Hosted multi-tenant mode: sign in, link your Coolify, no deploy needed (coolify.mctl.ai) #430
mashkovd
started this conversation in
Show and tell
Replies: 1 comment
|
Love this! Yeah get it into PR! Thank you |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Built on top of this project — thank you for the clean architecture, it made this straightforward to add without touching the core
CoolifyMcpServer/OAuthProvider.The gap I kept hitting: every install path here (npx, the Desktop extension, the remote container) still means someone deploys and operates a container next to their own Coolify. Great for an agency running one Coolify per client, less great if you just want to point claude.ai at your Coolify right now without standing up infrastructure first.
So I forked and added a multi-tenant hosted mode (
MCP_TENANCY=multi): sign in with GitHub or Google, link your Coolify's address + an API token on/enroll, addhttps://coolify.mctl.ai/mcpas a custom connector in claude.ai, done. No container, no OAuth app to register yourself.What's unchanged from upstream: the 45 tools, PKCE, the destructive-op elicitation guard (fails closed in HTTP mode, since claude.ai can't elicit), the audit log, the SSRF guard. What's new for multi-tenant: credentials live in Vault keyed by
(provider, provider's own id), re-validated and DNS-pinned on every call (not just at enrol, to close a rebind window), and revocation is a realdestroy, not a KVdeletetombstone.Live at https://coolify.mctl.ai if anyone wants to kick the tires. Fork: https://github.com/mctlhq/mctl-coolify-mcp, multi-tenant docs: docs/multi-tenant.md.
Happy to upstream the multi-tenant pieces as a PR if that's of interest — mentioning it here first rather than opening one unprompted.
All reactions