Install
$ agentstack add mcp-try-dock-ai-mcp ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v1.0.1 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v1.0.1. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
@trydock/mcp
[](https://www.npmjs.com/package/@trydock/mcp) [](https://docs.npmjs.com/generating-provenance-statements) [](./LICENSE)
Local stdio bridge to the Dock MCP server. Point any MCP-capable agent (Claude Desktop, Cursor, Windsurf, Zed, Cline, Continue) at your Dock workspaces in one config change.
> Do you need this package? > > If your agent supports remote MCP connectors (Claude.ai web, > Claude.ai Projects), you don't need this — add > https://trydock.ai/api/mcp as a custom connector and follow the OAuth > flow. See the MCP reference. > > This package is for agents that only speak local stdio MCP — the > dominant pattern for Claude Desktop and most code-editor agents today.
Quickstart
- Get an API key in Dock's Settings → API keys
(trydock.ai).
- Add the config for your agent below.
- Restart the agent. You'll see Dock's 8 tools appear.
Configs
All clients follow the same pattern: run npx -y @trydock/mcp, pass DOCK_API_KEY in env. Per-client JSON snippets are in [configs/](./configs):
| Client | File | Typical config path | |---|---|---| | Claude Desktop | [configs/claude-desktop.json](./configs/claude-desktop.json) | ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) | | Cursor | [configs/cursor.json](./configs/cursor.json) | ~/.cursor/mcp.json | | Windsurf | [configs/windsurf.json](./configs/windsurf.json) | ~/.codeium/windsurf/mcp_config.json | | Zed | [configs/zed.json](./configs/zed.json) | ~/.config/zed/settings.json (under context_servers) | | Cline (VS Code) | [configs/cline.json](./configs/cline.json) | VS Code settings → cline.mcpServers | | Continue | [configs/continue.json](./configs/continue.json) | ~/.continue/config.json |
Example (Claude Desktop):
{
"mcpServers": {
"dock": {
"command": "npx",
"args": ["-y", "@trydock/mcp"],
"env": {
"DOCK_API_KEY": "dk_..."
}
}
}
}
Tools
All 8 tools are forwarded to the hosted Dock server. JSON schemas live in [schemas/](./schemas).
| Tool | Purpose | |---|---| | [list_workspaces](./schemas/listworkspaces.json) | Enumerate workspaces you can access | | [get_workspace](./schemas/getworkspace.json) | Fetch a workspace by slug | | [list_rows](./schemas/listrows.json) | Read rows from a table-mode workspace | | [create_row](./schemas/createrow.json) | Append a row | | [update_row](./schemas/updaterow.json) | Partial-merge update | | [delete_row](./schemas/deleterow.json) | Remove a row | | [create_workspace](./schemas/createworkspace.json) | Create a new workspace | | [get_recent_events](./schemas/getrecent_events.json) | Read the activity log |
Full reference with examples: trydock.ai/docs/mcp.
How the bridge works
The bridge is a ~100-line Node process ([src/bridge.js](./src/bridge.js)). Every JSON-RPC message your agent writes on stdin is forwarded over HTTPS to https://trydock.ai/api/mcp with your DOCK_API_KEY as Bearer auth. The hosted server owns authentication, rate limits, audit, and tool execution. The bridge stores no state and logs no request bodies.
Environment variables:
| Variable | Required? | Purpose | |---|---|---| | DOCK_API_KEY | yes | Bearer token (get one from Settings → API keys) | | DOCK_MCP_URL | no | Override the upstream endpoint (staging / self-host). Default: https://trydock.ai/api/mcp |
Security
- Your API key is only held in the agent's environment and passed on
each HTTPS call. It's never logged, never written to disk by this bridge.
- Rotate keys any time in Dock's Settings → API keys. Old keys return
401 immediately on revocation.
- Keys are stored as SHA-256 hashes on Dock's side, not plaintext. A
Dock DB leak wouldn't expose usable credentials.
- See the full security doc for the
threat model, the revocation runbook, and what data is audited.
License
MIT. Copyright © 2026 Vector Apps, Inc.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: try-dock-ai
- Source: try-dock-ai/mcp
- License: MIT
- Homepage: https://godock.ai/docs/mcp
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v1.0.1 Imported from the upstream source.