
Hostwatch
io.github.sergii-ziborovv1.0.1Updated Sep 30, 2026
Observe and safely control sites, TLS, containers, traffic, databases and jobs with Hostwatch.
Overview
Hostwatch lets an assistant observe and, with owner approval, control sites, TLS, containers, traffic, databases and jobs through a hosted remote MCP server.
- What it does
- Hostwatch exposes a remote MCP server at gethostwatch.com/mcp. Its main tools are search, which discovers read and write operations, and execute, which runs a named operation. Monitoring covers sites, TLS certificates, traffic, suspicious requests, HTTP errors, Docker and Podman workloads, storage, data services, jobs and node health. Two resources describe the operation catalog and two prompts guide incident and TLS reviews.
- When to use it
- Use it when you want an assistant to check the health and security posture of your infrastructure and services, review incidents or TLS certificates, and optionally perform approved write operations. It suits teams already using Hostwatch for monitoring rather than standalone use.
- Requirements
- A remote MCP client with Streamable HTTP and OAuth support can connect directly to the endpoint. Otherwise install the Go bridge (Go 1.24 or later, or a prebuilt executable on PATH) and configure your client to launch it over stdio. A signed-in Hostwatch account and organization are required; OAuth authorization code with PKCE is used, and no API key or agent credential is requested.
Installation
In SourceWeft
- Open Hostwatch in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"hostwatch": {
"type": "http",
"url": "https://gethostwatch.com/mcp"
}
}
}README
Hostwatch MCP
Hostwatch exposes a remote MCP server at https://gethostwatch.com/mcp. This public repository contains the Codex plugin, a Go bridge for local MCP clients, connection metadata, icon, and usage guide. Every connection belongs to a signed-in Hostwatch user and organization. The Hostwatch control plane and node agent source are maintained separately.
Install the Codex plugin
Sign in with email, password and the configured second factor, or scan the one-time QR code with an already signed-in Hostwatch iPhone app. Review the requested organization and permissions on the consent screen. Start a new Codex chat after installation to load the plugin. The plugin guide explains scopes and revocation.
Connect a local MCP client with the Go app
Use the Go app when an MCP client accepts a local stdio command but cannot complete remote OAuth on its own. Install Go 1.24 or later, then run:
Prebuilt macOS, Linux, and Windows executables are also available on the Releases page. Download the executable for your operating system and architecture, rename it to hostwatch-mcp (hostwatch-mcp.exe on Windows), and place it on your PATH.
login opens the Hostwatch authorization page. Sign in to your Hostwatch account directly or approve its QR code with your signed-in Hostwatch app, then review the organization and requested access. The Go app receives a short-lived OAuth authorization code on a temporary loopback callback; it never asks for an API key or node-agent credential. To request write access as an organization owner, use hostwatch-mcp login --write. Hostwatch still asks for explicit confirmation for each write operation.
Configure your MCP client to launch the app over stdio. For example, in a client that supports mcpServers:
If your MCP client cannot find the installed executable, use the absolute path from go env GOPATH followed by /bin/hostwatch-mcp. Run hostwatch-mcp status to inspect the local connection and hostwatch-mcp logout to revoke it. login --no-browser prints the Hostwatch URL for manual opening and accepts the final callback URL. See the connection guide for details.
Clients with native Streamable HTTP and OAuth support can connect straight to https://gethostwatch.com/mcp. The Go app is a client-side bridge to that same Hostwatch account, not an independent infrastructure agent. The server is listed in the official MCP Registry.
What it can do
search discovers read and write operations; execute runs a named operation. Monitoring covers sites, TLS certificates, traffic, suspicious requests, HTTP errors, Docker and Podman workloads, storage, data services, jobs, and node health. Two resources describe the operation catalog, and two prompts guide incident and TLS reviews. See docs/mcp.md for the operation list and security model.
Hostwatch requires OAuth authorization code with PKCE. Read and write scopes are separate, writes are restricted to owners and require per-action confirmation, and tokens can be revoked. API keys and agent credentials are not requested by the plugin or Go app.
For security reports, see SECURITY.md. The plugin files are subject to LICENSE; the hosted service is governed by the Hostwatch terms.
Source: README.md at commit 5e0e1a4
Tools
0Version history
1- v1.0.1LatestSep 30, 2026
