
Mcpolyglot
io.github.ishay60v0.4.3更新於 Oct 4, 2026
Policy-checked, audited agent access to Postgres, MySQL, SQLite, MongoDB and OpenAPI REST APIs.
概覽
讓助理在政策檢查與稽核下存取 Postgres、MySQL、SQLite、MongoDB 與 OpenAPI REST 資料來源。
- 功能
- Mcpolyglot 是一個本機命令列工具,可產生設定檔、驗證連線、列出工具,並以 stdio 或 Streamable HTTP 方式提供 MCP 伺服器。它會暴露用來查詢與讀取所設定資料庫與 REST API 的工具,並透過每個來源的政策限制資料表、存取層級與上限。在 HTTP 模式下支援多個代理,每個代理有自己的權杖、作用範圍與收窄後的政策,並依權杖記錄稽核用的 agentId。
- 適用情境
- 當助理需要在明確的存取規則下查詢你自己的資料庫或 REST API,並希望依代理劃分範圍、保留稽核紀錄時使用。也適合多個代理需要看到同一批來源不同子集的情境。
- 執行需求
- 需要 Node.js,透過 npx 執行 npm 套件 @mcpolyglot/cli。需要設定檔(mcpolyglot.config.ts),其中包含各來源的連線資訊與密鑰。HTTP 模式需要以 token 指令建立的 bearer 權杖;agents 需要 bearer 驗證而非 OAuth,在 stdio 下會被忽略。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Mcpolyglot,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@mcpolyglot/cli
The mcpolyglot command-line interface. Scaffolds a config, validates connectivity, lists tools, and serves the MCP server over stdio or Streamable HTTP.
Commands
serve --http prints the bearer token, MCP URL, and /healthz URL on stderr. Pin the token in your config (transport.auth.token) for stable deployments; omit it to mint a fresh token on each start.
Multiple agents over HTTP
Give each agent its own token, sources and scopes. Tokens are stored only as sha256 hashes:
- An agent sees only tools of the sources listed under it, and only tools its scopes fully cover.
scopesdefaults to, and is capped at, the union of those sources' scopes. - A per-agent
policycan only narrow the source'spolicy: per table the most restrictive access wins, deny lists are combined, and caps take the smaller value. An agent can't re-open a table the source hides or gain writes the source doesn't grant. The reverse also holds: a table the agent's policy doesn't list falls to itsdefaultAccess(at mostread), so an agent that should keep a source's write access must list that table aswriteagain. It gets its own connector, so its own DB connection; sources listed without a policy share the main one. - The token decides the audit
agentId; thex-mcpolyglot-agentheader is ignored whenagentsis set. Unknown or revoked tokens get401. - Rotate: add the new hash, move the client over, set
revoked: trueon the old one (or delete it), restartserve. There is no hot reload. agentsneeds bearer auth (not OAuth) and is ignored under stdio (single local user).doctorlists what each agent can and can't use.
Stdio servers must keep stdout clean, so all CLI output goes to stderr.
Docs
- Full README → https://github.com/ishay60/mcpolyglot
- Architecture → https://github.com/ishay60/mcpolyglot/blob/develop/ARCHITECTURE.md
- Examples → https://github.com/ishay60/mcpolyglot/tree/develop/examples
MIT licensed.
來源:packages/cli/README.md,提交 0835998
工具
0版本歷史
1- v0.4.3最新Oct 4, 2026
