Install
$ agentstack add mcp-fidarorg-mcpfoundry ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Create secure, production-ready MCP servers from your database or API — in under 5 minutes. ⚒️
[](https://www.npmjs.com/package/mcpfoundry) [](https://www.npmjs.com/package/mcpfoundry) [](./LICENSE) [](https://nodejs.org) [](./CONTRIBUTING.md)
[Quick Start](#-quick-start-60-seconds) · [Features](#-why-mcpfoundry) · [Security](#-the-ztai-security-shield-optional) · [Examples](#-two-ways-to-create) · [Contributing](./CONTRIBUTING.md)
> Stop hand-writing MCP servers. Point mcpfoundry at a database or an OpenAPI spec and get a clean, runnable, secure-by-option MCP server whose tools actually run — real parameterised SQL or real HTTP calls, not TODO stubs. Node.js or Python. Zero boilerplate.
⚡ Quick Start (60 seconds)
npx mcpfoundry create \
--type openapi \
--input https://petstore3.swagger.io/api/v3/openapi.json \
--output ./petstore-mcp
cd petstore-mcp && npm install && npm start
# 🎉 MCP server live on http://localhost:3000/mcp
That's a full MCP server — every endpoint turned into a validated tool — running. No SDK wrangling, no transport plumbing, no boilerplate.
Connect it to Claude in one step: every generated project includes a ready-to-use .mcp.json. Open the folder in Claude Code (it auto-detects the file), or paste the block into Claude Desktop's config. The generated README.md has the exact snippet.
✨ Why mcpfoundry?
| | | |---|---| | ⏱️ Ship in 5 minutes | One command turns a DB or API into a working MCP server. | | 🔒 Secure by option | Add --secure for a zero-trust JWT guard + deception canary. Off by default, never forced. | | 🛡️ Hardened by default | Every tool gets strict Zod / Pydantic parameter validation — no opt-in needed. | | 🏭 Production quality | Self-contained, lint-clean, type-safe output that builds and boots out of the box. | | 🧩 Maintainable & extensible | Clean Template-Compiler architecture — add a language with a folder, no core changes. | | 🌐 HTTP or stdio | Streamable HTTP by default; --no-http for stdio (Claude Desktop / Claude Code style). | | 🐍 Node.js & Python | First-class @modelcontextprotocol/sdk (TS) and FastMCP (Python) output. | | ⚙️ Working out of the box | Tools run real code — parameterised SQL (SQLite) or HTTP calls to your API — not placeholders. | | 🔌 DB & OpenAPI | Introspect SQLite/Postgres into CRUD tools, or convert any OpenAPI/Swagger spec (file or URL, JSON/YAML) into tools that call the upstream API. | | 📎 One-click Claude connection | Every project ships a .mcp.json — auto-detected by Claude Code, paste-ready for Claude Desktop. |
🛠️ Two ways to create
1. From an OpenAPI / Swagger spec
Every endpoint becomes a typed, validated MCP tool.
mcpfoundry create --type openapi --input ./openapi.yaml --output ./my-server
2. From a database
Tables are introspected into CRUD tools. SQLite tools run real, parameterised SQL out of the box — just point DATABASE_PATH at your file:
mcpfoundry create --type database --provider sqlite --uri ./app.db --output ./db-server
cd db-server && npm install && DATABASE_PATH=../app.db npm start
Postgres is also introspected (its handlers are scaffolded stubs for now):
mcpfoundry create --type database \
--provider postgres \
--uri "postgresql://user:pass@localhost:5432/mydb" \
--output ./pg-server --lang python
> 💡 Preview first with --dry-run to see exactly which tools you'll get — no files written: > > ``text > ✔ Dry run — 4 tool(s) would be generated: > • list_pets(limit?: integer) > • create_pet(name: string, tag?: string) > • get_pet_by_id(pet_id: integer) > • delete_pet(pet_id: integer) > ``
🔐 The ZTAI Security Shield (optional)
Pass --secure and every generated server enforces zero-trust access — recommended, never required:
- 🔑 JWT Guard — verifies a short-lived HS256 token (an
Authorization: Bearerheader per request over HTTP, orZTAI_AUTH_TOKENat startup over stdio) againstJWT_SECRET. Invalid or missing → rejected before any tool runs. - 🧱 Parameter hardening — strict Zod / Pydantic schemas (this is always on, even without
--secure— it's just good hygiene). - 🪤 Deception canary — set
ZTAI_CANARY_IDand tool output carries a subtle, traceable marker to help detect adversarial data exfiltration.
Without --secure you still get a perfectly good, vendor-neutral MCP server.
🎛️ All options
| Flag | Description | | --- | --- | | --type | database or openapi (required) | | --provider | sqlite \| postgres \| mysql \| mongodb (database mode) | | --uri | DB connection string (database mode) | | --input | OpenAPI spec — file path or URL, JSON or YAML (openapi mode) | | --output | Output directory (required) | | --lang | nodejs (default) or python | | --transport | http (default) or stdio | | --no-http | Shortcut for --transport stdio | | --port | Port for the HTTP transport (default 3000) | | --secure | Embed the optional ZTAI Security Shield | | --force | Overwrite a non-empty output directory | | --dry-run | Preview the generated tools, then exit |
> SQLite & Postgres are introspected today; SQLite emits working SQL. MySQL & MongoDB are stubbed and open for [contributions](./CONTRIBUTING.md).
🧩 How it works
mcpfoundry follows a clean Template-Compiler pattern:
source (DB / OpenAPI) ──▶ parser ──▶ normalized IR (ToolSpec[])
│
Handlebars compiler
│
▼
templates// ──▶ your generated server
Parsers and templates are decoupled by a normalized intermediate representation, so adding a new language is just a new templates// folder — no engine changes. See [CONTRIBUTING.md](./CONTRIBUTING.md).
🤝 Contributing
Two of the most common contributions — a new language template or a new database provider — need zero changes to the core engine. See [CONTRIBUTING.md](./CONTRIBUTING.md).
📄 License
[MIT](./LICENSE) — build freely.
⭐ Star on GitHub if mcpfoundry saved you an afternoon.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: FidarOrg
- Source: FidarOrg/mcpfoundry
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.