
Mcpolyglot
io.github.ishay60v0.4.3Updated Oct 4, 2026
Policy-checked, audited agent access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST APIs.
Overview
Gives an assistant policy-checked, audited access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST sources.
- What it does
- Mcpolyglot is a local CLI that scaffolds a config, validates connectivity, lists tools and serves an MCP server over stdio or Streamable HTTP. It exposes tools for querying and reading the databases and REST APIs you configure, with per-source policies that restrict tables, access levels and caps. Over HTTP it supports multiple agents, each with its own token, scopes and narrowed policy, and records an audit agentId per token.
- When to use it
- Use it when an assistant needs to query your own databases or REST APIs under explicit access rules, and you want per-agent scoping and an audit trail. It suits setups where several agents should see different subsets of the same sources.
- Requirements
- Node.js to run the npm package @mcpolyglot/cli via npx. A config file (mcpolyglot.config.ts) with connection details and secrets for each source. For HTTP mode, bearer tokens created with the token command; agents require bearer auth, not OAuth, and are ignored under stdio.
Installation
In SourceWeft
- Open Mcpolyglot in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@mcpolyglot/cli
The mcpolyglot command-line interface. Scaffolds a config, validates connectivity, lists tools, and serves the MCP server over stdio or Streamable HTTP.
Commands
serve --http prints the bearer token, MCP URL, and /healthz URL on stderr. Pin the token in your config (transport.auth.token) for stable deployments; omit it to mint a fresh token on each start.
Multiple agents over HTTP
Give each agent its own token, sources and scopes. Tokens are stored only as sha256 hashes:
- An agent sees only tools of the sources listed under it, and only tools its scopes fully cover.
scopesdefaults to, and is capped at, the union of those sources' scopes. - A per-agent
policycan only narrow the source'spolicy: per table the most restrictive access wins, deny lists are combined, and caps take the smaller value. An agent can't re-open a table the source hides or gain writes the source doesn't grant. The reverse also holds: a table the agent's policy doesn't list falls to itsdefaultAccess(at mostread), so an agent that should keep a source's write access must list that table aswriteagain. It gets its own connector, so its own DB connection; sources listed without a policy share the main one. - The token decides the audit
agentId; thex-mcpolyglot-agentheader is ignored whenagentsis set. Unknown or revoked tokens get401. - Rotate: add the new hash, move the client over, set
revoked: trueon the old one (or delete it), restartserve. There is no hot reload. agentsneeds bearer auth (not OAuth) and is ignored under stdio (single local user).doctorlists what each agent can and can't use.
Stdio servers must keep stdout clean, so all CLI output goes to stderr.
Docs
- Full README → https://github.com/ishay60/mcpolyglot
- Architecture → https://github.com/ishay60/mcpolyglot/blob/develop/ARCHITECTURE.md
- Examples → https://github.com/ishay60/mcpolyglot/tree/develop/examples
MIT licensed.
Source: packages/cli/README.md at commit 0835998
Tools
0Version history
1- v0.4.3LatestOct 4, 2026
