MCPlama logo

MCPlama

Visit

An open-source, self-hosted MCP gateway that centralizes server access, credentials, policies, connection tokens, and audit logs for AI clients.

Share:
View alternatives

MCPlama

MCPlama is an open-source, self-hosted MCP gateway and control plane for teams that run more than one Model Context Protocol server. Instead of copying credentials and server configuration into every developer's Claude, Codex, Cursor, or VS Code setup, operators register a server once and give each permitted user a controlled connection URL. The project released v1.0.1 on October 5, 2026 and is licensed under AGPL-3.0-or-later.

What it centralizes

The gateway keeps OAuth and API credentials, server lifecycle controls, user and server access policies, connection tokens, and MCP activity audit logs in one deployment. When a client connects, MCPlama resolves its connection token, validates the request origin, checks policy, injects the relevant credential, records the event, and proxies the request to the selected MCP server. This is a practical answer to a common team problem: local MCP JSON files tend to duplicate secrets and make revocation difficult.

MCPlama separates the public gateway from the component that starts MCP containers. In the recommended multi-container setup, a broker has Docker socket access while the gateway and runner containers do not. The architecture is useful for teams that need a clear boundary around where untrusted tool runtimes execute, although operators must still review each server they install and secure the host, reverse proxy, backups, and secrets.

A practical workflow

Start with the documented Docker image and complete the setup wizard; there is no default administrator account. Add a low-risk MCP server from the catalog, authorize its provider credentials, and create one connection token for a test user. Put the generated URL into a supported client configuration, such as Claude Desktop, Cursor, or .vscode/mcp.json, then confirm the audit log and access policy behave as expected. Only after that should a team move shared production credentials behind the gateway.

The project documents a local evaluation deployment, but production requires operator-managed secrets and an HTTPS reverse proxy. A self-hosted gateway reduces duplicated configuration; it does not eliminate the security implications of granting an AI client access to an MCP tool. Treat tokens as credentials, rotate them when staff or servers change, and keep the container broker isolated as the security model describes.

Alternatives and fit

Choose MCPlama when a team needs to centralize multiple MCP servers and give different users controlled, auditable connections. It is a protocol-layer product rather than an agent framework or an individual MCP server. MCP Login describes the underlying protocol ecosystem, while OpenClaw and CowAgent are broader self-hosted agent options with different responsibilities.

MCPlama is a promising early project, not a managed SaaS. Its small maintenance history and AGPL license deserve review before an organization standardizes on it. Read the official security model and deployment guide before exposing it to the internet.

Comments

No comments yet. Be the first to comment!