Mcpolyglot

io.github.ishay60v0.4.3更新于 Oct 4, 2026

Policy-checked, audited agent access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST APIs.

概览

AI 生成的概览

让助手在策略检查与审计下访问 Postgres、MySQL、SQLite、MongoDB 和 OpenAPI REST 数据源。

功能
Mcpolyglot 是一个本地命令行工具,可生成配置、验证连通性、列出工具,并以 stdio 或 Streamable HTTP 方式提供 MCP 服务器。它暴露用于查询和读取所配置数据库与 REST API 的工具,并通过每个数据源的策略限制表、访问级别和上限。在 HTTP 模式下支持多个代理,每个代理有自己的令牌、作用域和收窄后的策略,并按令牌记录审计用的 agentId。
适用场景
当助手需要在明确的访问规则下查询你自己的数据库或 REST API,并希望按代理划分范围、保留审计记录时使用。也适合多个代理需要看到同一批数据源不同子集的场景。
运行要求
需要 Node.js,通过 npx 运行 npm 包 @mcpolyglot/cli。需要配置文件(mcpolyglot.config.ts),其中包含各数据源的连接信息和密钥。HTTP 模式需要用以 token 命令创建的 bearer 令牌;agents 需要 bearer 认证而非 OAuth,在 stdio 下会被忽略。
安装前请注意
该服务器会连接真实的数据库和 REST API,配置的凭据与密钥会在运行时解析。策略可以授予写权限;每个代理的策略只能收窄数据源的策略,未列出的表会落到 defaultAccess,因此写权限必须显式重新列出。令牌仅以 sha256 哈希存储且只打印一次;未知或已撤销的令牌返回 401。没有热重载,修改后需要重启。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Mcpolyglot,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

@mcpolyglot/cli

The mcpolyglot command-line interface. Scaffolds a config, validates connectivity, lists tools, and serves the MCP server over stdio or Streamable HTTP.

bash
npx @mcpolyglot/cli init       # interactive wizardnpx @mcpolyglot/cli doctor     # validate config, ping sources, list toolsnpx @mcpolyglot/cli tools      # list tools mcpolyglot would exposenpx @mcpolyglot/cli serve      # start the MCP server (stdio)npx @mcpolyglot/cli serve --http --port 7337   # start over Streamable HTTP

Commands

CommandPurpose
initInteractively scaffold an mcpolyglot.config.ts in the current directory.
doctorLoad + validate config, resolve secrets, ping each source, list tools.
toolsPrint every tool mcpolyglot would expose for the current config.
serveStart the server. --http flips to Streamable HTTP with bearer auth.
tokentoken create <agentId> mints a per-agent token; token hash hashes one.

serve --http prints the bearer token, MCP URL, and /healthz URL on stderr. Pin the token in your config (transport.auth.token) for stable deployments; omit it to mint a fresh token on each start.

Multiple agents over HTTP

Give each agent its own token, sources and scopes. Tokens are stored only as sha256 hashes:

bash
mcpolyglot token create analyst       # prints the token once, its hash, and a config snippetecho -n "$TOKEN" | mcpolyglot token hash
ts
agents: [  {    id: 'analyst',    tokens: [{ hash: '<sha256 hex>', label: '2026-09' }],    scopes: ['schema:read', 'tables:read', 'query:raw'],    sources: { 'pg.main': { policy: { tables: { users: 'none' } } } },  },],
  • An agent sees only tools of the sources listed under it, and only tools its scopes fully cover. scopes defaults to, and is capped at, the union of those sources' scopes.
  • A per-agent policy can only narrow the source's policy: per table the most restrictive access wins, deny lists are combined, and caps take the smaller value. An agent can't re-open a table the source hides or gain writes the source doesn't grant. The reverse also holds: a table the agent's policy doesn't list falls to its defaultAccess (at most read), so an agent that should keep a source's write access must list that table as write again. It gets its own connector, so its own DB connection; sources listed without a policy share the main one.
  • The token decides the audit agentId; the x-mcpolyglot-agent header is ignored when agents is set. Unknown or revoked tokens get 401.
  • Rotate: add the new hash, move the client over, set revoked: true on the old one (or delete it), restart serve. There is no hot reload.
  • agents needs bearer auth (not OAuth) and is ignored under stdio (single local user). doctor lists what each agent can and can't use.

Stdio servers must keep stdout clean, so all CLI output goes to stderr.

Docs

MIT licensed.

来源:packages/cli/README.md,提交 0835998

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.4.3最新Oct 4, 2026