Sprintable MCP
BYO 에이전트용 Sprintable MCP 서버. 에이전트 런타임을 Sprintable API에 stdio로 연결한다.
레포 clone 불필요 — uvx 한 줄로 구동.
Quick start
export SPRINTABLE_API_URL=https://sprintable-backend-prod-787818285179.asia-northeast3.run.app # backend-direct(SSE 필수). dev=sprintable-backend-dev-787818285179.asia-northeast3.run.app
export AGENT_API_KEY=sk_live_... # 에이전트 API 키
uvx sprintable
설치형:
pip install sprintable
sprintable # 엔트리포인트
# 또는
python -m sprintable_mcp
동작
- 부팅 시
/api/v2/auth/me로 인증 컨텍스트를 잡고,/api/v2/mcp/manifest로 이 키의 허용 toolset을 받아 허용된 도구만 노출한다(E-MCP S3). 호출 시에도 허용 밖 도구는 차단(E-MCP S2). - 매니페스트를 못 받으면 레거시 비파괴셋으로 안전 degrade(파괴적 도구 숨김). crash 없음.
의존성
backend(app/*) 비의존 — mcp / httpx / pydantic / pydantic-settings만 필요(E-MCP S4 import 디탱글).
필수 환경변수
| 변수 | 설명 |
|---|---|
SPRINTABLE_API_URL |
Sprintable 백엔드 URL (backend-direct run.app — CF 깔끔도메인 app.sprintable.ai 금지: /agent/stream SSE 버퍼·봇차단) |
AGENT_API_KEY |
에이전트 API 키(sk_live_...). http 모드는 per-request bearer 가 실인증이라 never-hit fallback |
MCP_TRANSPORT |
stdio(기본·로컬) | http(Cloud Run 호스팅) |
MCP_ALLOWED_HOSTS |
http 모드 DNS-rebinding 보호 호스트 화이트리스트(comma·exact). 비우면 보호 OFF(bearer+TLS 가 실보안) |
Cloud Run 호스팅 배포
| 환경 | 스크립트 | 서비스 | MCP_ALLOWED_HOSTS |
|---|---|---|---|
| dev | scripts/deploy_mcp_dev.sh |
sprintable-mcp-dev |
(비움·보호 OFF) |
| prod | scripts/deploy_mcp_prod.sh |
sprintable-mcp-prod |
sprintable-mcp-prod-787818285179.asia-northeast3.run.app,mcp.sprintable.ai(exact·보호 ON·다중) |
- 동일 backend 이미지를
python -m sprintable_mcpcommand override 로 구동(별 빌드 0). - gcloud 배포 실행은 PO 전담(인프라 lane). 스크립트는 PR 리뷰 대상.
- prod
AGENT_API_KEY는 Secret Manager 참조(AGENT_API_KEY_SECRET=<secret-name>)·값 노출 0. 미지정 시 per-request-bearer placeholder 로 폴백(http 모드 실인증=per-request bearer). - 온보딩 config: prod 백엔드에
MCP_PUBLIC_URL(=https://mcp.sprintable.ai/mcp깔끔 도메인) 설정 시 온보딩 응답mcp_config가 streamable-http(type:"http"+Bearer)로 생성(미설정=dev localhost SSE).
고객 facing 깔끔 도메인(mcp.sprintable.ai)
raw Cloud Run URL 대신 고객엔 https://mcp.sprintable.ai/mcp 노출. CF route/Worker proxy 패턴(app.sprintable.ai
와 동일·Cloud Run domain-mapping 미사용·cf-ray 확認). additive — raw run.app origin 유지하며 깔끔 도메인 추가.
- MCP_ALLOWED_HOSTS additive: run.app(오리진) +
mcp.sprintable.ai(CF 가 원본 Host 전달 시 421 방지·S2 DNS-rebinding).--set-env-vars가 comma 로 항목 구분하므로 다중 host 값은^##^커스텀 구분자로 escape. - PO 마무리: ①CF zone DNS(mcp 서브도메인 → run.app origin·가능하면 origin Host=run.app override) ②게이트웨이
재배포 또는
gcloud run services update sprintable-mcp-prod --update-env-vars="^##^MCP_ALLOWED_HOSTS=run.app,mcp.sprintable.ai"③prod 백엔드MCP_PUBLIC_URL=https://mcp.sprintable.ai/mcp--update-env-vars.
Metadata
Release files for sprintable 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sprintable-0.1.1.tar.gz | 54.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sprintable-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 128.4 kB
Release files / sprintable-0.1.1.tar.gz
| Download URL | sprintable-0.1.1.tar.gz |
|---|---|
| Size | 54.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bc25bd4aaae19ed5aab048bba0a1247cc6791a58dc21f4d85adee9e391439fc9
|
|
BLAKE2b-256 checksum How to use checksums |
996027d978c2728e50885586349d4748488736e1d9381b99589956b269fcb9fd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.
Transparency logRelease files / sprintable-0.1.1-py3-none-any.whl
| Download URL | sprintable-0.1.1-py3-none-any.whl |
|---|---|
| Size | 74.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
89c7ad5678452cf980158286f33a8774d79d3b7c8f545924b97b64ec043846e4
|
|
BLAKE2b-256 checksum How to use checksums |
e5e7a4db56ebe8374799af8dccdd09b1230f3576b22e8fc5af532a45836e2e4c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.
Transparency log