MCP Client Onboarder

Onboard, scope, and revoke clients for the central MCP multiplexer. Creates a Keycloak client_credentials identity, generates an Eunomia authorization policy from a profile template (full-access / read-only / server-scoped / role-based), merges it into the multiplexer's zero-trust policy, and supports ephemeral (TTL) clients with an automatic reaper. Use when the user says "onboard an MCP client", "give an agent access to the multiplexer", "scope a client to servers X,Y", "create a read-only MCP client", "revoke/expire an MCP client", or "mcp access control". Do NOT use for remote per-service Eunomia policies (use eunomia-policy-manager) or general Keycloak SSO (use the Keycloak skill).

Knuckles-Team 3c3759e 11 files · 27.7 KB Updated

File contents

Knuckles-Team/universal-skills/tree/main/universal_skills/infrastructure/mcp-client-onboarder commit 3c3759ee6d

Frequently asked questions

npx skillmds@latest add knuckles-team/mcp-client-onboarder