Server data from the Official MCP Registry
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
About
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Remote endpoints: streamable-http: https://www.secure-flows.com/mcp
Security Report
The secureFlows MCP server is a well-structured tool that wraps OpenAPI endpoints with proper authentication controls and input validation. Authentication is appropriately scoped—generated tools require valid tokens (firebaseToken, sessionToken, or userToken), while static tools operate token-free by design. Code quality is good with proper error handling, no dangerous patterns detected, and permissions align with the server's purpose (HTTP forwarding, file I/O for spec loading, environment variable access). Minor observations: broad exception handling in resilience patterns and environment variable access for configuration are standard for this category. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 3 high severity).
6 files analyzed · 8 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
secureFlows MCP Server
Cloud-deployable MCP server that wraps the secureFlows OpenAPI
surface tagged ai-safe and ai-optional.
This repo is a public mirror, published periodically from the private secureFlows monorepo where development actually happens. Issues and PRs are welcome; large changes may take a release cycle to land upstream first.
What is an MCP server?
An MCP server is a small HTTP service that exposes a set of “tools” an AI client can call in a standard way.
In this repo:
- The secureFlows MCP server exposes tools that are auto-generated from your OpenAPI YAML specs.
- When a client calls a tool, the MCP server forwards the call to your real secureFlows backend (
connection.host) and returns the response in a normalized tool result.
This lets an AI client:
- discover available secureFlows operations via
listTools - call them via
callTool - without hardcoding the API surface or manual auth/header wiring
What it does
Two kinds of tools, registered together in src/server.ts:
Generated tools (src/tools/build-tools.ts) — one per OpenAPI operation:
- Loads:
docs/openapi/session/secure-flows-session-api.yamldocs/openapi/user/secure-flows-user-api.yamldocs/openapi/docs/secure-flows-docs-api.yaml
- Exposes only operations tagged
ai-safeorai-optionalas MCP tools - Forwards requests to a caller-provided secureFlows host — a thin, generic HTTP wrapper with no
secureFlows-specific judgment. Every one of these requires a live
auth.*token, so they're only useful once a session already exists (see Runtime model below). - Maps secureFlows auth headers from MCP tool inputs:
auth.firebaseTokenauth.sessionTokenauth.userToken
Static tools (src/tools/static-tools.ts) — hand-written, not generated from the spec:
-
secureflows_build_login_url/secureflows_build_logout_url— build the hosted-login and redirect-logout URLs correctly by construction (always/app/sessions/login, never the legacy/app/login; refuses a post-logoutredirect_urithat points at/callbackor leakssession_token). No secureFlows token required. -
secureflows_lint_integration— checks generated app source against the integration rules and reports structured findings instead of leaving them as prose the agent has to self-police. No secureFlows token required. Two kinds of finding:scope: "file"— a forbidden construct is present, at an exactfile:line: env-var config constants, token inlocalStorage, legacy/app/login,fetch/XHR logout, client-side JWT decode, revoke-on-sign-out, emptycatch {}, restoresetSession(null)on non-auth errors, Continue CTA gated onsession === null, …scope: "project"— required handling is absent across every file passed in: detecting401/410but never clearing the token, never handling403, or handling403without theBILLING_GRACE_LOCKcarve-out.
The absence checks exist because the pattern rules structurally could not catch the defect class that dominates real generated apps. Measured: on a real trial's app that the eval harness's LLM judge scored 4/10 — citing "stale token never cleared on signed-out", "403 variants unhandled", "no error handling" — the pattern rules alone produced zero findings, because every one of those bugs is an absence, and a regex can only see what is present. With the absence checks it produces 3, including the
error-severity token-clearing one. Both check kinds are validated against the canonicaltemplates/web-app-secureflowsstarter, which must stay at zero findings.Still heuristic text analysis, not a parser or type checker: it misses what it has no rule for, a project check can be satisfied by the right keyword in the wrong place, and it cannot cover the checks that need a running app (auth-guard mount races, the fresh-reload check). A fast first pass — not a replacement for the Agent implementation checklist in SKILL.md.
These static tools exist because the generated tools can't help with the part of an integration that happens before a session exists — scaffolding the redirect/callback/token-lifecycle code — which is exactly where most secureFlows integration mistakes happen.
Uses a stateless HTTP MCP transport, so the server does not persist tenant config or secrets.
Runtime model
Each tool call receives:
connection.host: secureFlows base URLconnection.workspaceName: optional default workspaceconnection.appId: optional default application idauth.*: whichever token the selected endpoint needs
workspaceName and appId are treated as stable app config. The server injects them into known secureFlows request shapes when omitted by the caller.
For agents (the only supported client path)
Point the MCP client at the hosted URL — same host as the product, path /mcp (not a subdomain):
| Environment | MCP URL |
|---|---|
| Production | https://www.secure-flows.com/mcp |
| Staging | https://secure-flows-staging.onrender.com/mcp |
| Health | …/mcp/health → {"ok":true} |
{
"mcpServers": {
"secureflows": {
"url": "https://www.secure-flows.com/mcp"
}
}
}
Do not tell agents to run npx or use localhost — that splits the story and breaks anyone who never starts a local process. Wired in the web Docker image (Node on 127.0.0.1:8787, nginx location = /mcp; see docs/ROUTING.md). The Node process installs uncaughtException / unhandledRejection guards so a single bad request does not exit the process; docker/entrypoint.sh also restarts MCP if the process still exits.
Local development (maintainers of this package)
cd mcp-server
npm install
npm run build
npm test
npm run dev
The server starts on http://0.0.0.0:8787 by default (POST /mcp, GET /health). This is for
changing the MCP server itself — not the path product agents should configure.
Environment variables
PORT: HTTP port, default8787(in the web container, entrypoint setsPORT=8787only for the MCP child so nginx keeps Render’s public$PORT)HOST: bind host, default0.0.0.0(web container uses127.0.0.1)ALLOWED_HOSTS: optional comma-separated host allowlist for MCP host header validationMCP_ALLOWED_HOSTS: entrypoint override forALLOWED_HOSTSwhen starting the in-image process
Endpoints
POST /mcp: MCP Streamable HTTP endpointGET /health: health check (publicly exposed asGET /mcp/healthvia nginx)
Embedding secureFlows in an application
Product apps integrate directly with secureFlows HTTP APIs and hosted login. Start from:
docs/integration/quickstart.md— provisioning (workspace + application) and runtime hosted logindocs/integration/CONCEPT.md— baseline order: login → create workspace before advanced featuresdocs/openapi/integration-auth.yaml—/app/sessions/login(session apps) vs/app/login(legacy/console)
Product apps still integrate directly with the HTTP APIs above, not through this server. The
generated tools here are for agents/automation that already have a token (testing, scripted
verification). The static tools (secureflows_build_login_url, secureflows_build_logout_url,
secureflows_lint_integration) need no token and are meant to be called by a coding agent while
it's still scaffolding the integration — see What it does above.
Testing this MCP server
npm testinmcp-server/— unit tests plus HTTP smoke (test/http-smoke.test.ts): starts the Express app on an ephemeral port, checksGET /health,GET /mcp→ 405, and a real Streamable-HTTP clientlistTools+callTool(secureflows_build_login_url).- After deploy: Playwright
tests/smoke/mcp-health.spec.tshits publicGET /mcp/healthandGET /mcpon the target host (production smoke job). - Local maintainer loop:
npm run dev, thencurl -sS http://127.0.0.1:8787/health. - Optional: MCP client against
POST /mcpwithconnection.host+auth.*for generated tools.
Deployment
Shipped inside the web Docker image and proxied at /mcp on www.secure-flows.com / staging
(see For agents above). No separate subdomain.
The npm package secureflows-mcp-server is how CI publishes a versioned artifact (and how a
standalone container can be built from mcp-server/Dockerfile); it is not the agent-facing
setup path. Publish on v*.*.* tags via .github/workflows/publish-secureflows-mcp-server.yml.
docker build -f mcp-server/Dockerfile -t secureflows-mcp-server .
docker run --rm -p 8787:8787 secureflows-mcp-server
Notes
- Hosted login / redirect endpoints are exposed only if they are tagged
ai-safeorai-optionalin the OpenAPI specs. - Documentation search (
get_docs_search) isai-safe, requires noauth.*— onlyconnection.hostand queryq. - Human-only admin console APIs are intentionally excluded.
- The response payload from each tool includes:
statusokurlheadersdata
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
