RouterCAUTION
MCP Router — development, support and security updates ended 2026-09-18. Historical source and final release for existing users.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
End of support — September 18, 2026. Development, support and security updates have ended. Cloud services and billing have stopped. v0.6.4 is the final desktop release for existing users; local features remain available. New adoption is not recommended. End-of-support and migration guide.
The material below describes the historical product. Cloud features are no longer available.
MCP Router A Unified MCP Server Management App
[](https://github.com/mcp-router/mcp-router) [](https://discord.com/invite/dwG9jPrhxB) -@mcp__router-1DA1F2?style=flat&logo=x)
English | [日本語 | 中文]
🎯 Overview
MCP Router is a desktop application for simplifies the management of Model Context Protocol (MCP) servers.
✨ Key Features
- 🌐 Universal — Connect to any MCP server
- Remote or local servers
- Supports DXT, JSON, Manual
- 🖥️ Cross-platform — Windows and macOS
- 🗂 Context Management — Keep growing MCP server contexts organized
- Group MCP servers into Projects
- Manage modes with Workspaces (like browser profiles)
- Toggle tools on/off per server
🔒 Privacy & Security
Your Data Stays Local
- ✅ All data is stored locally - Request logs, configurations, and server data remain on your device
- ✅ Credentials are secure - API keys and authentication credentials are stored locally and never transmitted externally
- ✅ Complete control - You have full control over your MCP server connections and data
Transparency
- 🔍 Auditable
2053f05a089dOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ui --env APPLE_API_KEY=${APPLE_API_KEY} --env APPLE_API_KEY_ID=${APPLE_API_KEY_ID} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env MCPR_TOKEN=${MCPR_TOKEN} -- npx -y @mcp_router/[email protected]{
"mcpServers": {
"ui": {
"command": "npx",
"args": [
"-y",
"@mcp_router/[email protected]"
],
"env": {
"APPLE_API_KEY": "${APPLE_API_KEY}",
"APPLE_API_KEY_ID": "${APPLE_API_KEY_ID}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"MCPR_TOKEN": "${MCPR_TOKEN}"
}
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
tool_discovery | read | Discover available tools across MCP servers. |
tool_execute | write | Execute a discovered tool on an MCP server. |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
icon.icns
icon.icns
"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAhIAAAISAQAAAACxRhsSAAABhGlDQ1BJQ0MgUHJvZmlsZQAAeJx9kT1Iw0AcxV9TS0WqDnYo4hChOtlFRRylikWwUNoKrTqYXPoFTRqSFBdHwbXg4Mdi1cHFWVcHV0EQ/ABxF5wUXaTE/yWFFjEeHPfj3
.cursorindexingignore
.prettierrc.json
const servers = await this.page.$$eval(
const workspaces = await this.page.$$eval(
const appPath = path.join(__dirname, "../../.webpack/arm64/main/index.js");
require("dotenv").config({ path: path.resolve(__dirname, "../../.env") });import { API_BASE_URL, mainWindow } from "../../../main";import { getSharedConfigManager } from "../../infrastructure/shared-config-manager";import claudeIcon from "../../../../public/images/apps/claude.svg";
assert.throws(() => normalizeRemoteMcpUrl("https://127.0.0.1/mcp"));@modelcontextprotocol/sdk, node-fetch, @types/node, typescript
@anthropic-ai/dxt, @codemirror/lang-javascript, @codemirror/state, @codemirror/theme-one-dark, @codemirror/view, @modelcontextprotocol/sdk, @tabler/icons-react, @types/react
@electron/rebuild, @eslint/js, @types/better-sqlite3, @types/node, @types/node-fetch, @types/react, @types/react-router-dom, @typescript-eslint/eslint-plugin
@trpc/client, superjson, zod, @trpc/server, @types/node, eslint, tsup, typescript
@types/node, typescript
Gates applied: no_behavioural_pass.
2053f05a089dfull audit observations/trust-audit/mcp-server/mcp-router__router-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 2053f05a089d | CAUTION | B | 82 | source changed, verdict held |
Questions
What is the Router MCP server?
MCP Router — development, support and security updates ended 2026-09-18. Historical source and final release for existing users.
What tools does Router expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Router safe to connect to an agent?
With care. The audit graded it B (82/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Router need?
It reads APPLE_API_KEY, APPLE_API_KEY_ID, GITHUB_TOKEN and MCPR_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Router run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mcp_router/ui at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (2053f05a089d), read on 2026-09-23. The repository is watched and re-audited when it changes.