Let MCP clients (agents) control a monitor agent through a /mcp endpoint.
Design
- Transport: Streamable HTTP, stateless JSON mode (rmcp 3.5,
stateful_mode: false, json_response: true), behind a small ntex adapter. TLS or loopback only; Origin checked against cors_allowed_origins.
- Credentials: new
api_tokens table (migration 024). Tokens sbt_ + 64 hex, stored as SHA-256; scopes, expiry (default 90 days), last_used_at / last_used_ip.
- Effective grants = token scopes ∩ the account role's grants;
admin is never granted to a token, admin operations are not exposed.
- Revoked when the account's password changes; deleted with the account.
/api-tokens: JWT only, re-authentication to create; admins can list and revoke every account's tokens.
- Tools:
tools/list filtered by scope; tools call service functions shared with the existing HTTP handlers.
run_command: risk from sbm_parser::command_risk::classify + CommandRules. Commands that need confirmation use MCP elicitation when the client supports it, otherwise they are refused with a hint to add an Allow rule. (Approval from the panel: later.)
- Audit:
Kind::Mcp in access_log.
- Rate limit: per-IP (ntex-ratelimiter) before auth; per-token after auth once ntex-ratelimiter supports generic keys (0.4);
LoginThrottle keeps covering auth failures.
Plan
Let MCP clients (agents) control a monitor agent through a
/mcpendpoint.Design
stateful_mode: false,json_response: true), behind a small ntex adapter. TLS or loopback only;Originchecked againstcors_allowed_origins.api_tokenstable (migration 024). Tokenssbt_+ 64 hex, stored as SHA-256; scopes, expiry (default 90 days),last_used_at/last_used_ip.adminis never granted to a token, admin operations are not exposed./api-tokens: JWT only, re-authentication to create; admins can list and revoke every account's tokens.tools/listfiltered by scope; tools call service functions shared with the existing HTTP handlers.run_command: risk fromsbm_parser::command_risk::classify+CommandRules. Commands that need confirmation use MCP elicitation when the client supports it, otherwise they are refused with a hint to add an Allow rule. (Approval from the panel: later.)Kind::Mcpinaccess_log.LoginThrottlekeeps covering auth failures.Plan
api_tokens+token_caller+/api-tokens;/mcpwith read tools; tests incl. e2e with an rmcp clientmonitor_settings) + docs