SutramX

io.github.SutramXv0.1.1更新於 Oct 4, 2026

SutramX uptime monitoring: monitors, check results, incidents, status pages and uptime/SLO reports.

概覽

AI 產生的概覽

讓助理讀取與管理 SutramX 上線監控:監控項目、檢查結果、事件、狀態頁,以及可用率/SLO 報告。

功能
透過公開 API 將助理連接到 SutramX 工作區。唯讀工具涵蓋工作區資訊、監控項目彙總與清單、檢查歷史、事件、狀態頁、探測區域,以及含錯誤預算的可用率/SLO 報告。寫入工具可建立、修改、暫停、恢復與立即執行監控項目,確認或手動解決事件、加入時間軸備註,以及建立或修改狀態頁及其監控項目清單。兩個刪除工具預設隱藏,需明確啟用。
適用情境
適合讓助理排查故障、回答監控狀態與事件相關問題,或依 SutramX 工作區產出可用率與 SLO 報告。也適合需要建立或調整監控項目與狀態頁的代理。唯讀模式適合只需查看的助理。
執行需求
在本機執行 Node.js 20 或更新版本的行程,可透過 npx 或建置後的進入點啟動。需要 SutramX 工作區 API 金鑰,放在 SUTRAMX_API_KEY(建議代理使用唯讀金鑰)。選用設定:SUTRAMX_READ_ONLY、SUTRAMX_ALLOW_DESTRUCTIVE、SUTRAMX_API_URL,以及 HTTP 模式的 HOST、PORT、MCP_ALLOWED_HOSTS、MCP_ALLOWED_ORIGINS。需要連線至 SutramX API 的網路。
安裝前請注意
此伺服器能執行 API 金鑰允許的一切操作。標準金鑰可建立、修改、暫停與確認監控項目、事件和狀態頁;刪除需啟用 SUTRAMX_ALLOW_DESTRUCTIVE。建議使用唯讀金鑰並設定 SUTRAMX_READ_ONLY=true。監控設定中的憑證會以 [REDACTED] 回傳。來自受監控網站的文字屬於不可信資料。方案限制與僅擁有者可變更的設定仍然有效。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 SutramX,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

SutramX MCP server

A Model Context Protocol server that lets AI agents and assistants (Claude Code, Claude Desktop and other MCP clients) work with your SutramX workspace: list and change monitors, read check results, handle incidents and manage status pages.

It talks to the public SutramX API with a workspace API key, so it can do exactly what that key can do and nothing more.

Tools

ToolWhat it doesChanges data?
sutramx_whoamiWorkspace, plan and limits for the keyno
sutramx_monitor_summaryCounts by status, open incidents, 24h uptimeno
sutramx_list_monitorsMonitors with live status and uptime; filter by status, tag, textno
sutramx_get_monitorOne monitor by id or monitoring-as-code keyno
sutramx_create_monitorCreate a monitor of any type: http, api, ping, port, udp, dns, multistep or cron (pass key for an idempotent create-or-update)yes
sutramx_update_monitorChange name, URL, interval, config, tags, regionsyes
sutramx_pause_monitor / sutramx_resume_monitorStop or restart checksyes
sutramx_delete_monitorDelete a monitor and its history (hidden unless deletes are enabled)yes, destructive
sutramx_run_checkRun one real check nowrecords a check
sutramx_get_check_resultsCheck history by region and status, paginatedno
sutramx_list_incidents / sutramx_get_incidentIncidents with confirming regions and acknowledgementno
sutramx_acknowledge_incidentAcknowledge (stops escalation)yes
sutramx_resolve_incidentResolve by hand with a noteyes
sutramx_add_incident_noteAdd a timeline noteyes
sutramx_list_status_pages / sutramx_get_status_pageStatus pages and the monitors on themno
sutramx_create_status_page / sutramx_update_status_pageCreate a page, or change its title, description, slug, is_public, logo_url, accent_color, favicon_url, hide_powered_by, show_response_times (any other setting is rejected)yes
sutramx_set_status_page_monitorsReplace the monitors shown on a pageyes
sutramx_delete_status_pageDelete a page (hidden unless deletes are enabled)yes, destructive
sutramx_uptime_reportUptime %, incidents, MTTR and health score per monitor over 7/14/30/90 days, plus SLO error budgets and burn ratesno
sutramx_list_maintenance_windowsMaintenance windows (scope, schedule, recurrence); filter by stateno
sutramx_list_regionsProbe locations and their codesno

Destructive tools are annotated with destructiveHint, so clients that support it ask before running them.

Access modes

Agents can be steered by text they read (prompt injection), so the user, not the agent, chooses which tools the server offers. Tools that are not allowed are not registered at all: the agent never sees them.

Modestdio (env)HTTP (env for the whole server, or a header per client)Tools offered
read-onlySUTRAMX_READ_ONLY=trueX-SutramX-Read-Only: trueonly the "no" rows above
default(neither set)(neither set)everything except the two delete tools
deletes enabledSUTRAMX_ALLOW_DESTRUCTIVE=trueX-SutramX-Allow-Destructive: trueeverything
  • Both settings are off by default, so sutramx_delete_monitor and sutramx_delete_status_page are hidden unless deletes are enabled. true, 1, yes and on (any case) turn a setting on; anything else leaves it off.
  • Read-only wins: with read-only on, the delete tools stay hidden even when deletes are enabled.
  • HTTP mode: a header can only add to the server's environment, not take away from it. SUTRAMX_READ_ONLY=true on the server makes every request read-only whatever the headers say, and SUTRAMX_ALLOW_DESTRUCTIVE=true on the server enables deletes for every request that is not read-only. Without them, each client chooses with its own headers.
  • Use read-only mode for assistants that only need to look (triage, reporting), ideally together with a Read-only API key (below).

1. Create an API key

In SutramX, open Settings → API keys → Create API key. Keys start with sk_ and are shown once.

Recommended for agents: a Read-only key. It can call every "no" tool above, and the SutramX API itself refuses every change it attempts (403 READ_ONLY_ACCESS), so a leaked key or a prompt-injected agent cannot create, pause, acknowledge, resolve or delete anything. This holds even if the server's own read-only mode is off; combine both (SUTRAMX_READ_ONLY=true hides the write tools from the agent as well). Use a Standard key only for an agent that really needs to change things; it is enough for every tool above.

2. Build

bash
cd mcp-servernpm installnpm run build

Node.js 20 or newer is required.

3. Connect a client

Claude Code

bash
claude mcp add sutramx \  --env SUTRAMX_API_KEY=sk_your_key \  -- node /absolute/path/to/mcp-server/dist/index.js

Or add it to .mcp.json in a project:

json
{  "mcpServers": {    "sutramx": {      "command": "node",      "args": ["/absolute/path/to/mcp-server/dist/index.js"],      "env": { "SUTRAMX_API_KEY": "sk_your_key" }    }  }}

Claude Desktop

Edit claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/claude_desktop_config.json, Windows: %APPDATA%\Claude\claude_desktop_config.json):

json
{  "mcpServers": {    "sutramx": {      "command": "node",      "args": ["/absolute/path/to/mcp-server/dist/index.js"],      "env": { "SUTRAMX_API_KEY": "sk_your_key" }    }  }}

Restart Claude Desktop. Try: "Which SutramX monitors are down right now, and since when?"

Streamable HTTP (remote or shared)

bash
PORT=3333 node dist/index.js --http

The endpoint is POST http://127.0.0.1:3333/mcp (stateless, JSON responses). Every request must send its own SutramX key:

Authorization: Bearer sk_your_key

so one server can serve several users and workspaces. Connect Claude Code to it with:

bash
claude mcp add --transport http sutramx http://127.0.0.1:3333/mcp \  --header "Authorization: Bearer sk_your_key"

When the server listens on loopback (the default, HOST=127.0.0.1), SUTRAMX_API_KEY is used for requests that send no Authorization header (a header that is not a SutramX key is rejected with 401). Browser requests are only accepted from a loopback Origin or one listed in MCP_ALLOWED_ORIGINS. With any other HOST the environment key is ignored, and you should put the server behind HTTPS. Set MCP_ALLOWED_HOSTS (comma-separated host names) to keep DNS-rebinding protection when binding to 0.0.0.0. GET /health returns the server version.

Configuration

VariableDefaultPurpose
SUTRAMX_API_KEY(required for stdio)Workspace API key
SUTRAMX_API_URLhttps://api.sutramx.comAPI base URL (self-hosted or staging)
TRANSPORTstdiohttp is the same as --http
HOST / PORT127.0.0.1 / 3333HTTP listener
MCP_ALLOWED_HOSTS(none)Allowed Host headers when not on loopback
SUTRAMX_READ_ONLYfalseRegister only read tools
SUTRAMX_ALLOW_DESTRUCTIVEfalseRegister the delete tools
MCP_ALLOWED_ORIGINS(none)Extra browser origins allowed to call /mcp (comma-separated, e.g. https://app.example.com); requests without Origin are always allowed

Notes

  • Plan limits apply exactly as in the dashboard. When a tool returns ENTITLEMENT_LIMIT_REACHED or FEATURE_NOT_AVAILABLE, the plan does not allow it.
  • Billing, team members and API keys cannot be managed with an API key, and so not with this server. Per-monitor alert recipients (config.notification_emails) can only be set with an API key that has Automation access; other keys get a clear error.
  • Maintenance windows can be listed but not created, changed or deleted: they silence alerting, so the API makes them owner-only and refuses every API key (403 WORKSPACE_OWNER_REQUIRED). SLO targets are set in the dashboard; sutramx_uptime_report reads them.
  • With a read-only key, sutramx_whoami reports read_only: true, and any write tool returns READ_ONLY_ACCESS with a hint telling the agent not to retry.
  • config on sutramx_update_monitor replaces the whole object. Agents are told to read the monitor first and send the merged config.

Security

  • SUTRAMX_API_URL must be https:// (plain http:// only for loopback); the server refuses to start otherwise, warns when NODE_TLS_REJECT_UNAUTHORIZED=0, and never follows redirects with a key.
  • Credentials stored in monitor config (headers such as Authorization/Cookie, keys named like *token*, *secret*, *password*, *api_key*, and passwords in URLs) are returned as [REDACTED]. Sending [REDACTED] back in sutramx_update_monitor keeps the stored value; it cannot stand for a value that is not stored.
  • Text that comes from monitored sites or other people (check errors, names, notes) is shown single-line inside «», without control characters, and the server instructions tell the agent to treat it as data.
  • Ids are UUIDs, keys and slugs match strict patterns, times must be ISO-8601, so tool arguments cannot change the API path or add query parameters.
  • HTTP mode: every request needs its own Authorization: Bearer sk_...; the env key is only a fallback on loopback. Put a rate limiter in front of a public deployment (the API itself rate-limits per key).

Development

bash
npm run dev          # stdio, from sourcenpm test             # tool tests against a fake APInpx @modelcontextprotocol/inspector node dist/index.js   # interactive inspector

License

MIT, see LICENSE.

來源:README.md,提交 9b2526a

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 4, 2026