Skip to content

feat(monitor): MCP server endpoint #1681

Description

@lollipopkit

Let MCP clients (agents) control a monitor agent through a /mcp endpoint.

Design

  • Transport: Streamable HTTP, stateless JSON mode (rmcp 3.5, stateful_mode: false, json_response: true), behind a small ntex adapter. TLS or loopback only; Origin checked against cors_allowed_origins.
  • Credentials: new api_tokens table (migration 024). Tokens sbt_ + 64 hex, stored as SHA-256; scopes, expiry (default 90 days), last_used_at / last_used_ip.
    • Effective grants = token scopes ∩ the account role's grants; admin is never granted to a token, admin operations are not exposed.
    • Revoked when the account's password changes; deleted with the account.
    • /api-tokens: JWT only, re-authentication to create; admins can list and revoke every account's tokens.
  • Tools: tools/list filtered by scope; tools call service functions shared with the existing HTTP handlers.
    • run_command: risk from sbm_parser::command_risk::classify + CommandRules. Commands that need confirmation use MCP elicitation when the client supports it, otherwise they are refused with a hint to add an Allow rule. (Approval from the panel: later.)
  • Audit: Kind::Mcp in access_log.
  • Rate limit: per-IP (ntex-ratelimiter) before auth; per-token after auth once ntex-ratelimiter supports generic keys (0.4); LoginThrottle keeps covering auth failures.

Plan

  • PR1: api_tokens + token_caller + /api-tokens; /mcp with read tools; tests incl. e2e with an rmcp client
  • PR2: destructive tools, confirmation, audit
  • PR3: token UI (panel Account/Access, app monitor_settings) + docs
  • Per-token rate limit after ntex-ratelimiter 0.4.0

Activity

  1. winnowl commented on Oct 10, 2026

    @winnowl

    Issue triage

    Feasibility:needs-clarification | Risk:medium

    Information needed to reproduce:

    • Should PR1 expose only read-only tools, and which read scopes should gate each tool?
    • What exact Origin behavior is required when the header is absent, malformed, or does not match cors_allowed_origins?
    • What credential/permission errors and token lifecycle cases should tests cover, including expiry, password change, account deletion, and admin revocation?
    • Which service functions and existing HTTP handlers should MCP tools share?
    • What rmcp version/API and ntex adapter constraints are required for stateless JSON mode and elicitation capability detection?

    Suggested labels(not applied automatically):feature, api, mcp, security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions