MCP server for EVC Mesh: tasks, memory and coordination for human + AI agent teams
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Model Context Protocol (MCP) server for EVC Mesh β a task management platform for coordinating humans and AI agents.
Connects AI agents (Claude Code, Cursor, Cline, OpenClaw, etc.) to EVC Mesh via MCP tools for task management, persistent memory, event publishing, and multi-agent coordination.
This is the actively developed copy. evc-mesh also ships an MCP server (./cmd/mcp, same internal/mcp tool set) that it builds and deploys itself β the two exist because Go's internal/ visibility rules mean one repo can't import the other's package, not because they're meant to diverge. New tools and fixes land here first.
agk_...)Or build from source:
-i is required β the server speaks MCP over stdio, and Docker only wires up
stdin when the container runs interactively. Add -e MESH_MCP_PROFILE=core
to switch profiles (see Tool Profiles below). The image is
published for linux/amd64 and linux/arm64 from Dockerfile in this repo
on every tagged release (docs/RELEASING.md).
The MCP server supports two profiles to optimize context window usage:
| Profile | Tools | Context overhead | Best for |
|---|---|---|---|
| core | 25 | ~8K tokens (4% of 200K) | Claude Code, Cursor, small-context models |
| full | 63 | ~18K tokens (9% of 200K) | Power users, automation agents, admin ops |
Set via MESH_MCP_PROFILE environment variable. Default: full.
| Variable | Required | Default | Description |
|---|---|---|---|
MESH_API_URL | Yes | http://localhost:8005 | Base URL of the Mesh API |
MESH_AGENT_KEY | Yes (stdio) | β | Agent API key (agk_...) |
MESH_MCP_PROFILE | No | full | Tool profile for stdio: core or full (SSE serves both) |
MESH_MCP_TRANSPORT | No | stdio | Transport mode: stdio or sse |
MESH_MCP_HOST | No | 0.0.0.0 | SSE server bind host |
MESH_MCP_PORT | No | 8081 | SSE server bind port |
MESH_MCP_AUTH_FAIL_RPM | No | 20 | SSE mode: per-IP budget for authentication attempts against a not-yet-cached agent key on /sse, /core/sse, /mcp, /mcp/core. Over budget β 429 without calling Mesh API. 0 disables. |
MESH_MCP_SESSION_CACHE_TTL_MIN | No | 15 | SSE mode: how long a successful authentication is trusted before the key is re-checked β bounds how long a revoked key keeps working without a restart. |
MESH_MCP_AUTH_FAIL_CACHE_SEC | No | 30 | SSE mode: how long a failed authentication (bad/unknown key) is remembered, so repeating the same bad key doesn't call Mesh API every request. |
MESH_MCP_PUBLIC_URL | No | β | SSE mode: the URL the MCP root is reachable at from outside, e.g. https://mesh.example.com/mcp. Used for the absolute SSE endpoint and as the OAuth resource URL (see OAuth). Unset: derived from each request's host, which is only right when clients reach this server directly β behind a proxy set it, or the derived core URL (/core) will not match the public one (/mcp/core). |
MESH_MCP_OAUTH_ISSUER | No | origin of MESH_MCP_PUBLIC_URL | SSE mode: the OAuth authorization server named in the protected-resource metadata β your Mesh instance's public origin. Set it only if the MCP server is served from a different origin than the Mesh API. |
MESH_MCP_OAUTH_CACHE_TTL_SEC | No | 60 | SSE mode: how long a verified OAuth access token is trusted before Mesh API is asked again. Deliberately much shorter than the agent-key TTL so a revoked grant stops working within about a minute. |
MESH_MCP_DECIDER_USERNAME | No | β | Username recorded as decided_by when record_owner_decision answers a gated task. Unset: the workspace owner. |
MESH_MCP_LEGACY_TOOL_ALIASES | No | off | 1 also registers the tools' earlier names, for deployments whose callers still use them. Leave off for new installs. |
In stdio mode the server also starts when MESH_AGENT_KEY is not set. It then
answers initialize and tools/list as usual, and every tool call returns
instructions for setting MESH_API_URL and MESH_AGENT_KEY. This lets MCP
clients and catalogs inspect the tool list before you have a key. If a key is
set but authentication fails at startup (API unreachable, key rejected), the
server keeps running: tools are listed, and each call retries authentication
and returns the reason until it succeeds.
Every tool declares the MCP hints readOnlyHint, destructiveHint,
idempotentHint and openWorldHint, so clients can tell read-only tools
(get_*, list_*, recall, search_docs, β¦) from ones that change or
remove data (update_*, move_task, forget, β¦).
Each initialize is logged with the client's clientInfo.name and version,
and counted in the Prometheus metric mesh_mcp_initialize_total{client,profile}
(exposed on /metrics in SSE mode; client names are normalised and capped).
Add to your project's .mcp.json:
Add to Cursor MCP settings (Settings β MCP Servers):
For connecting multiple agents through a shared MCP endpoint:
SSE mode serves two profiles simultaneously on different paths:
| Path | Profile | Description |
|---|---|---|
/sse + /message | full | All 63 tools (backward compatible) |
/core/sse + /core/message | core | 25 essential tools |
The same process also serves the Streamable HTTP transport (stateless, one
agent key per request, sent in the Authorization: Bearer or X-Agent-Key
header β the query parameter is refused there):
| Path | Profile |
|---|---|
/mcp | full |
/core | core |
Authentication per connection via:
Authorization: Bearer agk_... headerX-Agent-Key: agk_... header?agent_key=agk_... query parameter (SSE connect only)Authorization: Bearer mot_... β an OAuth access token issued by your Mesh instance (see below); the header only, never the query string, and on the Streamable HTTP endpoints only (SSE connections need an agent key)Clients that sign users in with OAuth β remote-connector directories, MCP Inspector, editors that follow the MCP authorization spec β connect to the Streamable HTTP endpoints without a pre-shared key. Your Mesh instance is the authorization server (dynamic client registration, PKCE, user consent); this server is the resource server and does two things:
Challenges. A request with no credential, or with an OAuth access token
Mesh API rejects (expired, revoked, never issued), gets 401 and
which is where a client starts the authorization flow. A rejected agent key
keeps answering 403. Only a verdict from Mesh API (a 4xx other than
408/429) makes a token invalid: if Mesh API cannot be reached or answers
with an error that says nothing about the token (5xx, 429), the answer is
503 with Retry-After, so a valid token is not thrown away over an outage.
Serves the metadata (RFC 9728) at the well-known path derived from each endpoint's URL:
| Endpoint | Metadata |
|---|---|
https://mesh.example.com/mcp (full) | /.well-known/oauth-protected-resource/mcp |
https://mesh.example.com/mcp/core (core) | /.well-known/oauth-protected-resource/mcp/core |
resource is MESH_MCP_PUBLIC_URL (trailing slash, query and fragment
removed; /core appended for the core profile), so set it to the URL your
users paste into the client.
The authorization server defaults to that URL's origin; override it with
MESH_MCP_OAUTH_ISSUER.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/evc-mesh-mcp)<a href="https://allmcps.com/mcp/evc-mesh-mcp"><img src="https://allmcps.com/api/badge/evc-mesh-mcp?style=directory" alt="Evc Mesh MCP on AllMCPs" /></a>