Skip to main content

ramen-mcp-bridge

A stdio MCP server that forwards every JSON-RPC message to a Ramen worker's ramen.v1.Mcp/Call over gRPC. It exists for MCP clients that can only start a local process (stdio) — Claude Desktop, Cursor, and the reference mcp SDK all speak Streamable HTTP directly against Ramen's edge and don't need it; see local-quickstart for that path instead.

Install

pip install ramen-mcp-bridge        # → ramen-mcp-bridge on PATH
# or: uv tool install ramen-mcp-bridge

Use

Against a local worker (plaintext, no TLS):

RAMEN_MCP_KEY="$KEY" ramen-mcp-bridge --target localhost:8080 --insecure --group demo --zone local

Against a cloud deployment (GCP GKE or AWS EKS) fronted by a load balancer with a publicly-trusted certificate (the default since Ramen v0.5.5 — see deploy/README.md):

ramen-mcp-bridge --target <public-hostname>:443 --tls --key rmk_… --group demo --zone a

--tls alone verifies against your system's CA trust store — nothing to download, no kubectl command. An older cluster still using the self-signed fallback needs its CA pulled once (kubectl -n ramen-system get secret ramen-console-tls -o jsonpath='{.data.tls\.crt}' | base64 -d > ramen-lb.pem) and a --ca ramen-lb.pem flag.

Sign in as yourself (0.2.0)

Instead of a shared rmk_ group key, the bridge can sign you in through the console — with your password, a magic link, or the identity provider the console is configured with (Microsoft Entra ID, Google Workspace, any OIDC issuer). A super admin registers an OAuth client on the console's Config page with the redirect URI http://127.0.0.1/callback (any port) and gives you its client id; your account needs a role in the group (an MCP User is enough):

ramen-mcp-bridge --target <public-hostname>:443 --tls --oauth https://<public-hostname> --client-id <client id> \
  --group demo --zone a

The first run opens your browser on the console's sign-in page (--no-browser prints the URL instead); after you approve, the refresh token is kept in ~/.config/ramen-mcp-bridge/tokens-*.json (mode 0600, --token-file to move it) and later runs need no browser until it expires or is revoked. Access tokens are scoped to mcp:<group>:<zone>, refreshed before they expire and after the worker answers UNAUTHENTICATED; every call the worker logs then names your account (user:<id>), not a key. Environment: RAMEN_BRIDGE_OAUTH, RAMEN_BRIDGE_CLIENT_ID, RAMEN_BRIDGE_TOKEN_FILE.

Point an MCP client at it directly:

{"mcpServers": {"ramen-stdio": {"command": "ramen-mcp-bridge",
  "env": {"RAMEN_BRIDGE_TARGET": "<public-hostname>:443", "RAMEN_BRIDGE_TLS": "1",
          "RAMEN_MCP_KEY": "rmk_…", "RAMEN_BRIDGE_GROUP": "demo", "RAMEN_BRIDGE_ZONE": "a"}}}}

Every flag has a RAMEN_BRIDGE_* environment variable equivalent (--target → RAMEN_BRIDGE_TARGET, --tls → RAMEN_BRIDGE_TLS=1, --group → RAMEN_BRIDGE_GROUP, --zone → RAMEN_BRIDGE_ZONE) so the key never has to sit in a client's config file — RAMEN_MCP_KEY (or RAMEN_BRIDGE_KEY) is enough. --health [SERVICE] checks grpc.health.v1 and exits 0 when SERVING, for a liveness probe.

Develop

uv sync --group dev
uv run pytest
./gen_proto.sh   # regenerate src/ramen_proto from proto/ramen/v1/mcp.proto after a proto change

License: BSD-3-Clause, same as ramen.

Metadata

Release files for ramen-mcp-bridge 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ramen-mcp-bridge 0.2.0
File Size Uploaded
ramen_mcp_bridge-0.2.0.tar.gz 111.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ramen-mcp-bridge 0.2.0
File Interpreter ABI Platform
ramen_mcp_bridge-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 125.9 kB

Release files / ramen_mcp_bridge-0.2.0.tar.gz

Download URL ramen_mcp_bridge-0.2.0.tar.gz
Size 111.4 kB
Tags Source
SHA-256 checksum
How to use checksums
df31a59565935887338c597dbdf671e058c333e3e099c8f4460182f33a2a77aa
BLAKE2b-256 checksum
How to use checksums
a5647438cffcfc54fc4f5a7824db775fe5df787664d06f8077ee7298a116255e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / ramen_mcp_bridge-0.2.0-py3-none-any.whl

Download URL ramen_mcp_bridge-0.2.0-py3-none-any.whl
Size 14.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
07c2dc850cfff4e39b31a6ff9e552aa78caa8dc0be8316c041a42be7cd5ba9b7
BLAKE2b-256 checksum
How to use checksums
b290bcb7a330c121c120366ff8abe660d0e2ed8dd5cc6de7bac9e4404b222b15
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page