corporate-mcp-client
SPIFFE/mTLS MCP client for Claude Desktop.
Fetches short-lived X.509 certificates from your external Cert API — no local SPIRE agent, no Python pre-installed, no cert files on disk.
How it works
Claude Desktop (stdio)
|
v
corporate-mcp-client (spawned by uvx)
|
|-- POST /attest -> your Cert API (gets 1h X.509 cert)
|-- builds mTLS SSLContext in memory
|
v
Your Nginx (validates SPIFFE ID cert)
|
v
MCP Gateway -> MCP Server (unmodified)
claude_desktop_config.json
{
"mcpServers": {
"corporate-mcp": {
"command": "uvx",
"args": ["corporate-mcp-client"],
"env": {
"CERT_API_URL": "https://cert-api.yourcompany.com",
"ENROLLMENT_TOKEN": "your-enrollment-token-here",
"MCP_SERVER_URL": "https://your-mcp-server.com/mcp"
}
}
}
}
Environment variables
| Variable | Required | Description |
|---|---|---|
| CERT_API_URL | Yes | Your Cert API base URL |
| ENROLLMENT_TOKEN | Yes | Pre-shared token issued per customer |
| MCP_SERVER_URL | Yes | Your MCP server endpoint |
| CERT_API_CA | No | Path to CA bundle for Cert API (private CA) |
| CERT_REFRESH_SECS | No | Cert refresh window in seconds (default: 3300) |
| LOG_LEVEL | No | DEBUG / INFO / WARNING (default: INFO) |
Customer setup
# 1. Install uv (once)
curl -LsSf https://astral.sh/uv/install.sh | sh
# 2. Add config block to claude_desktop_config.json
# 3. Restart Claude Desktop
# Done — uvx handles everything else automatically
Metadata
Release files for agent-mcp-mtls-util 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agent_mcp_mtls_util-1.0.0.tar.gz | 1.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agent_mcp_mtls_util-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 4.1 kB
Release files / agent_mcp_mtls_util-1.0.0.tar.gz
| Download URL | agent_mcp_mtls_util-1.0.0.tar.gz |
|---|---|
| Size | 1.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cb054d4fe5701f30d42a34ae0ba882a1e7e15d1333d1dea9dc31247a6ac46fef
|
|
BLAKE2b-256 checksum How to use checksums |
22af6192f0f6c64e60c169ee668fa4d2321c6e42b8e6ed0d3425614802cabe7d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.12
|
Release files / agent_mcp_mtls_util-1.0.0-py3-none-any.whl
| Download URL | agent_mcp_mtls_util-1.0.0-py3-none-any.whl |
|---|---|
| Size | 2.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1122ca9c2c82087aff51de04be31039aa1c1c6c550435fd546dead358136e265
|
|
BLAKE2b-256 checksum How to use checksums |
865c3ea7ed7e4a8bee0377a44eebc94ce689d5b8dab0760f7c611a9b5309f82c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.12
|