nex mcp client delivery
Secure, multi-tenant MCP server delivery kit for deploying remote LLM tools via Cloudflare Tunnels.
Free
Works with the AI tools you already use
nex mcp client delivery
Example session with this skill installed
I need to deliver a remote MCP server for a client named 'acme-corp' to access their inventory. It needs to run on a Pi at mcp.acme.com and require a token for the manager.
- Read your context and instructions
- Compiled the nex mcp client
- Generated the document
De oplevering voor acme-corp staat klaar. Eén klant, één poort, één token, en een auditlogboek dat achteraf laat zien wie wat opvroeg.
Wat er is aangemaakt
| Onderdeel | Waarde |
|---|---|
| Dienst | nex-mcp-acme-corp, afgeschermde systemd-unit |
| Endpoint | https://mcp.acme.com/mcp, achter Cloudflare Tunnel |
| Luistert op | 127.0.0.1:8848, geen open poort naar buiten |
| Authenticatie | bearer token, audience gebonden aan de canonieke URL |
| Rechten | scope read voor de zaakvoerder |
| Auditlogboek | /var/log/nex-mcp/acme-corp/audit.jsonl |
De tool, in tools_client.py
from auth import Principal
from tools import tool
@tool(
name="zoek_voorraad",
description="Zoekt de actuele voorraad per productgroep.",
scope="read",
input_schema={
"type": "object",
"properties": {
"groep": {"type": "string"},
"limiet": {"type": "integer", "minimum": 1, "maximum": 100, "default": 25},
},
"required": ["groep"],
},
)
def zoek_voorraad(principal: Principal, args: dict) -> str:
tenant = principal.tenant_id # uit het token, nooit uit args
rows = db.fetch_stock(tenant, groep=args["groep"],
limit=min(int(args.get("limiet", 25)), 100))
return format_rows(rows)
De tenant staat niet in het schema. Dat is geen stijlkeuze: het register weigert een tool te registreren die tenant_id als argument declareert, en een aanroep die het alsnog meestuurt krijgt een 403. Zo kan een klant niet vragen om de voorraad van een andere klant.
Wat de tests aantonen
test_token_voor_andere_dienst_wordt_geweigerd PASSED
test_verlopen_token_wordt_geweigerd PASSED
test_client_kan_zijn_tenant_niet_zelf_kiezen PASSED
test_tool_die_verboden_argument_declareert... PASSED
test_scope_bepaalt_wat_je_ziet_en_wat_je_mag PASSED
test_tenant_komt_uit_het_token_tot_in_de_handler PASSED
test_auditlogboek_laat_geheimen_niet_door PASSED
7 passed
Een token met scope read ziet zoek_voorraad wel en een schrijftool niet. Niet grijs, niet geblokkeerd: hij staat gewoon niet in tools/list.
Uitrollen
sudo ./setup.sh acme-corp 8848 # eenmalig: gebruiker, mappen, unit, firewall
./deploy.sh acme-corp ./server # reservekopie, rsync -a -I, herstart, /healthz
Zakt de gezondheidscontrole, dan print deploy.sh de laatste veertig regels uit het journaal plus de terugdraairegel om te plakken. Er blijft nooit een half uitgerolde versie draaien.
Nog te doen
- Hostname
mcp.acme.comtoevoegen aan de tunnel, doelhttp://127.0.0.1:8848, altijd boven dehttp_status:404regel. - Token uitgeven met
auth.issue_token("zaakvoerder@acme.com", "acme-corp", ["read"])vanuit je eigen backend. README-voor-de-klant.mdmeesturen. Die staat in het Nederlands en legt uit wat Claude wel en niet mag zien.
nex-mcp-client-delivery.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
Exposing internal business data to LLMs like Claude or Cursor requires more than just a wrapper. You need a production-grade bridge that handles multi-tenancy and security without leaking data between clients.
This skill provides the deployment machinery to ship a secure, remote MCP (Model Context Protocol) server to a Raspberry Pi or cloud instance. It implements a FastAPI-based bridge behind Cloudflare Tunnels, ensuring that when a client queries their orders or dossiers, they only see their own data. It moves beyond simple local setups to a managed delivery workflow with automated systemd configuration and health checks.
What it does
- Multi-tenant isolation ensures the
tenant_idis extracted strictly from the auth token, preventing one client from accessing another's data. - Production deployment scripts automate systemd unit creation, user sandboxing, and log rotation on Linux environments.
- Secure tunneling provides a blueprint for Cloudflare Tunnel and Access integration, removing the need for open inbound ports.
- Granular tool scoping maps specific LLM tools to
readorwritepermissions per user token. - Audit logging records every tool invocation to a filtered JSONL file, masking sensitive credentials for compliance.
How it works
- Define tools in
tools_client.pyusing JSON schemas and assigned scopes likereadorwrite. - Configure environment variables in
.env, including theMCP_TOKEN_SECRETand canonical URLs. - Provision the host using
setup.shto create sandboxed system users and restricted systemd units. - Deploy and verify via
deploy.sh, which manages backups, rsync synchronization, and/healthzchecks.
Frameworks & tools
Built with Python and FastAPI for the server layer. Deployment targets Linux environments (optimized for Raspberry Pi/Debian) using systemd, rsync, and Cloudflare Tunnels.
Why this beats prompting it yourself
Building a secure MCP bridge requires handling edge cases like rsync idempotency and JWT validation that generic prompts often overlook. This skill enforces a "security-by-default" architecture where the server refuses to boot with weak keys or misconfigured tenants.
Use cases
- Providing a client access to their private CRM data directly within Claude.
- Exposing existing FastAPI backend logic to an agentic workflow via remote HTTP.
- Managing multiple customer MCP endpoints on a single edge device with strict isolation.
- Auditing LLM-driven write operations for legal or compliance requirements.
Known limitations
Does not support SSE (Server-Sent Events) for progress streaming. Sessions are stored in-memory, restricting the server to a single worker process unless an external store like Redis is added.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 4 days ago
- Free to download with an account