Local multi-account MCP broker β one endpoint, every account. Switch identity without reconnecting.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
One credential broker. Every account. From the CLI or MCP. Multi-account tool access for AI agents, with credentials kept local.
One-click buttons require the npm package to be published. See RELEASING.md.
If you work with more than one company, you use the same MCP server (Supabase, GitHub, Slackβ¦) with different identities β a different account, email and token per client. Today most LLM clients hold one account at a time per connector: to switch client you disconnect, reconnect, and redo the OAuth login. Every time.
The MCP protocol has no notion of "account": one session = one identity = one set of credentials. JanusMCP fills that gap.
JanusMCP is a local multi-account tool broker for AI agents. It can be used directly from the CLI or as an MCP server in front of the real upstream servers:
janusmcp tools / schema / call invoke tools on demand, with no bulk tool
definitions loaded upfront.You drive it with three control tools that appear in any client:
janus_list_accounts, janus_use_account, janus_whoami.
The CLI discovers schemas only when needed, accepts JSON through --args or stdin,
supports explicit accounts/profiles, and provides stable exit codes. See the
CLI guide and copyable agent instructions.
Both modes share the same config, OS-keychain vault, OAuth tokens and persisted active
account. Use janusmcp daemon start to keep upstream sessions warm across repeated CLI calls.
Once released, install via your favorite channel (all published automatically on each tag β see RELEASING.md):
β¦or download a prebuilt binary from Releases.
Two Supabase clients, PATs kept in your OS keychain (never in the config):
Add it to Claude Desktop:
For ChatGPT / Gemini / Cursor / Copilot, run HTTP and point them at the URL:
Run janusmcp help for the full reference. The essentials:
| Command | What it does |
|---|---|
janusmcp serve | Run the broker (default). Transports via env: JANUS_TRANSPORT=stdio|http|both, JANUS_HTTP_HOST, JANUS_HTTP_PORT. |
janusmcp tools [selector] | Compact tool list for the active (or given) account/profile. --json for full definitions; optional --timeout. |
janusmcp schema <tool> | Full JSON definition of one tool. --account <id|profile> disambiguates; optional --timeout. |
janusmcp call <tool> | Invoke a tool. Supports --account, --args, stdin, stable --json, and optional --timeout. |
janusmcp use <account|profile> | Persist the active selector for future CLI commands and new MCP sessions. |
janusmcp daemon start|stop|restart|status | Manage the optional loopback-only daemon that reuses upstream sessions. |
janusmcp ui | Open the local control panel β add accounts, log in, set secrets. |
janusmcp add <template> [id] | Add an account from a template (janusmcp catalog lists them). |
janusmcp catalog | List the built-in account templates. |
janusmcp connect <id> | Connect an account; for remote OAuth, opens the browser. |
janusmcp status | Show each account's login/secret status (no secret values). |
janusmcp vault set <name> / delete <name> | Store / remove a secret in the OS keychain. |
janusmcp login <provider> <name> | OAuth loopback login; token referenced as oauth:<name>. |
janusmcp providers | List built-in OAuth providers. |
janusmcp install <client> | Configure an LLM client to launch JanusMCP. |
janusmcp uninstall <client> | Remove JanusMCP from an LLM client's config. |
janusmcp version Β· janusmcp help | Version Β· this reference. |
Supported <client> values for install / uninstall: claude-desktop, claude-code,
cursor, vscode, gemini, codex, chatgpt, print. Run janusmcp install list
(or uninstall list) to see each target and whether it's already configured.
Inside any connected client you also get the control tools janus_list_accounts,
janus_use_account, janus_whoami, janus_login, janus_use_profile, and
janus_with_account.
A profile groups accounts of the same client across different services. Activating it exposes the tools of all its accounts together, and each call is routed to the right upstream:
Then in chat: janus_use_profile with { "profile": "client_a" } β Supabase and
GitHub tools for Client A are available simultaneously. Colliding tool names across
accounts are namespaced (<account>_<tool>).
janus_with_account runs a single call on another account without changing the
active one β e.g. { "account_id": "client_b", "tool": "list_tables" }. Omit tool
to list that account's available tools first.
Loading every MCP tool definition into an LLM context is expensive. In code-execution mode an agent (or you) invokes tools on demand from the shell instead β Γ la "code execution with MCP" β so the context holds only the results it actually asked for:
call prints the tool's text content to stdout and exits non-zero on a tool error, so
it composes with pipes and scripts. Selectors resolve exactly like in the broker: the
persisted active account by default, or any account id / profile name; a name that
collides across a profile's accounts must be disambiguated with --account. Secrets
resolve through the same vault/OAuth stack as serve β nothing extra to configure.
This makes JanusMCP a first-class citizen for CLI-driven agents (Claude Code,
Codex, Cursor agents, or any agent with shell access): instead of registering it as
an MCP server, just tell the agent that janusmcp tools / schema / call exist.
Discovery, schemas and invocation happen on demand, credentials stay in the keychain,
and multi-account switching works the same as over MCP. Both modes share the config
and the persisted active account, so you can mix them freely.
For repeated calls, janusmcp daemon start launches an authenticated loopback-only
broker. tools, schema, and call auto-detect it and reuse its upstream sessions;
--direct bypasses it and --daemon requires it. Set JANUS_DAEMON=auto|require|off
to choose a default policy.
| Multi-account, one endpoint | N identities for the same service, no reconnecting |
| Identity scoping | per-call β per-session (Mcp-Session-Id) β global, via bindingMode: global | session | locked |
| Dual transport | stdio (local-first clients) + Streamable HTTP (remote-first clients), same process |
| Secure vault | OS keychain (macOS/Windows/Linux) + encrypted-file fallback; secrets as vault:<name> |
| OAuth loopback | janusmcp login (PKCE), tokens stored in the vault, auto-refresh, oauth:<name> |
| Context-safe | only the active account's tools are exposed; switching emits tools/list_changed |
| MCP and CLI | same broker as an MCP server or via janusmcp tools / schema / call β no bulk tool definitions loaded upfront |
The MCP gateway space (MetaMCP, mcp-proxy, IBM ContextForge, β¦) aggregates different servers behind one endpoint. JanusMCP solves the orthogonal, under-served problem: many identities for the same service, without saturating the model's context, from any LLM, fully local. It's a credential-aware broker, not a flat aggregator.
Scaffold an account from a ready-made template with janusmcp add <template> (run
janusmcp catalog for the full, up-to-date list). Most use browser OAuth (dynamic client
registration); a few need extra setup, noted below.
supabase, github, notion, sentry, stripe,
hubspot, paypal, linear, vercel, canva, neon, netlify, zapier.asana, monday, intercom, webflow, wix, square,
globalping.cloudflare-bindings, cloudflare-observability,
cloudflare-radar, cloudflare-builds, cloudflare-browser.gmail, google-drive,
google-calendar, google-chat β see go/docs/google-workspace.md.activecampaign (paste your Remote MCP URL).figma-desktop (local, recommended) and figma (remote, restricted β see below).http-oauth, sse-oauth, supabase-pat, stdio.Missing one? Add any remote server with http-oauth / sse-oauth, any local one with
stdio, or define your own template in ~/.config/janusmcp/templates.json.
ActiveCampaign ships an official remote MCP server with a unique URL per account (ActiveCampaign β Settings β Developer β Remote MCP URL) and browser-based OAuth β a natural fit for the multi-account broker. Add one account per client:
Because the URL is per-account, the template seeds a REPLACE_ACTIVECAMPAIGN_MCP_URL
placeholder you must replace with your own URL. Login uses dynamic client registration, so
no client ID/secret is needed.
Google offers remote MCP servers for Gmail, Drive, Calendar and Chat, but β unlike most
providers here β they require your own OAuth client (created in the Google Cloud
Console); they don't support dynamic client registration. JanusMCP supports this via the
oauthClientId / oauthClientSecret / scopes fields, preset by the gmail,
google-drive, google-calendar and google-chat templates:
Full one-time Google Cloud setup (enable MCP APIs, consent screen, Desktop OAuth client)
and scope details are in go/docs/google-workspace.md.
Figma offers two MCP servers, handled differently here:
Local Dev Mode server (recommended). Figma's desktop app hosts an MCP server on
http://127.0.0.1:3845/mcp. It's local, needs no OAuth, and works out of the box:
enable it in the desktop app (Dev Mode β Inspect β Enable desktop MCP server) and add it
with janusmcp add figma-desktop figma_work. Requires a Dev/Full seat on a paid Figma plan.
Remote server (https://mcp.figma.com/mcp) β restricted. Figma allowlists the OAuth
client_name during dynamic client registration and returns 403 Forbidden to any client
that isn't in its MCP catalog (VS Code, Cursor, Claude
Code, β¦). JanusMCP is not (yet) an approved client.
β οΈ Workaround β opt-in, use at your own risk. You can make JanusMCP register under an approved name by setting
"clientName": "Claude Code"on a remotefigmaaccount in yourconfig.json. This impersonates an approved client and may violate Figma's Terms of Service; it can also break whenever Figma updates its allowlist. It is not enabled by default. Prefer the local Dev Mode server above for real work.
The proper long-term fix is for JanusMCP to be submitted to and approved for Figma's MCP
catalog, so no client_name override is needed. This is planned.
Alpha β the core is implemented and tested in Go.
janusmcp install β¦), Claude Desktop .mcpb, registry server.jsonwith_account one-shot cross-account callsjanusmcp tools / schema / call) β invoke tools on
demand instead of loading all definitions, to cut token usagejanusmcp catalog / addSee design-broker-mcp-multi-account.md for the full design.
go/ β the broker (Go). This is the real implementation. Build & docs βspike/ β the original TypeScript spike, kept as a verified reference of behavior.design-broker-mcp-multi-account.md β architecture & rationale.docs/ β current architecture, compatibility contract, testing, ADRs, and operations.JanusMCP runs entirely on your machine. It has no backend servers, collects no data, and
contains no analytics or telemetry β the developers receive nothing about you or your usage.
Credentials and tokens are stored in your OS keychain (or, if you opt in, an encrypted local
file) and are used only to authenticate to the services you configure; they never pass through
the model context. Network connections are made only to the MCP servers and OAuth providers you
configure. Because everything is local, data is retained only on your own device for as long as
you keep it, and removing it (janusmcp vault delete <name>, or uninstalling) removes it
entirely.
Full policy: https://janusmcp.dev/privacy.
Contributions are very welcome β see CONTRIBUTING.md. New connector presets, client integration guides, and packaging help are especially appreciated.
MIT β see LICENSE.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/janusmcp)<a href="https://allmcps.com/mcp/janusmcp"><img src="https://allmcps.com/api/badge/janusmcp?style=directory" alt="Janusmcp on AllMCPs" /></a>