Hatago HubCAUTION
Hatago MCP Hub is a lightweight hub server that provides unified management for multiple MCP servers.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 日本語
[](https://www.npmjs.com/package/@himorishige/hatago-mcp-hub) [](https://github.com/himorishige/hatago-mcp-hub/releases) [](https://deepwiki.com/himorishige/hatago-mcp-hub)
Hatago (旅籠) — A relay point connecting modern AI tools with MCP servers.
Overview
Hatago MCP Hub is a lightweight hub that unifies access to multiple MCP (Model Context Protocol) servers from tools like Claude Code, Codex CLI, Cursor, Windsurf, and VS Code.
Documentation
- Docs index:
docs/README.md - Canonical CLI & Hub guide:
packages/mcp-hub/README.md - Public docs site (JA default): https://hatago.dev/ja/ — English: https://hatago.dev/en/
Dev.to: Getting Started with Multi-MCP Using Hatago MCP Hub — One Config to Connect Them All
✨ Features
🚀 Performance (v0.0.14)
- 8.44x Faster Startup - 85.66ms → 10.14ms
- 17% Smaller Package - 1.04MB → 854KB
- Simplified Architecture - Direct server management without abstraction layers
🎯 Simple & Lightweight
- Zero Configuration Start (HTTP mode) -
npx @himorishige/hatago-mcp-hub serve --http - Non-invasive to Existing Projects - Doesn't pollute your project directory
🔌 Rich Connectivity
- Multi-Transport Support - STDIO / HTTP / SSE
- Remote MCP Proxy - Transparent connection to HTTP-based MCP servers
- NPX Server Integration - Dynamic management of npm package MCP servers
🏮 Additional Features
Configuration Updates
- Manual Restart Required - Configuration changes require server restart
- Alternative Solutions:
- Use process managers (PM2, nodem
196c0c071b15OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hatago-transport --env API_KEY_2=${API_KEY_2} --env API_TOKEN=${API_TOKEN} --env AUTH_TOKEN=${AUTH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y @himorishige/[email protected]{
"mcpServers": {
"hatago-transport": {
"command": "npx",
"args": [
"-y",
"@himorishige/[email protected]"
],
"env": {
"API_KEY_2": "${API_KEY_2}",
"API_TOKEN": "${API_TOKEN}",
"AUTH_TOKEN": "${AUTH_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}Exposed tools (17)
16 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add numbers |
calc | read | Calculator tool |
calculator | read | Math tool |
echo | read | Echo input |
echo_object | read | Echo the input as JSON |
echo_tool | read | Echo tool |
fail | read | Always fails |
fetch | read | Fetch tool |
greeting | read | Generate a greeting |
name | read | Name to greet |
no_handler | read | Tool without handler |
slow | read | Respond slowly |
stream_echo | read | Stream multiple chunks |
summary | read | Generate summary |
test_prompt | read | A test prompt |
test_tool | read | Test tool |
translate | read | Translate text |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
logger.info(`[Hub] Registering progress token`, { progressToken, sessionId } as LogData);console.log(' - Default endpoint: http://127.0.0.1:3535/mcp');console.log(' - SSE endpoint: http://127.0.0.1:3535/sse');console.log(' - Health check: http://127.0.0.1:3535/health');origin: ['http://localhost:*', 'http://127.0.0.1:*', 'https://*.workers.dev'],
origin: ['http://localhost:*', 'http://127.0.0.1:*'],
.git-blame-ignore-revs
.prettierignore
WARP.md
expect(result.mcpServers.test.command).toBe('/usr/local/bin/server');fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
fixturePath = join(__dirname, '../../test-fixtures/dist/stdio-server.js');
const packageJson = JSON.parse(readFileSync(join(__dirname, '../../package.json'), 'utf-8')) as {@eslint/js, eslint, eslint-config-prettier, prettier, typescript-eslint
@modelcontextprotocol/sdk, commander, chalk, @types/node, tsdown, typescript, vitest
@modelcontextprotocol/sdk, zod, tsdown, typescript, vitest
@modelcontextprotocol/sdk, diff, hono, zod, zod-to-json-schema, @cloudflare/vitest-pool-workers, @cloudflare/workers-types, @types/node
@modelcontextprotocol/sdk, hono, commander, @types/node, tsdown, typescript, vitest
You are a Senior Code Reviewer for the Hatago project, an expert in Hono framework, MCP (Model Context Protocol), functional programming, and multi-runtime environments.
- CLI: `--env-file <path...>` to load environment variables before config parsing, and `--env-override` to overwrite existing values. Supports `KEY=VALUE` / `export KEY=VALUE`, `#` comments, quotes st
hatago serve --env-file ./.env # Load variables from .env before start (repeatable)
hatago serve --env-file ./.env # Load variables from .env before start (can repeat)
Gates applied: no_behavioural_pass.
196c0c071b15full audit observations/trust-audit/mcp-server/himorishige__hatago-hub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 196c0c071b15 | CAUTION | C | 77 | first audit |
Questions
What is the Hatago Hub MCP server?
Hatago MCP Hub is a lightweight hub server that provides unified management for multiple MCP servers.
What tools does Hatago Hub expose?
17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hatago Hub safe to connect to an agent?
With care. The audit graded it C (77/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Hatago Hub need?
It reads API_KEY_2, API_TOKEN, AUTH_TOKEN, GITHUB_TOKEN, TOKEN, TOKEN1 and TOKEN2 from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Hatago Hub run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @himorishige/hatago-transport at 0.0.16.
How current is this page?
The grade is for one exact copy of the source (196c0c071b15), read on 2026-10-08. The repository is watched and re-audited when it changes.