Mcp ProxyCAUTION
A bridge between Streamable HTTP and stdio MCP transports
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://codecov.io/gh/sparfenyuk/mcp-proxy)
- mcp-proxy
- About
- 1. stdio to SSE/StreamableHTTP
- 1.1 Configuration
- 1.2 Example usage
- 2. SSE to stdio
- 2.1 Configuration
- 2.2 Example usage
- Named Servers
- Installation
- Installing via PyPI
- Installing via Github repository (latest)
- Installing as container
- Troubleshooting
- Extending the container image
- Docker Compose Setup
- Command line arguments
- Example config file
- Testing
About
The mcp-proxy is a tool that lets you switch between server transports. There are two supported modes:
- stdio to SSE/StreamableHTTP
- SSE to stdio
1. stdio to SSE/StreamableHTTP
Run a proxy server from stdio that connects to a remote SSE server.
This mode allows clients like Claude Desktop to communicate to a remote server over SSE even though it is not supported natively.
graph LR A["Claude Desktop"] |stdio| B["mcp-proxy"] B |SSE| C["External MCP Server"] style A fill:#ffe6f9,stroke:#333,color:black,stroke-width:2px style B fill:#e6e6ff,stroke:#333,color:black,stroke-width:2px style C fill:#e6ffe6,stroke:#333,color:black,stroke-width:2px
1.1 Configuration
This
82c7b53edf5aOBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-proxy --env API_ACCESS_TOKEN=${API_ACCESS_TOKEN} -- uvx mcp-proxy{
"mcpServers": {
"mcp-proxy": {
"command": "uvx",
"args": [
"mcp-proxy"
],
"env": {
"API_ACCESS_TOKEN": "${API_ACCESS_TOKEN}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo | read | Echo tool |
test_tool | read | A test tool |
tool | read | tool-description |
tool-name | read | tool-description |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
normalized_verify = False
.pre-commit-config.yaml
If a default server is specified (the `command_or_url` argument without `--named-server` or `--named-server-config`), it will be accessible at the root paths (e.g., `http://127.0.0.1:8080/sse`).
Named servers (whether defined by `--named-server` or `--named-server-config`) will be accessible under `/servers/<server-name>/` (e.g., `http://127.0.0.1:8080/servers/fetch1/sse`).
mcp-proxy http://127.0.0.1:8080/sse
Gates applied: no_behavioural_pass.
82c7b53edf5afull audit observations/trust-audit/mcp-server/sparfenyuk__mcp-proxy.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 82c7b53edf5a | CAUTION | B | 89 | source changed, verdict held |
Questions
What is the Mcp Proxy MCP server?
A bridge between Streamable HTTP and stdio MCP transports
What tools does Mcp Proxy expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp Proxy safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Mcp Proxy need?
It reads API_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcp Proxy run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-proxy.
How current is this page?
The grade is for one exact copy of the source (82c7b53edf5a), read on 2026-09-22. The repository is watched and re-audited when it changes.