Mcpolyglot

io.github.ishay60v0.4.3Updated Oct 4, 2026

Policy-checked, audited agent access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST APIs.

Overview

AI-generated overview

Gives an assistant policy-checked, audited access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST sources.

What it does
Mcpolyglot is a local CLI that scaffolds a config, validates connectivity, lists tools and serves an MCP server over stdio or Streamable HTTP. It exposes tools for querying and reading the databases and REST APIs you configure, with per-source policies that restrict tables, access levels and caps. Over HTTP it supports multiple agents, each with its own token, scopes and narrowed policy, and records an audit agentId per token.
When to use it
Use it when an assistant needs to query your own databases or REST APIs under explicit access rules, and you want per-agent scoping and an audit trail. It suits setups where several agents should see different subsets of the same sources.
Requirements
Node.js to run the npm package @mcpolyglot/cli via npx. A config file (mcpolyglot.config.ts) with connection details and secrets for each source. For HTTP mode, bearer tokens created with the token command; agents require bearer auth, not OAuth, and are ignored under stdio.
Before you install
The server connects to live databases and REST APIs, so configured credentials and secrets are resolved at runtime. Policies can grant write access; per-agent policies only narrow a source's policy, and a table not listed falls to defaultAccess, so write access must be re-listed explicitly. Tokens are stored as sha256 hashes and printed once; unknown or revoked tokens get 401. There is no hot reload, so changes need a restart.

Installation

In SourceWeft

  1. Open Mcpolyglot in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

@mcpolyglot/cli

The mcpolyglot command-line interface. Scaffolds a config, validates connectivity, lists tools, and serves the MCP server over stdio or Streamable HTTP.

bash
npx @mcpolyglot/cli init       # interactive wizardnpx @mcpolyglot/cli doctor     # validate config, ping sources, list toolsnpx @mcpolyglot/cli tools      # list tools mcpolyglot would exposenpx @mcpolyglot/cli serve      # start the MCP server (stdio)npx @mcpolyglot/cli serve --http --port 7337   # start over Streamable HTTP

Commands

CommandPurpose
initInteractively scaffold an mcpolyglot.config.ts in the current directory.
doctorLoad + validate config, resolve secrets, ping each source, list tools.
toolsPrint every tool mcpolyglot would expose for the current config.
serveStart the server. --http flips to Streamable HTTP with bearer auth.
tokentoken create <agentId> mints a per-agent token; token hash hashes one.

serve --http prints the bearer token, MCP URL, and /healthz URL on stderr. Pin the token in your config (transport.auth.token) for stable deployments; omit it to mint a fresh token on each start.

Multiple agents over HTTP

Give each agent its own token, sources and scopes. Tokens are stored only as sha256 hashes:

bash
mcpolyglot token create analyst       # prints the token once, its hash, and a config snippetecho -n "$TOKEN" | mcpolyglot token hash
ts
agents: [  {    id: 'analyst',    tokens: [{ hash: '<sha256 hex>', label: '2026-09' }],    scopes: ['schema:read', 'tables:read', 'query:raw'],    sources: { 'pg.main': { policy: { tables: { users: 'none' } } } },  },],
  • An agent sees only tools of the sources listed under it, and only tools its scopes fully cover. scopes defaults to, and is capped at, the union of those sources' scopes.
  • A per-agent policy can only narrow the source's policy: per table the most restrictive access wins, deny lists are combined, and caps take the smaller value. An agent can't re-open a table the source hides or gain writes the source doesn't grant. The reverse also holds: a table the agent's policy doesn't list falls to its defaultAccess (at most read), so an agent that should keep a source's write access must list that table as write again. It gets its own connector, so its own DB connection; sources listed without a policy share the main one.
  • The token decides the audit agentId; the x-mcpolyglot-agent header is ignored when agents is set. Unknown or revoked tokens get 401.
  • Rotate: add the new hash, move the client over, set revoked: true on the old one (or delete it), restart serve. There is no hot reload.
  • agents needs bearer auth (not OAuth) and is ignored under stdio (single local user). doctor lists what each agent can and can't use.

Stdio servers must keep stdout clean, so all CLI output goes to stderr.

Docs

MIT licensed.

Source: packages/cli/README.md at commit 0835998

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.4.3LatestOct 4, 2026