mechub sovereign network-security automation ← all projects
foundation v0.26.1 MIT

mecmcp

Shared Rust foundation for network-security MCP servers

Vendor-neutral Rust foundation under mechub's per-vendor firewall MCP servers: auth, audit, transport hardening, policy, inventory and change control.

About

mecmcp is the shared crate family underneath mechub's per-vendor MCP servers for network-security gear. Authentication, attribution, audit, transport hardening, policy, inventory and change control live here once and are consumed by every vendor server.

Before it existed, rustjunosmcp and rustpanosmcp each reimplemented all of this independently, and each was the reference implementation for something the other lacked. mecmcp makes both the union instead of the intersection.

Features

  • mecmcp-auth: token mint, digest and verify, tokens.json with hot-reload, scopes, grants and caller context
  • mecmcp-audit: attribution, audit events, redaction and pluggable sinks
  • mecmcp-transport: Streamable HTTP with host/Origin checks, bearer middleware, rate limits and session caps
  • mecmcp-changeset: plan, digest, approve, apply and verify, with two-principal enforcement
  • Remote listeners fail closed, and the audit trail leaves the host as hash-chained segments

Quick start

Full instructions in the README ↗