Skip to main content

Sprintable MCP

BYO 에이전트용 Sprintable MCP 서버. 에이전트 런타임을 Sprintable API에 stdio로 연결한다. 레포 clone 불필요 — uvx 한 줄로 구동.

Quick start

export SPRINTABLE_API_URL=https://sprintable-backend-prod-787818285179.asia-northeast3.run.app   # backend-direct(SSE 필수). dev=sprintable-backend-dev-787818285179.asia-northeast3.run.app
export AGENT_API_KEY=sk_live_...                         # 에이전트 API 키
uvx sprintable

설치형:

pip install sprintable
sprintable        # 엔트리포인트
# 또는
python -m sprintable_mcp

동작

  • 부팅 시 /api/v2/auth/me로 인증 컨텍스트를 잡고, /api/v2/mcp/manifest로 이 키의 허용 toolset을 받아 허용된 도구만 노출한다(E-MCP S3). 호출 시에도 허용 밖 도구는 차단(E-MCP S2).
  • 매니페스트를 못 받으면 레거시 비파괴셋으로 안전 degrade(파괴적 도구 숨김). crash 없음.

의존성

backend(app/*) 비의존 — mcp / httpx / pydantic / pydantic-settings만 필요(E-MCP S4 import 디탱글).

필수 환경변수

변수 설명
SPRINTABLE_API_URL Sprintable 백엔드 URL (backend-direct run.app — CF 깔끔도메인 app.sprintable.ai 금지: /agent/stream SSE 버퍼·봇차단)
AGENT_API_KEY 에이전트 API 키(sk_live_...). http 모드는 per-request bearer 가 실인증이라 never-hit fallback
MCP_TRANSPORT stdio(기본·로컬) | http(Cloud Run 호스팅)
MCP_ALLOWED_HOSTS http 모드 DNS-rebinding 보호 호스트 화이트리스트(comma·exact). 비우면 보호 OFF(bearer+TLS 가 실보안)

Cloud Run 호스팅 배포

환경 스크립트 서비스 MCP_ALLOWED_HOSTS
dev scripts/deploy_mcp_dev.sh sprintable-mcp-dev (비움·보호 OFF)
prod scripts/deploy_mcp_prod.sh sprintable-mcp-prod sprintable-mcp-prod-787818285179.asia-northeast3.run.app,mcp.sprintable.ai(exact·보호 ON·다중)
  • 동일 backend 이미지를 python -m sprintable_mcp command override 로 구동(별 빌드 0).
  • gcloud 배포 실행은 PO 전담(인프라 lane). 스크립트는 PR 리뷰 대상.
  • prod AGENT_API_KEY 는 Secret Manager 참조(AGENT_API_KEY_SECRET=<secret-name>)·값 노출 0. 미지정 시 per-request-bearer placeholder 로 폴백(http 모드 실인증=per-request bearer).
  • 온보딩 config: prod 백엔드에 MCP_PUBLIC_URL(=https://mcp.sprintable.ai/mcp 깔끔 도메인) 설정 시 온보딩 응답 mcp_config 가 streamable-http(type:"http"+Bearer)로 생성(미설정=dev localhost SSE).

고객 facing 깔끔 도메인(mcp.sprintable.ai)

raw Cloud Run URL 대신 고객엔 https://mcp.sprintable.ai/mcp 노출. CF route/Worker proxy 패턴(app.sprintable.ai 와 동일·Cloud Run domain-mapping 미사용·cf-ray 확認). additive — raw run.app origin 유지하며 깔끔 도메인 추가.

  • MCP_ALLOWED_HOSTS additive: run.app(오리진) + mcp.sprintable.ai(CF 가 원본 Host 전달 시 421 방지·S2 DNS-rebinding). --set-env-vars 가 comma 로 항목 구분하므로 다중 host 값은 ^##^ 커스텀 구분자로 escape.
  • PO 마무리: ①CF zone DNS(mcp 서브도메인 → run.app origin·가능하면 origin Host=run.app override) ②게이트웨이 재배포 또는 gcloud run services update sprintable-mcp-prod --update-env-vars="^##^MCP_ALLOWED_HOSTS=run.app,mcp.sprintable.ai" ③prod 백엔드 MCP_PUBLIC_URL=https://mcp.sprintable.ai/mcp --update-env-vars.

Metadata

Release files for sprintable 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sprintable 0.2.0
File Size Uploaded
sprintable-0.2.0.tar.gz 85.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sprintable 0.2.0
File Interpreter ABI Platform
sprintable-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 198.6 kB

Release files / sprintable-0.2.0.tar.gz

Download URL sprintable-0.2.0.tar.gz
Size 85.9 kB
Tags Source
SHA-256 checksum
How to use checksums
28c41b22c1e18274b2b222ebf16a92673c9051fe12d36583410c7a660a64b75d
BLAKE2b-256 checksum
How to use checksums
ec16ac3bb34cc66fb70bf9b2bd281dd6d290d1df8fae8b70915a5fec959e309d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release files / sprintable-0.2.0-py3-none-any.whl

Download URL sprintable-0.2.0-py3-none-any.whl
Size 112.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f8b245b4d63b790298fe2680242fdb5d13f10a32c912222003ed028c443c8670
BLAKE2b-256 checksum
How to use checksums
4d3ca3fbeb882266b0a829dc89e8f4131ca6e43434665c773e29a02778aa32a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page