Skip to content

Releases: ForITLLC/mcp-gateway

ForIT MCP Gateway v0.1.1 — local client configuration

Choose a tag to compare

@BTForIT BTForIT released this 10 Sep 19:25

Keep real client settings outside the public source tree, under ~/.config/forit-mcp-gateway/clients/ or in a dedicated private deployment repository.

  • Exclude client configuration folders, local environment files, and credential files from Git, Docker contexts, and package builds.
  • Explicitly enumerate source-release contents.
  • Reject tracked deployment folders and unreviewed configuration files in CI, including force-added files.
  • Document one local directory, one JSON file per client/environment, environment-based secrets, and read-only container mounts.

The public repository and earlier v0.1.0 packages contain no client deployment configuration. The only public API configuration is the fictional catalog example. Public history and file scans found no secrets. Packaging checks verified that injected dummy private files are omitted from both the wheel and source archive, and the tracked-file check rejects force-added client configuration.

ForIT MCP Gateway v0.1.0

Choose a tag to compare

@BTForIT BTForIT released this 10 Sep 19:17

First public release of ForIT MCP Gateway, independently maintained by ForIT LLC and built on FastMCP 3.2.3.

  • Namespaced OpenAPI 3 tools with read-only defaults and explicit operation allowlists.
  • Service bearer authentication and Microsoft Entra OAuth integration.
  • ForIT branding on consent and OAuth error pages, with custom logo support.
  • ETag/content-hash schema refresh with last-working-schema retention.
  • Fixed upstream credential headers, origin/base-path confinement, and disabled redirects.
  • A fictional local catalog demo, non-root Dockerfile, and setup/security documentation.

Licensed under Apache-2.0 with FastMCP attribution. This repository starts with a clean public history; private integrations and deployment data are not included.

Validation: 11 tests pass on Python 3.11, 3.12, and 3.13; container build and CLI check pass in GitHub Actions. A fresh wheel installation and authenticated HTTP demo were also verified. Gitleaks found no leaks in the exported files or public Git history.

Initial scope: all authenticated clients share a deployment's upstream identity and selected operations. Use separate deployments and scoped credentials for separate trust boundaries. Entra requires tenant-side configuration; automated checks cover registration/consent/error-page rendering, not a live tenant sign-in. See README for details.