Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file added .yarn/install-state.gz
Binary file not shown.
40 changes: 18 additions & 22 deletions bun.lock
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
"": {
"name": "address-validation-api",
"dependencies": {
"@modelcontextprotocol/sdk": "^1.10.2",
"cloudflare": "^4.2.0",
"hono": "^4.7.7",
"jszip": "^3.10.1",
Expand All @@ -19,6 +18,7 @@
"@types/bun": "latest",
"@types/node": "^22.14.0",
"@types/uuid": "^9.0.8",
"typescript": "^5.8.3",
},
"peerDependencies": {
"typescript": "^5.8.3",
Expand Down Expand Up @@ -46,7 +46,7 @@

"@cloudflare/workers-types": ["@cloudflare/workers-types@4.20250424.0", "", {}, ""],

"@modelcontextprotocol/sdk": ["@modelcontextprotocol/sdk@1.10.2", "", { "dependencies": { "content-type": "^1.0.5", "cors": "^2.8.5", "cross-spawn": "^7.0.3", "eventsource": "^3.0.2", "express": "^5.0.1", "express-rate-limit": "^7.5.0", "pkce-challenge": "^5.0.0", "raw-body": "^3.0.0", "zod": "^3.23.8", "zod-to-json-schema": "^3.24.1" } }, "sha512-rb6AMp2DR4SN+kc6L1ta2NCpApyA9WYNx3CrTSZvGxq9wH71bRur+zRqPfg0vQ9mjywR7qZdX2RGHOPq3ss+tA=="],
"@modelcontextprotocol/sdk": ["@modelcontextprotocol/sdk@1.6.1", "", { "dependencies": { "content-type": "^1.0.5", "cors": "^2.8.5", "eventsource": "^3.0.2", "express": "^5.0.1", "express-rate-limit": "^7.5.0", "pkce-challenge": "^4.1.0", "raw-body": "^3.0.0", "zod": "^3.23.8", "zod-to-json-schema": "^3.24.1" } }, ""],

"@tsconfig/bun": ["@tsconfig/bun@1.0.7", "", {}, ""],

Expand Down Expand Up @@ -104,8 +104,6 @@

"cors": ["cors@2.8.5", "", { "dependencies": { "object-assign": "^4", "vary": "^1" } }, ""],

"cross-spawn": ["cross-spawn@7.0.6", "", { "dependencies": { "path-key": "^3.1.0", "shebang-command": "^2.0.0", "which": "^2.0.1" } }, "sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA=="],

"debug": ["debug@4.4.0", "", { "dependencies": { "ms": "^2.1.3" } }, ""],

"define-data-property": ["define-data-property@1.1.4", "", { "dependencies": { "es-define-property": "^1.0.0", "es-errors": "^1.3.0", "gopd": "^1.0.1" } }, ""],
Expand Down Expand Up @@ -204,8 +202,6 @@

"isarray": ["isarray@1.0.0", "", {}, ""],

"isexe": ["isexe@2.0.0", "", {}, "sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw=="],

"jmespath": ["jmespath@0.16.0", "", {}, ""],

"jose": ["jose@5.2.3", "", {}, ""],
Expand All @@ -222,9 +218,9 @@

"merge-descriptors": ["merge-descriptors@2.0.0", "", {}, ""],

"mime-db": ["mime-db@1.54.0", "", {}, ""],
"mime-db": ["mime-db@1.52.0", "", {}, "sha512-sPU4uV7dYlvtWJxwwxHD0PuihVNiE7TyAbQ5SWxDCB9mUYvOgroQOwYQQOKPJ8CIbE+1ETVlOoK1UC2nU3gYvg=="],

"mime-types": ["mime-types@3.0.1", "", { "dependencies": { "mime-db": "^1.54.0" } }, ""],
"mime-types": ["mime-types@2.1.35", "", { "dependencies": { "mime-db": "1.52.0" } }, "sha512-ZDY+bPm5zTTF+YpCrAU9nK0UgICYPT0QtT1NZWFv4s++TNkcgVaT0g6+4R2uI4MjQjzysHB1zxuWL50hzaeXiw=="],

"ms": ["ms@2.1.3", "", {}, ""],

Expand Down Expand Up @@ -254,11 +250,9 @@

"parseurl": ["parseurl@1.3.3", "", {}, ""],

"path-key": ["path-key@3.1.1", "", {}, "sha512-ojmeN0qd+y0jszEtoY48r0Peq5dwMEkIlCOu6Q5f41lfkswXuKtYrhgoTpLnyIcHm24Uhqx+5Tqm2InSwLhE6Q=="],

"path-to-regexp": ["path-to-regexp@8.2.0", "", {}, ""],

"pkce-challenge": ["pkce-challenge@5.0.0", "", {}, "sha512-ueGLflrrnvwB3xuo/uGob5pd5FN7l0MsLf0Z87o/UQmRtwjvfylfc9MurIxRAWywCYTgrvpXBcqjV4OfCYGCIQ=="],
"pkce-challenge": ["pkce-challenge@4.1.0", "", {}, ""],

"possible-typed-array-names": ["possible-typed-array-names@1.1.0", "", {}, ""],

Expand Down Expand Up @@ -298,10 +292,6 @@

"setprototypeof": ["setprototypeof@1.2.0", "", {}, ""],

"shebang-command": ["shebang-command@2.0.0", "", { "dependencies": { "shebang-regex": "^3.0.0" } }, "sha512-kHxr2zZpYtdmrN1qDjrrX/Z1rR1kG8Dx+gkpK1G4eXmvXswmcE1hTWBWYUzlraYw1/yZp6YuDY77YtvbN0dmDA=="],

"shebang-regex": ["shebang-regex@3.0.0", "", {}, "sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A=="],

"side-channel": ["side-channel@1.1.0", "", { "dependencies": { "es-errors": "^1.3.0", "object-inspect": "^1.13.3", "side-channel-list": "^1.0.0", "side-channel-map": "^1.0.1", "side-channel-weakmap": "^1.0.2" } }, ""],

"side-channel-list": ["side-channel-list@1.0.0", "", { "dependencies": { "es-errors": "^1.3.0", "object-inspect": "^1.13.3" } }, ""],
Expand Down Expand Up @@ -346,8 +336,6 @@

"whatwg-url": ["whatwg-url@5.0.0", "", { "dependencies": { "tr46": "~0.0.3", "webidl-conversions": "^3.0.0" } }, "sha512-saE57nupxk6v3HY35+jzBwYa0rKSy0XR8JSxZPwgLr7ys0IBzhGviA1/TUGJLmSVqs8pb9AnvICXEuOHLprYTw=="],

"which": ["which@2.0.2", "", { "dependencies": { "isexe": "^2.0.0" }, "bin": { "node-which": "./bin/node-which" } }, "sha512-BLI3Tl1TW3Pvl70l3yq3Y64i+awpwXqsGBYWkkqMtnbXgrMD+yj7rhW0kuEDxzJaYXGjEW5ogapKNMEKNMjibA=="],

"which-typed-array": ["which-typed-array@1.1.19", "", { "dependencies": { "available-typed-arrays": "^1.0.7", "call-bind": "^1.0.8", "call-bound": "^1.0.4", "for-each": "^0.3.5", "get-proto": "^1.0.1", "gopd": "^1.2.0", "has-tostringtag": "^1.0.2" } }, ""],

"wrappy": ["wrappy@1.0.2", "", {}, ""],
Expand All @@ -362,24 +350,32 @@

"zod-to-json-schema": ["zod-to-json-schema@3.24.3", "", { "peerDependencies": { "zod": "^3.24.1" } }, ""],

"accepts/mime-types": ["mime-types@3.0.1", "", { "dependencies": { "mime-db": "^1.54.0" } }, ""],

"aws-sdk/uuid": ["uuid@8.0.0", "", { "bin": "dist/bin/uuid" }, ""],

"cloudflare/@types/node": ["@types/node@18.19.86", "", { "dependencies": { "undici-types": "~5.26.4" } }, "sha512-fifKayi175wLyKyc5qUfyENhQ1dCNI1UNjp653d8kuYcPQN5JhX3dGuP/XmvPTg/xRBn1VTLpbmi+H/Mr7tLfQ=="],

"content-disposition/safe-buffer": ["safe-buffer@5.2.1", "", {}, ""],

"form-data/mime-types": ["mime-types@2.1.35", "", { "dependencies": { "mime-db": "1.52.0" } }, "sha512-ZDY+bPm5zTTF+YpCrAU9nK0UgICYPT0QtT1NZWFv4s++TNkcgVaT0g6+4R2uI4MjQjzysHB1zxuWL50hzaeXiw=="],

"opencontrol/@modelcontextprotocol/sdk": ["@modelcontextprotocol/sdk@1.6.1", "", { "dependencies": { "content-type": "^1.0.5", "cors": "^2.8.5", "eventsource": "^3.0.2", "express": "^5.0.1", "express-rate-limit": "^7.5.0", "pkce-challenge": "^4.1.0", "raw-body": "^3.0.0", "zod": "^3.23.8", "zod-to-json-schema": "^3.24.1" } }, ""],
"express/mime-types": ["mime-types@3.0.1", "", { "dependencies": { "mime-db": "^1.54.0" } }, ""],

"opencontrol/hono": ["hono@4.7.4", "", {}, ""],

"openid-client/jose": ["jose@4.15.9", "", {}, ""],

"send/mime-types": ["mime-types@3.0.1", "", { "dependencies": { "mime-db": "^1.54.0" } }, ""],

"type-is/mime-types": ["mime-types@3.0.1", "", { "dependencies": { "mime-db": "^1.54.0" } }, ""],

"accepts/mime-types/mime-db": ["mime-db@1.54.0", "", {}, ""],

"cloudflare/@types/node/undici-types": ["undici-types@5.26.5", "", {}, "sha512-JlCMO+ehdEIKqlFxk6IfVoAUVmgz7cU7zD/h9XZ0qzeosSHmUJVOzSQvvYSYWXkFXC+IfLKSIffhv0sVZup6pA=="],

"form-data/mime-types/mime-db": ["mime-db@1.52.0", "", {}, "sha512-sPU4uV7dYlvtWJxwwxHD0PuihVNiE7TyAbQ5SWxDCB9mUYvOgroQOwYQQOKPJ8CIbE+1ETVlOoK1UC2nU3gYvg=="],
"express/mime-types/mime-db": ["mime-db@1.54.0", "", {}, ""],

"send/mime-types/mime-db": ["mime-db@1.54.0", "", {}, ""],

"opencontrol/@modelcontextprotocol/sdk/pkce-challenge": ["pkce-challenge@4.1.0", "", {}, ""],
"type-is/mime-types/mime-db": ["mime-db@1.54.0", "", {}, ""],
}
}
48 changes: 28 additions & 20 deletions docs/hono-mcp-server.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,11 @@ This document serves as the single source of truth for setting up, developing, a
```
/mcp/
routes.ts # Route definitions: health, SSE, JSON-RPC
mcp.ts # MCP server wrapper, tool registry, helpers
server.ts # Custom MCP server implementation
service.ts # MCP service wrapper
streamableHttp.ts # Custom StreamableHTTP transport
types.ts # Type definitions for MCP
/tools/ # Tool definitions and registry
sse.ts # Custom SSETransport bridging MCP <-> browser EventSource
registry.ts # In-memory tool registry abstraction
```

Expand Down Expand Up @@ -41,12 +43,18 @@ router.post('/messages', messagesHandler)

```ts
import { Hono } from 'hono';
import { SSETransport } from './sse';
import { mcpService } from './mcp';
import { StreamableHTTPServerTransport } from './mcp/streamableHttp';
import { mcpService } from './mcp/service';

const app = new Hono();

app.get('/sse', (c) => SSETransport.handle(c));
app.get('/sse', (c) => {
const transport = new StreamableHTTPServerTransport({
sessionIdGenerator: () => crypto.randomUUID(),
});
return mcpService.getServerInstance().connect(transport);
});

app.post('/messages', (c) => mcpService.handleMessage(c));

mcpService.init();
Expand All @@ -58,12 +66,12 @@ mcpService.init();

- Install dependencies:
```sh
npm install hono @hono/node-server @modelcontextprotocol/sdk zod
npm install hono zod
```
- Implement `SSETransport` (see [SSE docs](https://developer.mozilla.org/en-US/docs/Web/API/Server-sent_events))
- Build an `MCPService` thin wrapper around the SDK server:
- Implement custom MCP server and transport (see our implementation in `/mcp/`)
- Build an `MCPService` thin wrapper around the custom server:
```ts
import { Server } from '@modelcontextprotocol/sdk/server';
import { Server } from './mcp/server';
const server = new Server({ name: 'My MCP' }, { capabilities: { tools: {} } });
server.setRequestHandler(CallToolRequestSchema, ...);
```
Expand All @@ -83,7 +91,7 @@ mcpService.init();

## 4. Local Dev / Debugging Tips

- Use [@modelcontextprotocol/inspector](https://www.npmjs.com/package/@modelcontextprotocol/inspector) proxy at `http://localhost:4200/sse` to inspect traffic
- Use a tool like Postman or curl to test your SSE endpoint
- Hono's dev server reloads if you pair with `tsx watch` or similar
- Add `?sessionId=...` query param logging for easier correlation in logs
- Use descriptive logging for SSE events and tool invocations
Expand All @@ -94,27 +102,27 @@ mcpService.init();

- [Hono Documentation](https://hono.dev)
- [Model Context Protocol Spec](https://github.com/modelcontext/protocol)
- [MCP SDK Server Package](https://github.com/modelcontext/sdk/tree/main/packages/server)
- [openapi2mcptools](https://www.npmjs.com/package/openapi2mcptools)
- [Inspector CLI](https://www.npmjs.com/package/@modelcontextprotocol/inspector)
- [Cloudflare Workers MCP](https://github.com/cloudflare/workers-mcp)
- [Cloudflare MCP Blog Post](https://blog.cloudflare.com/model-context-protocol/)

---

## Example: Minimal Hono MCP Server

```ts
import { Hono } from 'hono';
import { Server } from '@modelcontextprotocol/sdk/server';
import { SSETransport } from './sse';
import { Server } from './mcp/server';
import { StreamableHTTPServerTransport } from './mcp/streamableHttp';

const app = new Hono();
const mcpServer = new Server({ name: 'Example MCP' }, { capabilities: { tools: {} } });

app.get('/health', (c) => c.json({ status: 'ok', env: process.env.NODE_ENV }));
app.get('/sse', (c) => SSETransport.handle(c, mcpServer));
app.post('/messages', async (c) => {
const payload = await c.req.json();
return mcpServer.handleMessage(payload);
app.post('/mcp', async (c) => {
const transport = new StreamableHTTPServerTransport({
sessionIdGenerator: () => crypto.randomUUID(),
});
return mcpServer.connect(transport);
});

export default app;
Expand All @@ -131,4 +139,4 @@ export default app;

---

_Last updated: 2025-04-27_
_Last updated: 2025-04-29_
11 changes: 7 additions & 4 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,22 +5,25 @@
"private": true,
"scripts": {
"start": "bun run --watch src/api.ts",
"dev": "sst dev",
"dev": "bunx wrangler deploy && sst dev --stage lambdacurry2",
"build": "sst build",
"deploy": "sst deploy"
"deploy:sst": "sst deploy --stage lambdacurry2",
"deploy:do": "bunx wrangler deploy",
"deploy": "bun run deploy:sst && bun run deploy:do"
},
"devDependencies": {
"@biomejs/biome": "^1.9.4",
"@cloudflare/workers-types": "^4.20250424.0",
"@types/bun": "latest",
"@types/node": "^22.14.0",
"@types/uuid": "^9.0.8"
"@types/uuid": "^9.0.8",
"typescript": "^5.8.3",
"wrangler": "^3.0.0"
},
"peerDependencies": {
"typescript": "^5.8.3"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.10.2",
"cloudflare": "^4.2.0",
"hono": "^4.7.7",
"jszip": "^3.10.1",
Expand Down
26 changes: 21 additions & 5 deletions src/api.ts
Original file line number Diff line number Diff line change
Expand Up @@ -47,21 +47,37 @@ app.use(
// API Key Validation Middleware
// Apply this *before* mounting routes that need protection
// Or apply within specific route modules if needed granularly
app.use('*', async (c, next) => {
// Skip API key check for base routes (/, /health) and the MCP route (/mcp)
// Use startsWith to cover all sub-paths under /mcp if necessary, but exact match is likely sufficient here.
const publicPaths = ['/', '/health', '/mcp'];
if (publicPaths.some((p) => c.req.path === p)) {
app.use('*' /* Applies to all paths */, async (c, next) => {
// Check if the request path starts with any of the public prefixes
const publicPrefixes = ['/', '/health', '/mcp/']; // Include base, health, and the MCP prefix

// Special case for exact match on root path '/'
if (c.req.path === '/') {
await next();
return;
}

// Check prefixes for other paths (ensure trailing slash on prefixes if needed)
const isPublicPath = publicPrefixes.some((prefix) => {
// Avoid matching just '/' prefix for non-root paths unless intended
if (prefix === '/' && c.req.path !== '/') return false;
return c.req.path.startsWith(prefix);
});

if (isPublicPath) {
await next();
return;
}

// If not a public path, proceed with API key validation
const apiKey = c.req.header('x-api-key') || c.req.query('api_key');

if (!apiKey || apiKey !== Resource.API_KEY.value) {
console.warn(`[Auth] Invalid API key attempt for path: ${c.req.path}`);
return c.json({ error: 'Invalid or missing API key' }, 401);
}

console.log(`[Auth] API key validated for path: ${c.req.path}`);
await next();
});

Expand Down
Loading