McphubBLOCK
Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An open-source, self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.
[](https://github.com/samanhappy/mcphub/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@samanhappy/mcphub) [](https://hub.docker.com/r/samanhappy/mcphub) [](LICENSE) [](https://discord.gg/2BJehJZVH5) [](https://github.com/samanhappy/mcphub/stargazers)
English | Français | 中文版
MCPHub provides a unified control point between AI clients and MCP servers. Connect local and remote MCP servers once, organize and route their capabilities through stable endpoints, control access with authentication, scoped credentials, and per-user visibility, and operate everything with centralized logs, activity tracking, and health monitoring.
It works with MCP clients such as Claude Code, Cursor, Cherry Studio, OpenWebUI, and other MCP-compatible applications.
🌐 Website, Demo & Docs
- Website: mcphub.app
- Documentation: docs.mcphub.app
- Demo Environment: demo.mcphub.app
🚀 Features
Connect once, expose everywhere
- Smart Routing ⭐ - AI-powered tool discovery using vector semantic search (Learn more)
- Unified MCP Gateway - Expose all connected servers through stable MCP endpoints, including routes for groups and individual servers
- Server Aliases and Routing - D
77e1aac586dfOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcphub --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ADMIN_PASSWORD=${ADMIN_PASSWORD} --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} -- npx -y @samanhappy/mcphub@dev{
"mcpServers": {
"mcphub": {
"command": "npx",
"args": [
"-y",
"@samanhappy/mcphub@dev"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}",
"ADMIN_PASSWORD": "${ADMIN_PASSWORD}",
"API_KEY": "${API_KEY}",
"AUTH_TOKEN": "${AUTH_TOKEN}"
}
}
}
}Exposed tools (85)
76 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
AliceG | read | |
BobG | read | |
Fetch | read | HTTP fetch tool |
Firecrawl | read | Web scraping |
Intro | read | Introduction |
MixedG | read | |
Page | read | |
a | read | aa |
admin-group | read | owned by admin |
apps-open_dashboard | read | Open dashboard |
apps-poll_dashboard | read | Refresh dashboard |
b | read | bb |
blank | read | Fetch fallback conditions |
builtin-no-optional-fields | read | |
call_tool | write | STEP 3 of 3: Use this tool AFTER describe_tool to actually execute/invoke any tool you found. This is the execution step.\n\nWorkflow: search_tools → describe_tool → call_tool with the chosen tool name and required arguments.\n\nIMPORTANT: Always use describe_tool first to get the tool |
create_object | write | Create object |
create_thing | write | Create thing |
current | read | Fetch current conditions |
current_time | read | Current time |
db-db-query | read | |
delete_object | destructive | Delete object by id |
delete_objects | destructive | Bulk delete objects |
describe_tool | read | STEP 2 of 3: Use this tool AFTER search_tools to get the full parameter schema for a specific tool. This provides the complete inputSchema needed to correctly invoke the tool with call_tool.\n\nWorkflow: search_tools → describe_tool → call_tool |
example-openapi | read | |
fetch_html | read | Fetch HTML |
fetch_url | read | Fetch a URL |
find_user | read | Find a user |
getOther | read | other |
getProtected | read | protected |
getSub | read | sub |
getUsers | read | Get users |
get_current_time | read | Get current time |
get_record | read | Get a record by id |
get_tenant_record | read | Get a record within a tenant |
get_users | read | Get users |
gmail-list_accounts | read | List accounts |
gmail-send_email | write | Send an email |
layered-openapi | read | |
legacy | read | |
list_by_tags | read | List records by tags |
login | read | login |
new-api | read | |
new-tool | read | New tool |
oauth-server | read | |
open-dashboard | read | Open the dashboard |
org-search | read | Org web search |
p | read | pp |
ping | read | ping |
plain-openapi | read | |
poll-dashboard | read | Refresh dashboard data |
poll_dashboard | read | Refresh an MCP App |
r | read | rd |
read | read | Read access to your MCP servers and tools |
read_internal | read | read |
redis | read | Fast in-memory data store and cache |
redis-get | read | Get a cache value |
remote-server | read | |
replace_flags | read | Replace flags |
resource_disabled | read | Upstream disabled description |
resource_hosts | read | Upstream hosts description |
resource_no_override | read | Upstream no-override description |
s1-t | read | a tool |
search | read | Search |
search_tools | read | Search for relevant tools across ${scopeDescription}. |
seerr-get_movie | read | Get a movie |
serena | read | my server note |
shared-server | read | |
summarize | read | Summarize text |
t | read | |
test-dao-group | read | Test group for DAO operations |
test-group | read | Test group for development |
time | read | |
time-current_time | read | Get current time |
time-disabled_tool | read | |
time-poll_dashboard | read | Refresh an MCP App |
u8 | read | |
undefined | read | Fetch undefined fallback conditions |
upload_doc | write | Upload a doc |
upload_file | write | Upload a file |
weather-alpha | read | |
weather-beta | read | |
weather-current | read | |
weather-forecast | read | |
write | write | Execute tools and modify MCP server configurations |
x | read | a desc |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
return yaml.load(raw);
# DB_URL=postgresql://mcphub:password@localhost:5432/mcphub
现代 AI 应用场景中,将大模型(LLM)与各种数据源和工具无缝对接,往往需要手动编写大量胶水代码,并且无法快速复用。MCP(Model Context Protocol)协议由 Anthropic 在 2024 年开源,旨在提供类似“USB‐C”接口般的标准化通信方式,简化 AI 助手与内容仓库、业务系统等的集成流程。然而,MCP 服务器部署常常需要大量环境依赖、手动配置及持续运行,开发者常因安
尽管目前各家平台都在陆续推出各类 MCP 云服务,但在数据隐私、合规性和定制化需求日益增长的背景下,MCPHub 仍然是一个值得关注的本地部署解决方案。
.claude
# export DB_URL="postgresql://postgres:postgres@localhost:5432/mcphub_test"
- DB_URL=postgresql://mcphub:password@postgres:5432/mcphub
- DB_URL=postgresql://mcphub:password@postgres:5432/mcphub
DB_URL=postgresql://mcphub:secret@db:5432/mcphub
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
token: 'unrelated-scope-token',
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
delete_object, delete_objects
.coveragerc
CLAUDE.md
import { cn } from '../../utils/cn';import { cn } from '../../utils/cn';import enTranslation from '../../locales/en.json';
import zhTranslation from '../../locales/zh.json';
import frTranslation from '../../locales/fr.json';
const client = makeSchemaClient('http://169.254.169.254/latest/meta-data/');Gates applied: no_behavioural_pass.
77e1aac586dffull audit observations/trust-audit/mcp-server/samanhappy__mcphub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 77e1aac586df | BLOCK | F | 40 | source changed, verdict held |
| 2026-09-18 | 44de2b355405 | BLOCK | F | 40 | first audit |
Questions
What is the Mcphub MCP server?
Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.
What tools does Mcphub expose?
85 in total: 76 read-only, 7 that write, and 2 that can delete or overwrite (delete_object, delete_objects). Every one is listed on this page with its risk.
Is Mcphub safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mcphub need?
It reads ACCESS_TOKEN, ADMIN_PASSWORD, API_KEY, AUTH_TOKEN, AZURE_OPENAI_API_KEY, BETTER_AUTH_BASE_PATH, BETTER_AUTH_DISABLE_AUTO_CREATE, BETTER_AUTH_ENABLED, BETTER_AUTH_GITHUB_ENABLED, BETTER_AUTH_GOOGLE_ENABLED, BETTER_AUTH_OIDC_DISCOVERY_URL and BETTER_AUTH_OIDC_ENABLED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcphub run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @samanhappy/mcphub at dev.
How current is this page?
The grade is for one exact copy of the source (77e1aac586df), read on 2026-09-23. The repository is watched and re-audited when it changes.