โ”‚   โ””โ”€โ”€ api.ts     # API client
โ”œโ”€โ”€ data/             # Runtime data storage
โ”‚   โ”œโ”€โ”€ zips/         # Uploaded ZIP files
โ”‚   โ”œโ”€โ”€ extracted/    # Extracted file contents
โ”‚   โ”œโ”€โ”€ vds/          # Vector database storage
โ”‚   โ””โ”€โ”€ snapshots/    # System snapshots
โ””โ”€โ”€ logs/             # Application logs

๐Ÿšฆ Quick Start

Prerequisites

  • Node.js 18+

  • npm 8+

Local Development

  1. Clone and install dependencies:

git clone <repository>
cd mcp-server
npm install
  1. Start development servers:

npm run dev

This starts both the backend (port 3001) and frontend (port 5173) in development mode.

  1. Access the application:

  • Dashboard: http://localhost:5173

  • API: http://localhost:3001

  • Health Check: http://localhost:3001/api/health

Production Build

npm run build
npm start

๐Ÿ”ง Configuration

Environment Variables

Create a .env file in the backend directory:

NODE_ENV=production
PORT=3001
CORS_ORIGIN=*
MAX_FILE_SIZE=52428800
LOG_LEVEL=info
RATE_LIMIT_ENABLED=true

Security Configuration

The server includes comprehensive security measures:

  • File Upload Limits: 50MB max file size, ZIP files only

  • Rate Limiting: 5 uploads per 15 minutes, 100 API calls per 15 minutes

  • ZIP Security: Zip bomb protection, path traversal prevention, file type validation

  • Input Validation: Joi-based validation for all endpoints

  • CORS: Configurable cross-origin resource sharing

  • Helmet: Security headers and CSP

๐Ÿ“ก API Endpoints

MCP Tools

  • POST /api/mcp/tools/load-zip - Upload and extract ZIP files

  • POST /api/mcp/tools/mark-approved - Approve/reject contexts

  • POST /api/mcp/tools/snapshot - Create system snapshots

Data Management

  • GET /api/context - List contexts with filtering and pagination

  • GET /api/logs - Retrieve system logs

  • GET /api/stats - System statistics and metrics

  • GET /api/mcp/tools - List available MCP tools

System

  • GET /api/health - Health check endpoint

๐Ÿ”’ Security Features

ZIP File Processing

  • File Type Validation: Only ZIP files accepted

  • Size Limits: 50MB upload limit, 100MB extraction limit

  • Zip Bomb Protection: Compression ratio analysis

  • Path Traversal Prevention: Sanitized file paths

  • Content Filtering: Allowed file extensions only

API Security

  • Rate Limiting: Configurable request limits

  • Input Validation: Comprehensive request validation

  • Error Handling: Secure error responses

  • CORS Configuration: Controlled cross-origin access

  • Security Headers: Helmet.js integration

๐Ÿš€ Deployment

The project includes a render.yaml configuration for easy deployment:

  1. Connect your repository to Render

  2. The build and deployment will happen automatically

  3. Environment variables are configured in the YAML file

Manual Deployment

  1. Build the project:

npm run build
  1. Set environment variables:

export NODE_ENV=production
export PORT=3001
  1. Start the server:

npm start

๐Ÿ“Š Monitoring

Dashboard Features

  • System Overview: Uptime, file counts, memory/disk usage

  • Real-time Logs: Live log streaming with filtering

  • Context Management: Upload approval workflow

  • Tool Monitoring: MCP tool usage statistics

Logging

  • Structured Logging: JSON format with metadata

  • Log Rotation: Automatic log file rotation

  • Multiple Levels: Error, warn, info, debug

  • Export Capability: Download logs for analysis

๐Ÿงช Testing

# Run backend tests
npm run test --workspace=backend

# Run frontend tests  
npm run test --workspace=dashboard

# Run all tests
npm test

๐Ÿค Contributing

  1. Fork the repository

  2. Create a feature branch

  3. Make your changes

  4. Add tests for new functionality

  5. Submit a pull request

๐Ÿ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

๐Ÿ†˜ Support

For support and questions:

  • Check the Issues page

  • Review the API documentation

  • Check the logs for error details

๐Ÿ”„ Version History

  • v1.0.0 - Initial release with full MCP protocol support

  • Production-ready security features

  • Complete React dashboard

  • Render deployment configuration

-
security - not tested
-
license - not tested
-
quality - not tested

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/the-real-therealorry/mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server