Hostwatch

io.github.sergii-ziborovv1.0.1更新于 Sep 30, 2026

Observe and safely control sites, TLS, containers, traffic, databases and jobs with Hostwatch.

已验证Streamable HTTP可网页运行Cloud & InfrastructureDatabasesSecurity & Monitoring

概览

AI 生成的概览

Hostwatch 让助手通过托管的远程 MCP 服务器观察站点、TLS、容器、流量、数据库和作业,并在所有者批准后执行控制操作。

功能
Hostwatch 在 gethostwatch.com/mcp 提供远程 MCP 服务器。主要工具是 search(发现读和写操作)和 execute(运行指定操作)。监控范围包括站点、TLS 证书、流量、可疑请求、HTTP 错误、Docker 与 Podman 工作负载、存储、数据服务、作业和节点健康。两个资源描述操作目录,两个提示词引导事件与 TLS 审查。
适用场景
当你希望助手检查基础设施与服务的健康和安全状况、审查事件或 TLS 证书,并可选地执行经批准的写操作时,适合使用。它面向已经在使用 Hostwatch 进行监控的团队,而非独立使用。
运行要求
支持 Streamable HTTP 和 OAuth 的远程 MCP 客户端可直接连接该端点。否则需安装 Go 桥接程序(Go 1.24 或更高版本,或使用 PATH 中的预编译可执行文件),并将客户端配置为通过 stdio 启动它。需要已登录的 Hostwatch 账户和组织;使用带 PKCE 的 OAuth 授权码,不要求 API 密钥或代理凭据。
安装前请注意
每个连接都属于已登录的 Hostwatch 用户和组织,助手将以该账户的权限行事。写作用域单独授予、仅限组织所有者,且每次写入仍需显式确认,但写入可能更改或删除被监控的资源。请在同意页面核对所请求的组织和权限,不再需要时用 logout 撤销令牌。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Hostwatch,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "hostwatch": {
      "type": "http",
      "url": "https://gethostwatch.com/mcp"
    }
  }
}

README

Hostwatch MCP

Hostwatch exposes a remote MCP server at https://gethostwatch.com/mcp. This public repository contains the Codex plugin, a Go bridge for local MCP clients, connection metadata, icon, and usage guide. Every connection belongs to a signed-in Hostwatch user and organization. The Hostwatch control plane and node agent source are maintained separately.

Install the Codex plugin

sh
codex plugin marketplace add sergii-ziborov/hostwatch-mcpcodex plugin add hostwatch@hostwatchcodex mcp login hostwatch

Sign in with email, password and the configured second factor, or scan the one-time QR code with an already signed-in Hostwatch iPhone app. Review the requested organization and permissions on the consent screen. Start a new Codex chat after installation to load the plugin. The plugin guide explains scopes and revocation.

Connect a local MCP client with the Go app

Use the Go app when an MCP client accepts a local stdio command but cannot complete remote OAuth on its own. Install Go 1.24 or later, then run:

sh
go install github.com/sergii-ziborov/hostwatch-mcp/cmd/hostwatch-mcp@latesthostwatch-mcp login

Prebuilt macOS, Linux, and Windows executables are also available on the Releases page. Download the executable for your operating system and architecture, rename it to hostwatch-mcp (hostwatch-mcp.exe on Windows), and place it on your PATH.

login opens the Hostwatch authorization page. Sign in to your Hostwatch account directly or approve its QR code with your signed-in Hostwatch app, then review the organization and requested access. The Go app receives a short-lived OAuth authorization code on a temporary loopback callback; it never asks for an API key or node-agent credential. To request write access as an organization owner, use hostwatch-mcp login --write. Hostwatch still asks for explicit confirmation for each write operation.

Configure your MCP client to launch the app over stdio. For example, in a client that supports mcpServers:

json
{  "mcpServers": {    "hostwatch": {      "command": "hostwatch-mcp",      "args": ["serve"]    }  }}

If your MCP client cannot find the installed executable, use the absolute path from go env GOPATH followed by /bin/hostwatch-mcp. Run hostwatch-mcp status to inspect the local connection and hostwatch-mcp logout to revoke it. login --no-browser prints the Hostwatch URL for manual opening and accepts the final callback URL. See the connection guide for details.

Clients with native Streamable HTTP and OAuth support can connect straight to https://gethostwatch.com/mcp. The Go app is a client-side bridge to that same Hostwatch account, not an independent infrastructure agent. The server is listed in the official MCP Registry.

What it can do

search discovers read and write operations; execute runs a named operation. Monitoring covers sites, TLS certificates, traffic, suspicious requests, HTTP errors, Docker and Podman workloads, storage, data services, jobs, and node health. Two resources describe the operation catalog, and two prompts guide incident and TLS reviews. See docs/mcp.md for the operation list and security model.

Hostwatch requires OAuth authorization code with PKCE. Read and write scopes are separate, writes are restricted to owners and require per-action confirmation, and tokens can be revoked. API keys and agent credentials are not requested by the plugin or Go app.

For security reports, see SECURITY.md. The plugin files are subject to LICENSE; the hosted service is governed by the Hostwatch terms.

来源:README.md,提交 5e0e1a4

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.1最新Sep 30, 2026