nex mcp client delivery

    1

    Secure, multi-tenant MCP server delivery kit for deploying remote LLM tools via Cloudflare Tunnels.

    Free

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    nex mcp client delivery

    Example session with this skill installed

    I need to deliver a remote MCP server for a client named 'acme-corp' to access their inventory. It needs to run on a Pi at mcp.acme.com and require a token for the manager.

    • Read your context and instructions
    • Compiled the nex mcp client
    • Generated the document

    De oplevering voor acme-corp staat klaar. Eén klant, één poort, één token, en een auditlogboek dat achteraf laat zien wie wat opvroeg.

    Wat er is aangemaakt

    OnderdeelWaarde
    Dienstnex-mcp-acme-corp, afgeschermde systemd-unit
    Endpointhttps://mcp.acme.com/mcp, achter Cloudflare Tunnel
    Luistert op127.0.0.1:8848, geen open poort naar buiten
    Authenticatiebearer token, audience gebonden aan de canonieke URL
    Rechtenscope read voor de zaakvoerder
    Auditlogboek/var/log/nex-mcp/acme-corp/audit.jsonl

    De tool, in tools_client.py

    from auth import Principal
    from tools import tool
    
    @tool(
        name="zoek_voorraad",
        description="Zoekt de actuele voorraad per productgroep.",
        scope="read",
        input_schema={
            "type": "object",
            "properties": {
                "groep": {"type": "string"},
                "limiet": {"type": "integer", "minimum": 1, "maximum": 100, "default": 25},
            },
            "required": ["groep"],
        },
    )
    def zoek_voorraad(principal: Principal, args: dict) -> str:
        tenant = principal.tenant_id          # uit het token, nooit uit args
        rows = db.fetch_stock(tenant, groep=args["groep"],
                              limit=min(int(args.get("limiet", 25)), 100))
        return format_rows(rows)
    

    De tenant staat niet in het schema. Dat is geen stijlkeuze: het register weigert een tool te registreren die tenant_id als argument declareert, en een aanroep die het alsnog meestuurt krijgt een 403. Zo kan een klant niet vragen om de voorraad van een andere klant.

    Wat de tests aantonen

    test_token_voor_andere_dienst_wordt_geweigerd      PASSED
    test_verlopen_token_wordt_geweigerd                PASSED
    test_client_kan_zijn_tenant_niet_zelf_kiezen       PASSED
    test_tool_die_verboden_argument_declareert...      PASSED
    test_scope_bepaalt_wat_je_ziet_en_wat_je_mag       PASSED
    test_tenant_komt_uit_het_token_tot_in_de_handler   PASSED
    test_auditlogboek_laat_geheimen_niet_door          PASSED
    
    7 passed
    

    Een token met scope read ziet zoek_voorraad wel en een schrijftool niet. Niet grijs, niet geblokkeerd: hij staat gewoon niet in tools/list.

    Uitrollen

    sudo ./setup.sh acme-corp 8848     # eenmalig: gebruiker, mappen, unit, firewall
    ./deploy.sh acme-corp ./server     # reservekopie, rsync -a -I, herstart, /healthz
    

    Zakt de gezondheidscontrole, dan print deploy.sh de laatste veertig regels uit het journaal plus de terugdraairegel om te plakken. Er blijft nooit een half uitgerolde versie draaien.

    Nog te doen

    1. Hostname mcp.acme.com toevoegen aan de tunnel, doel http://127.0.0.1:8848, altijd boven de http_status:404 regel.
    2. Token uitgeven met auth.issue_token("zaakvoerder@acme.com", "acme-corp", ["read"]) vanuit je eigen backend.
    3. README-voor-de-klant.md meesturen. Die staat in het Nederlands en legt uit wat Claude wel en niet mag zien.

    nex-mcp-client-delivery.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Exposing internal business data to LLMs like Claude or Cursor requires more than just a wrapper. You need a production-grade bridge that handles multi-tenancy and security without leaking data between clients.

    This skill provides the deployment machinery to ship a secure, remote MCP (Model Context Protocol) server to a Raspberry Pi or cloud instance. It implements a FastAPI-based bridge behind Cloudflare Tunnels, ensuring that when a client queries their orders or dossiers, they only see their own data. It moves beyond simple local setups to a managed delivery workflow with automated systemd configuration and health checks.

    What it does

    • Multi-tenant isolation ensures the tenant_id is extracted strictly from the auth token, preventing one client from accessing another's data.
    • Production deployment scripts automate systemd unit creation, user sandboxing, and log rotation on Linux environments.
    • Secure tunneling provides a blueprint for Cloudflare Tunnel and Access integration, removing the need for open inbound ports.
    • Granular tool scoping maps specific LLM tools to read or write permissions per user token.
    • Audit logging records every tool invocation to a filtered JSONL file, masking sensitive credentials for compliance.

    How it works

    1. Define tools in tools_client.py using JSON schemas and assigned scopes like read or write.
    2. Configure environment variables in .env, including the MCP_TOKEN_SECRET and canonical URLs.
    3. Provision the host using setup.sh to create sandboxed system users and restricted systemd units.
    4. Deploy and verify via deploy.sh, which manages backups, rsync synchronization, and /healthz checks.

    Frameworks & tools

    Built with Python and FastAPI for the server layer. Deployment targets Linux environments (optimized for Raspberry Pi/Debian) using systemd, rsync, and Cloudflare Tunnels.

    Why this beats prompting it yourself

    Building a secure MCP bridge requires handling edge cases like rsync idempotency and JWT validation that generic prompts often overlook. This skill enforces a "security-by-default" architecture where the server refuses to boot with weak keys or misconfigured tenants.

    Use cases

    • Providing a client access to their private CRM data directly within Claude.
    • Exposing existing FastAPI backend logic to an agentic workflow via remote HTTP.
    • Managing multiple customer MCP endpoints on a single edge device with strict isolation.
    • Auditing LLM-driven write operations for legal or compliance requirements.

    Known limitations

    Does not support SSE (Server-Sent Events) for progress streaming. Sessions are stored in-memory, restricting the server to a single worker process unless an external store like Redis is added.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 days ago

    • Free to download with an account

    Needs access to

    Cloudflareaccess

    Listed4 days ago

    What's inside

    Frequently Asked Questions