{"_id":"@atbas/m-mcp-connector","_rev":"2-7f23d95d3b5cea14e6c18e6b67bc7d34","name":"@atbas/m-mcp-connector","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"@atbas/m-mcp-connector","version":"1.0.0","keywords":["mcp","model-context-protocol","jazzcash","dgpays","stdio"],"author":{"name":"Eren Atbas","email":"eren.atbas@gmail.com"},"license":"MIT","_id":"@atbas/m-mcp-connector@1.0.0","maintainers":[{"name":"eatbas","email":"eren.atbas@gmail.com"}],"homepage":"https://m-mcp.atbas.xyz/","bugs":{"url":"https://github.com/eatbas/m-mcp-connector/issues"},"bin":{"m-mcp-connector":"dist/cli.js"},"dist":{"shasum":"f9adcbd453dc7d0bf3eb2d885a861fcedc05af47","tarball":"https://registry.npmjs.org/@atbas/m-mcp-connector/-/m-mcp-connector-1.0.0.tgz","fileCount":51,"integrity":"sha512-2pqbSy3s07cbbpcBQH5MMYFF4QXmVLS3owMtDfU2Q+KsJSFmugjqZuFxaDwHiOBapymWEmhGk+U90qTQ1fKS9g==","signatures":[{"sig":"MEUCICMywkllnpr/ScZC9k2uwIfaJUkcsI89pl+tCNGlIb52AiEAwm2oh0kPmBNSdJD2mhtbaIwY4gXHg/D4uVLmz3j80FA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@atbas%2fm-mcp-connector@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":192797},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"f13d9ca9b34d419963fb8e5c1b9abbc8a53e9b58","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","prepublishOnly":"npm run build && npm run typecheck && npm test"},"_npmUser":{"name":"eatbas","email":"eren.atbas@gmail.com"},"repository":{"url":"git+https://github.com/eatbas/m-mcp-connector.git","type":"git"},"_npmVersion":"11.16.0","description":"stdio-to-HTTP bridge for MCP clients that cannot reach a remote Streamable HTTP server.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^6.0.3","@types/node":"^24.13.3"},"_npmOperationalInternal":{"tmp":"tmp/m-mcp-connector_1.0.0_1787602543937_0.1896298183344809","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@atbas/m-mcp-connector","version":"1.1.0","description":"stdio-to-HTTP bridge for MCP clients that cannot reach a remote Streamable HTTP server.","license":"MIT","author":{"name":"Eren Atbas","email":"eren.atbas@gmail.com"},"repository":{"type":"git","url":"git+https://github.com/eatbas/m-mcp-connector.git"},"homepage":"https://m-mcp.atbas.xyz/","bugs":{"url":"https://github.com/eatbas/m-mcp-connector/issues"},"keywords":["mcp","model-context-protocol","jazzcash","dgpays","stdio"],"type":"module","engines":{"node":">=22.0.0"},"bin":{"m-mcp-connector":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"main":"./dist/index.js","types":"./dist/index.d.ts","publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","test":"vitest run","prepublishOnly":"npm run build && npm run typecheck && npm test"},"dependencies":{"@modelcontextprotocol/sdk":"^1.30.0","zod":"^4.4.3"},"devDependencies":{"@types/node":"^24.13.3","typescript":"^6.0.3","vitest":"^4.1.10"},"gitHead":"81163cc3cecf7d0701a668f572ef7987be3e1433","_id":"@atbas/m-mcp-connector@1.1.0","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-enXsIsVZoztZ44uO5EY9eZ3vSvn1TNF+jgJ03wkSMi3CLtEs92fU3qUOOiCU2b/vhqPtOxLGc6ufIGYX612FxA==","shasum":"62d166d4044cb7013b1d110725f86fc1cbf497f3","tarball":"https://registry.npmjs.org/@atbas/m-mcp-connector/-/m-mcp-connector-1.1.0.tgz","fileCount":51,"unpackedSize":192797,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@atbas%2fm-mcp-connector@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCm4z14XS8cSeaN/TsM0UBSRSSLvie2hNR7EYW/f7hD3wIgGZNzAgcKhybm7lKP0FNv61xQoWHHL5Oe168SUyV95X0="}]},"_npmUser":{"name":"eatbas","email":"eren.atbas@gmail.com"},"directories":{},"maintainers":[{"name":"eatbas","email":"eren.atbas@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/m-mcp-connector_1.1.0_1787684818546_0.80408858206821"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-24T20:15:43.746Z","modified":"2026-08-25T19:06:59.214Z","1.0.0":"2026-08-24T20:15:44.087Z","1.1.0":"2026-08-25T19:06:58.694Z"},"bugs":{"url":"https://github.com/eatbas/m-mcp-connector/issues"},"author":{"name":"Eren Atbas","email":"eren.atbas@gmail.com"},"license":"MIT","homepage":"https://m-mcp.atbas.xyz/","keywords":["mcp","model-context-protocol","jazzcash","dgpays","stdio"],"repository":{"type":"git","url":"git+https://github.com/eatbas/m-mcp-connector.git"},"description":"stdio-to-HTTP bridge for MCP clients that cannot reach a remote Streamable HTTP server.","maintainers":[{"name":"eatbas","email":"eren.atbas@gmail.com"}],"readme":"# @atbas/m-mcp-connector\n\nThe connector for **m-mcp**, a hosted MCP service that serves version-pinned\nJazzCash and DGPays integration documentation to your coding agent.\n\nInstall it, put your token in your agent's settings, and your agent can ask\nm-mcp for the guide, the exact wire field names, the meaning of a response code\nor the go-live checklist — instead of answering from general knowledge of\npayment gateways.\n\nThis package serves nothing itself. Every request it receives is forwarded to\nthe hosted endpoint under your access token, and the endpoint's answer is\nreturned unchanged.\n\n## Install it globally\n\n```bash\nnpm i -g @atbas/m-mcp-connector\n```\n\nNeeds **Node 22 or newer**. Update it later with the same command.\n\nThen add it to your agent's configuration. This is the block the m-mcp console\ngives you when your token is issued:\n\n```json\n{\n  \"mcpServers\": {\n    \"m-mcp\": {\n      \"command\": \"m-mcp-connector\",\n      \"env\": {\n        \"M_MCP_TOKEN\": \"<the token the console showed you>\"\n      }\n    }\n  }\n}\n```\n\nFor Claude Desktop that file is `claude_desktop_config.json`; for other clients\nit is whatever holds their `mcpServers` map.\n\nPaste the block rather than typing the token on a command line. Every argument a\nprocess is started with is readable by anything else on the machine, through `ps`\nand `/proc/<pid>/cmdline`, and a token typed into a shell also stays in that\nshell's history file. An MCP client's `env` block is neither.\n\n## Configuration\n\n| Setting      | How it is given                                               | Default                                         |\n| ------------ | ------------------------------------------------------------- | ----------------------------------------------- |\n| Access token | `M_MCP_TOKEN`                                                 | none — the connector will not start without one |\n| Endpoint     | `M_MCP_URL`, or the first argument                            | `https://m-mcp.atbas.xyz/mcp`                   |\n| Verbosity    | `M_MCP_LOG_LEVEL`: `silent`, `error`, `warn`, `info`, `debug` | `info`                                          |\n\nThere is deliberately no `--token=` flag, for the reason above. Configure the\ncredential through `M_MCP_TOKEN`; the console does not issue a credential-bearing\nURL.\n\nOne older form is still accepted, and is documented here because the connector\nreally does honour it: a token supplied inside the endpoint URL as `?p=<token>`.\nThat is what merchants were given before this package existed. It is **stripped\nfrom the URL before any request is made**, so the credential never reaches the\nservice's access log or your proxy's, and `M_MCP_TOKEN` wins when both are\npresent — with a warning on stderr saying so, if the two disagree. Nothing issues\nthat form any more; if you have one, move the value into `M_MCP_TOKEN` at your\nconvenience.\n\nNo `.env` file is ever read. Your client starts this process in whichever\ndirectory it happens to be in — frequently one of your own projects — and a\ndotenv loader would silently adopt whatever credentials that project holds.\n\n## When it will not start\n\nRun:\n\n```bash\nm-mcp-connector doctor\n```\n\nIt prints the absolute path of the installed binary, your Node version, the\nendpoint it would talk to, whether a token was found and where from — never its\nvalue — the result of one live authenticated call when the configuration is\nvalid, and a configuration block built around that absolute path, ready to\npaste. If the check fails, the report names whether the configuration,\ncredential, endpoint or connector needs attention.\n\n| What you see                                 | What to do                                                                                                                                                                 |\n| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Your client reports `ENOENT`, or \"not found\" | Your client cannot see `m-mcp-connector` on its `PATH`. Run `m-mcp-connector doctor` in a terminal and paste the configuration block it prints — it uses an absolute path. |\n| `Node … is too old`                          | Upgrade Node to 22 or newer. `npm install` does not enforce this by default, which is why nothing warned you.                                                              |\n| `No access token`                            | Set `M_MCP_TOKEN` in your client's `env` block.                                                                                                                            |\n| `Malformed access token`                     | Copy the token again; a truncated paste is the usual cause.                                                                                                                |\n| `did not accept this access token`           | Check it has not been revoked, and that it was copied in full.                                                                                                             |\n| `refused this access token`                  | It has been revoked or has expired. Ask for a new one.                                                                                                                     |\n| `could not be reached`                       | The endpoint is unreachable from this machine. Check any proxy.                                                                                                            |\n| `A newer connector is available`             | Run `npm i -g @atbas/m-mcp-connector` again. The old one keeps working; this is advice, not a refusal.                                                                     |\n\n**Why the first row happens.** A GUI-launched application on macOS inherits a\nminimal `PATH` — roughly `/usr/bin:/bin:/usr/sbin:/sbin` — so a Node installed\nthrough nvm or Homebrew is invisible to it, and the bare name `m-mcp-connector`\ncannot be found. An absolute path in `command` fixes it, and `doctor` is how you\nget that path without hunting for it.\n\n## Diagnostics\n\n**stdout carries the JSON-RPC protocol and nothing else.** A single stray byte\nwritten there would desynchronise your client for the rest of the session, so\nevery diagnostic goes to stderr instead, one JSON object per line. Your client\ncaptures that stream: in Claude Desktop it is under `Settings → Developer → Open\nLogs Folder`.\n\n`m-mcp-connector doctor` is the exception, and only because it runs _instead of_\na session — it never opens the protocol channel, so its report goes to stdout\nwhere you can read, pipe or redirect it.\n\nEvery start-up failure carries a `fault` field saying whose move it is next:\n`configuration` and `credential` are yours to fix, `endpoint` means the service\ncould not be reached and nothing you set is wrong, and `connector` means a defect\nin this package worth reporting.\n\nIt exits `0` when your client closes the connection, which is what stopping the\nserver in your client does.\n\n## What it does with your token\n\n- It is sent to the endpoint in one place, an `Authorization: Bearer` header.\n- If you supplied it inside the URL, the `?p=` parameter is removed before any\n  request is made.\n- It is never written to a log line, and never appears in a `doctor` report —\n  the report is passed through the same redaction every log line gets, so a\n  token that arrived inside somebody else's error message is scrubbed too.\n  Diagnostics name the endpoint by origin and path only, never with a query\n  string, and every line the connector writes is scrubbed of the token on the way\n  out as a second line of defence.\n\nNothing else on your machine is read: the connector holds no credentials of your\nown and reaches no local file.\n\n## Where this comes from\n\n[`eatbas/m-mcp-connector`](https://github.com/eatbas/m-mcp-connector) is the\ngenerated public mirror of `packages/connector` in the private repository where\nthe m-mcp service is developed. Every release is built and published from that\nmirror so npm can issue a provenance attestation. After installing, verify the\nattestation with:\n\n```bash\nnpm audit signatures\n```\n\nThe manifest's `repository` deliberately carries no `directory` field: npm\nvalidates the attestation against the repository the publishing workflow ran in,\nand the package sits at that repository's root. This README keeps that rationale\nbeside the package metadata instead of maintaining a separate release document.\n\n## Working on it\n\nIn the private m-mcp workspace:\n\n```bash\npnpm --filter @atbas/m-mcp-connector build      # tsc, straight to dist/\npnpm --filter @atbas/m-mcp-connector typecheck\npnpm --filter @atbas/m-mcp-connector test\n```\n\nIn a generated checkout of the public mirror:\n\n```bash\nnpm ci\nnpm run build      # tsc, straight to dist/\nnpm run typecheck\nnpm test\n```\n\nThe suite runs entirely in process: the hosted endpoint is stubbed by a real MCP\nserver behind the SDK's own Streamable HTTP transport, reached through an\ninjected `fetch`, so no test touches the network. `src/stdio.test.ts` is the one\nto keep green above all others — it drives a whole request cycle, failure paths\nincluded, and asserts that nothing but JSON-RPC framing reaches stdout and that\nthe token appears in no output at all.\n\nThe public mirror is **generated**. Fixes are made in the private workspace and\nsynced out; a change committed directly to the mirror is overwritten by the next\nsync.\n\n## Licence\n\nMIT. See [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}