
Mcpolyglot
io.github.ishay60v0.4.3更新于 Oct 4, 2026
Policy-checked, audited agent access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST APIs.
概览
让助手在策略检查与审计下访问 Postgres、MySQL、SQLite、MongoDB 和 OpenAPI REST 数据源。
- 功能
- Mcpolyglot 是一个本地命令行工具,可生成配置、验证连通性、列出工具,并以 stdio 或 Streamable HTTP 方式提供 MCP 服务器。它暴露用于查询和读取所配置数据库与 REST API 的工具,并通过每个数据源的策略限制表、访问级别和上限。在 HTTP 模式下支持多个代理,每个代理有自己的令牌、作用域和收窄后的策略,并按令牌记录审计用的 agentId。
- 适用场景
- 当助手需要在明确的访问规则下查询你自己的数据库或 REST API,并希望按代理划分范围、保留审计记录时使用。也适合多个代理需要看到同一批数据源不同子集的场景。
- 运行要求
- 需要 Node.js,通过 npx 运行 npm 包 @mcpolyglot/cli。需要配置文件(mcpolyglot.config.ts),其中包含各数据源的连接信息和密钥。HTTP 模式需要用以 token 命令创建的 bearer 令牌;agents 需要 bearer 认证而非 OAuth,在 stdio 下会被忽略。
安装
在 SourceWeft 中
- 打开 控制台中的 Mcpolyglot,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@mcpolyglot/cli
The mcpolyglot command-line interface. Scaffolds a config, validates connectivity, lists tools, and serves the MCP server over stdio or Streamable HTTP.
Commands
serve --http prints the bearer token, MCP URL, and /healthz URL on stderr. Pin the token in your config (transport.auth.token) for stable deployments; omit it to mint a fresh token on each start.
Multiple agents over HTTP
Give each agent its own token, sources and scopes. Tokens are stored only as sha256 hashes:
- An agent sees only tools of the sources listed under it, and only tools its scopes fully cover.
scopesdefaults to, and is capped at, the union of those sources' scopes. - A per-agent
policycan only narrow the source'spolicy: per table the most restrictive access wins, deny lists are combined, and caps take the smaller value. An agent can't re-open a table the source hides or gain writes the source doesn't grant. The reverse also holds: a table the agent's policy doesn't list falls to itsdefaultAccess(at mostread), so an agent that should keep a source's write access must list that table aswriteagain. It gets its own connector, so its own DB connection; sources listed without a policy share the main one. - The token decides the audit
agentId; thex-mcpolyglot-agentheader is ignored whenagentsis set. Unknown or revoked tokens get401. - Rotate: add the new hash, move the client over, set
revoked: trueon the old one (or delete it), restartserve. There is no hot reload. agentsneeds bearer auth (not OAuth) and is ignored under stdio (single local user).doctorlists what each agent can and can't use.
Stdio servers must keep stdout clean, so all CLI output goes to stderr.
Docs
- Full README → https://github.com/ishay60/mcpolyglot
- Architecture → https://github.com/ishay60/mcpolyglot/blob/develop/ARCHITECTURE.md
- Examples → https://github.com/ishay60/mcpolyglot/tree/develop/examples
MIT licensed.
来源:packages/cli/README.md,提交 0835998
工具
0版本历史
1- v0.4.3最新Oct 4, 2026

