munim
Munim
One MCP server holding a live session with every client's account at once.
A coding agent can be logged in to one Cloudflare account. One Vercel. One Resend. Connect a second client and the first goes away. So the person looking after a dozen small businesses runs a dozen agent sessions, and none of them can answer a question about more than one client.
Munim holds them all. Each client gets its own registration with the provider, its own token and its own namespace in the tool list, so one agent can read across every client and write inside the one you named.
Kloudfirst -> Kloudfirst@gmail.com's Account (3 tools)
Ivy & Fern -> ivy@example.com's Account (3 tools)
both sessions opened concurrently, one process, no logoutThat is a real run against two real Cloudflare accounts, not a diagram. The
second account is a client's and their address is replaced here: they did not
consent to a public repository, and this file is also the PyPI page.
Reproduce it with your own two:
scripts/cross_account_probe.py.
Install
Requires Python 3.10+. Nothing else: no Node, no build step, no account to create first.
uv tool install munim # or: pipx install munim, or: pip install munim
claude mcp add munim -- munim-mcpStart
munim clients # who you look after, and what is connected
munim clients add "Ivy & Fern" # write one down, connect nothing yet
munim connect "Ivy & Fern" cloudflare # a browser opens; that is the whole setupThere is no wrong order. Connect first and the account you sign in to names the client, or write the client down first and connect whenever. Both arrive in the same place.
Then ask your coding agent something a single logged-in session cannot answer:
which of my clients has a domain expiring this quarter?
check ivyandfern.co.uk for Ivy & Fern StudioDoing the work, not just the diagnosis
Munim does not wrap each provider in verbs of its own. Every provider here runs its own MCP server with its own tools, so Munim forwards them and supplies the credential:
munim tools "Ivy & Fern" cloudflare # what that account can be asked to do
munim call "Ivy & Fern" cloudflare execute --args '{"code": "..."}'Your coding agent gets the same two as list_provider_tools and
call_provider_tool. There is no model in this path, so it works with agents
off, and every call is written to the run log with the tool and its arguments.
A call names one client and resolves that client's credentials alone.
When a provider's own MCP server does not publish what you need,
call_provider_api goes a layer down and makes one HTTP call to that provider's
API with the same client's credential. Vercel publishes no environment-variable
write and no way to attach a domain to a project, which is what this is for. It
takes a path and never a URL, and refuses anything that would send the
credential to another host.
Munim is local by default. The checks, the audit and the mail plan are
deterministic: they never needed a model and never call one, and neither does
the passthrough above. Three tools can also reason about what they find
(check, work_on_client, ask_across_clients), and that is switched off
until you ask for it, so having a key lying around is not the same as
consenting to use it.
munim config ai key gemini # prompts, stored in ~/.munim/credentials.json
munim config ai on # takes effect on the next call, no reconnect
munim config ai # what is on, on what, and where each came fromHosts are Amazon Bedrock, which works out of the box, plus Google Gemini and
Anthropic, which Strands ships as extras: pip install 'munim[gemini]'.
One thing this does not change: Munim runs as an MCP server, so whatever its tools return goes into your coding agent's context and therefore to whichever model that agent runs on. Turning agents off stops Munim calling a model of its own; it cannot change how MCP works. The privacy policy says so plainly.
munim doctor says what is set up, what is not, and the exact command to fix
each gap. Start there whenever something is unclear.
Documentation
the whole CLI | |
what your coding agent gets, and what it deliberately cannot do | |
a page each: setup, what connecting grants, what is verified | |
how it is built, and the four decisions that shape it | |
every design decision and its reasoning, including the wrong ones | |
what is not done, and why | |
running the tests, and reproducing the claim above |
Why this exists
One person maintains the web and email setup of a dozen small businesses. The clients own the accounts; the operator holds delegated access and does the work. Every provider allows one login at a time, so the workaround is a separate agent session per client.
The costly part is not the switching. It is that a mistake in mail setup breaks nothing visible. Get an A record wrong and the site is down in minutes. Get the SPF record wrong and the client's invoices quietly stop arriving, and nobody notices for weeks.
A munim is the steward a business owner trusts to keep their books and handle their affairs without being asked each time.
Disclosure
Built with AI assistance (Claude Code), which the hackathon rules permit. No pre-existing code was incorporated; the repository was created during the submission period.
Licence
MIT. See LICENSE.
Contributing
CONTRIBUTING.md says how to run the two suites and what a good change looks
like here, which is mostly about writing down why. docs/DECISIONS.md is the
numbered log those reasons live in, and several of its entries reverse an
earlier one.
Security issues go in a private advisory rather than an issue.
SECURITY.md says what is in scope, and lists what is already known and
deliberate so a report can skip it.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/vishalsg42/munim'
If you have feedback or need assistance with the MCP directory API, please join our Discord server