Skip to main content

MCP server bridging Claude Code to a browser extension over WS+HMAC

Project description

sallyport

The Python MCP-server half of Sallyport — a security-first bridge between Claude Code (or any MCP client) and your Chrome, with explicit trust boundaries instead of implicit ones.

Claude Code ── MCP/stdio ──▶ daemon (this package) ── WS+HMAC ──▶ extension (MV3) ── CDP ──▶ Chrome

The daemon speaks MCP on stdio and hosts an HMAC-authenticated WebSocket server on 127.0.0.1:10086 that the companion Chrome extension connects into. Every frame is signed (HMAC-SHA256 + timestamp + nonce); the extension enforces a per-domain allowlist and a per-domain opt-in for arbitrary JS.

Install

pip install sallyport

The package installs the sallyport-daemon console command.

Quickstart

sallyport-daemon doctor          # check Python, secret file + perms, port; print the pairing block
claude mcp add sallyport sallyport-daemon   # register with Claude Code

Then load the unpacked extension (or the release zip) from the main repository and paste the pairing block into its popup.

  • sallyport-daemon list-tools — print the tool catalogue (no daemon start)
  • sallyport-daemon serve — WS-only mode (no MCP) for wire testing
  • sallyport-daemon exec <tool> k=v … — fire one tool from the shell

Security

The full threat model, the load-bearing invariants, and known limitations live in SECURITY.md. In short: loopback-only bind, HMAC on every frame, a domain allowlist enforced in the extension, per-domain evaluate opt-in, password-field gates, and daemon-side filesystem sandboxes for upload/save_to_file.

License

MIT — see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sallyport-0.15.1.tar.gz (64.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sallyport-0.15.1-py3-none-any.whl (70.7 kB view details)

Uploaded Python 3

File details

Details for the file sallyport-0.15.1.tar.gz.

File metadata

  • Download URL: sallyport-0.15.1.tar.gz
  • Upload date:
  • Size: 64.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for sallyport-0.15.1.tar.gz
Algorithm Hash digest
SHA256 797278a1c273aa37a3c60a88e1cdf4c342d561461a0e342605fe3c3ef45f58aa
MD5 2236d5f65d94d8645e7b778248976cc5
BLAKE2b-256 f3f990dae97987bbeb8c130bf6646e83a11d088455323e1471a555ce42663c05

See more details on using hashes here.

Provenance

The following attestation bundles were made for sallyport-0.15.1.tar.gz:

Publisher: publish.yml on ginkida/sallyport

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sallyport-0.15.1-py3-none-any.whl.

File metadata

  • Download URL: sallyport-0.15.1-py3-none-any.whl
  • Upload date:
  • Size: 70.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for sallyport-0.15.1-py3-none-any.whl
Algorithm Hash digest
SHA256 bce5837032f5f377c52f5c7dcce758c45f05f2a01c450dc0d725ef605a9c6a43
MD5 c37a15592485ad45c8d79910a3fb3e37
BLAKE2b-256 aa0fb20d55d0fa4fc6bf5621fc2bfbb654cb5cd45b17ac1d4bf4c5294a6c14b7

See more details on using hashes here.

Provenance

The following attestation bundles were made for sallyport-0.15.1-py3-none-any.whl:

Publisher: publish.yml on ginkida/sallyport

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page