Metadata-Version: 2.5
Name: agent-mcp-mtls-util
Version: 1.0.0
Summary: SPIFFE/mTLS MCP client for Claude Desktop — no local agent needed
License: MIT
Keywords: claude,mcp,mtls,proxy,spiffe
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: Implementation :: PyPy
Classifier: Topic :: Internet :: Proxy Servers
Classifier: Topic :: Security :: Cryptography
Requires-Python: >=3.8
Requires-Dist: httpx>=0.27.0
Provides-Extra: dev
Requires-Dist: build; extra == 'dev'
Requires-Dist: hatchling; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: twine; extra == 'dev'
Provides-Extra: spiffe
Requires-Dist: pyspiffe>=0.4.0; extra == 'spiffe'
Description-Content-Type: text/markdown

# corporate-mcp-client

SPIFFE/mTLS MCP client for Claude Desktop.

Fetches short-lived X.509 certificates from your external Cert API —
no local SPIRE agent, no Python pre-installed, no cert files on disk.

## How it works

```
Claude Desktop (stdio)
    |
    v
corporate-mcp-client  (spawned by uvx)
    |
    |-- POST /attest -> your Cert API  (gets 1h X.509 cert)
    |-- builds mTLS SSLContext in memory
    |
    v
Your Nginx (validates SPIFFE ID cert)
    |
    v
MCP Gateway -> MCP Server (unmodified)
```

## claude_desktop_config.json

```json
{
  "mcpServers": {
    "corporate-mcp": {
      "command": "uvx",
      "args": ["corporate-mcp-client"],
      "env": {
        "CERT_API_URL":     "https://cert-api.yourcompany.com",
        "ENROLLMENT_TOKEN": "your-enrollment-token-here",
        "MCP_SERVER_URL":   "https://your-mcp-server.com/mcp"
      }
    }
  }
}
```

## Environment variables

| Variable           | Required | Description                                      |
|--------------------|----------|--------------------------------------------------|
| CERT_API_URL       | Yes      | Your Cert API base URL                           |
| ENROLLMENT_TOKEN   | Yes      | Pre-shared token issued per customer             |
| MCP_SERVER_URL     | Yes      | Your MCP server endpoint                         |
| CERT_API_CA        | No       | Path to CA bundle for Cert API (private CA)      |
| CERT_REFRESH_SECS  | No       | Cert refresh window in seconds (default: 3300)   |
| LOG_LEVEL          | No       | DEBUG / INFO / WARNING (default: INFO)           |

## Customer setup

```bash
# 1. Install uv (once)
curl -LsSf https://astral.sh/uv/install.sh | sh

# 2. Add config block to claude_desktop_config.json
# 3. Restart Claude Desktop
# Done — uvx handles everything else automatically
```
