corporate-mcp-client
SPIFFE/mTLS MCP client for Claude Desktop.
Fetches short-lived X.509 certificates from your external Cert API — no local SPIRE agent, no Python pre-installed, no cert files on disk.
How it works
Claude Desktop (stdio)
|
v
corporate-mcp-client (spawned by uvx)
|
|-- POST /attest -> your Cert API (gets 1h X.509 cert)
|-- builds mTLS SSLContext in memory
|
v
Your Nginx (validates SPIFFE ID cert)
|
v
MCP Gateway -> MCP Server (unmodified)
claude_desktop_config.json
{
"mcpServers": {
"corporate-mcp": {
"command": "uvx",
"args": ["corporate-mcp-client"],
"env": {
"CERT_API_URL": "https://cert-api.yourcompany.com",
"ENROLLMENT_TOKEN": "your-enrollment-token-here",
"MCP_SERVER_URL": "https://your-mcp-server.com/mcp"
}
}
}
}
Environment variables
| Variable | Required | Description |
|---|---|---|
| CERT_API_URL | Yes | Your Cert API base URL |
| ENROLLMENT_TOKEN | Yes | Pre-shared token issued per customer |
| MCP_SERVER_URL | Yes | Your MCP server endpoint |
| CERT_API_CA | No | Path to CA bundle for Cert API (private CA) |
| CERT_REFRESH_SECS | No | Cert refresh window in seconds (default: 3300) |
| LOG_LEVEL | No | DEBUG / INFO / WARNING (default: INFO) |
Customer setup
# 1. Install uv (once)
curl -LsSf https://astral.sh/uv/install.sh | sh
# 2. Add config block to claude_desktop_config.json
# 3. Restart Claude Desktop
# Done — uvx handles everything else automatically
Metadata
Release files for agent-mcp-mtls-util 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agent_mcp_mtls_util-1.0.1.tar.gz | 7.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agent_mcp_mtls_util-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.3 kB
Release files / agent_mcp_mtls_util-1.0.1.tar.gz
| Download URL | agent_mcp_mtls_util-1.0.1.tar.gz |
|---|---|
| Size | 7.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8c01401419c254db0b9ee16d75aa380fb2bc36a17c0f70ad8082207f46c4cc08
|
|
BLAKE2b-256 checksum How to use checksums |
148dc103254bde898825a736725c00af011ab690cdae414de7c8af0b7570420a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.12
|
Release files / agent_mcp_mtls_util-1.0.1-py3-none-any.whl
| Download URL | agent_mcp_mtls_util-1.0.1-py3-none-any.whl |
|---|---|
| Size | 7.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f84a963644c158662e736ed116624f2527583eebf6a707160d1a26f0ba56a6bb
|
|
BLAKE2b-256 checksum How to use checksums |
4b5ad4f42d99a5dbd009ff33f27bcdca14a12b2df02e83eb64358985dbd63b03
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.12
|