npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mahesh2-lab/codemcp

v2.0.13

Published

Project-scoped MCP server providing context, file access, and execution tools for AI assistants and MCP clients

Readme

@mahesh2-lab/codemcp

The Project-Scoped Model Context Protocol Server for Local Codebases

npm version License: MIT Protocol

CodeMCP connects AI assistants (Claude, Cursor, Windsurf, etc.) to your local project codebase through authenticated Streamable HTTP with sandboxed tools, interactive terminal approvals, and cross-session memory.


Quick Start

Run directly inside any project folder using npx (no installation required):

# Start with a secure public HTTPS tunnel (for remote AI clients like Claude)
npx @mahesh2-lab/codemcp

# Or start for local-only access (for local AI clients like Cursor / Claude Desktop)
npx @mahesh2-lab/codemcp --no-tunnel

When started, CodeMCP will automatically:

  1. Detect or initialize project metadata (codemcp.json, .mcpignore, CONTEXT.md).
  2. Display your Local URL, Global URL (if tunneled), and a secure Owner Password.
  3. Listen for incoming MCP tool requests.

Global Installation

If you prefer to install CodeMCP globally:

npm install --global @mahesh2-lab/codemcp

Then run it from anywhere:

# In the current directory:
codemcp

# Or specify a target directory:
codemcp ./path/to/project --no-tunnel

Connecting to Your AI Client

1. Claude Desktop

Add CodeMCP to your claude_desktop_config.json:

{
  "mcpServers": {
    "my-project": {
      "command": "npx",
      "args": ["-y", "@mahesh2-lab/codemcp", "--no-tunnel", "/absolute/path/to/project"]
    }
  }
}

2. Claude Code, Cursor, Windsurf & Remote Clients

  1. Run CodeMCP in your terminal:
    codemcp
  2. Copy the Global URL (e.g., https://your-domain.ngrok-free.app/mcp) or Local URL (http://localhost:4173/mcp).
  3. Add it as an HTTP MCP Server in your client settings.
  4. When your client prompts for authentication, open the URL and enter the Owner Password displayed in the CodeMCP terminal.

Interactive Approvals

By default, CodeMCP protects your codebase by asking for confirmation in the terminal before making changes:

┌─ Action Approval Required ───────────────────────────────────────┐
│ Action    : WRITE                                                │
│ Target    : src/index.js                                         │
│ Summary   : Add error handling for API requests                  │
├──────────────────────────────────────────────────────────────────┤
--- old
+++ new
@@ -1,3 +1,5 @@
+try {
   fetchData();
+} catch (err) { console.error(err); }
└──────────────────────────────────────────────────────────────────┘

Approve this action?
 [y] Allow once      [a] Always allow for session
 [n] Reject          [d] View full diff       [q] Cancel

Approval Shortcuts

| Key | Action | | :---: | :--- | | y | Allow once: Approves this single operation. | | a | Always allow: Approves this operation and all future operations for the current session. | | n | Reject: Blocks the operation with a rejection message returned to the AI. | | d | View full diff: Expands the entire unified diff. | | q | Cancel: Aborts the operation immediately. |

To disable approval prompts completely:

codemcp --no-approval
# Or persist in configuration:
codemcp approval off

To require approval only for deletions and commands:

codemcp --approval destructive

Common CLI Commands & Options

Commands

| Command | Description | | :--- | :--- | | codemcp [path] | Start the MCP server for the given project (defaults to current directory). | | codemcp init [path] | Create or update codemcp.json, .mcpignore, and CONTEXT.md. | | codemcp info [path] | Display project permissions, status, and indexed file count. | | codemcp approval <on\|off> | Turn approval prompts on or off in codemcp.json. | | codemcp credentials status | Inspect stored encrypted credentials. | | codemcp credentials set <key> <val> | Store credentials securely (e.g. NGROK_API_KEY). |

Options

| Flag | Description | Default | | :--- | :--- | :--- | | -p, --port <number> | Port to listen on (auto-detects next free port if busy) | 4173 | | --no-tunnel | Run locally without creating an ngrok tunnel | Tunneled | | -a, --approval <mode> | Approval mode: true/always, destructive, or false/never | true | | --no-approval | Disable all confirmation prompts (auto-apply changes) | Prompting | | -y, --yes | Skip interactive setup prompts and accept defaults | Interactive | | -h, --help | Show CLI help | |


Configuration (codemcp.json)

CodeMCP reads codemcp.json in your project root:

{
  "id": "my-project",
  "name": "My Project",
  "description": "Project overview and guidelines for AI assistants.",
  "permission": "both",
  "approval": true,
  "contextFile": "CONTEXT.md"
}
  • permission: "both" (read & write), "read" (read-only), or "write".
  • approval: true (ask before changes), false (no prompt), or "destructive" (prompts only for deletes & shell commands).
  • contextFile: Markdown file injected into AI system instructions (defaults to CONTEXT.md).

Available Tools

When connected, AI assistants can use these project-scoped tools:

  • Read & Explore: list_files, find_file, read_file, search_code (fast ripgrep search)
  • Edit & Write: write_file, edit_file, delete_file
  • Execute: execute_command (runs allowlisted dev binaries like git, npm, node, pytest, cargo, etc.)
  • Context & Memory: get_project_context, record_memory, get_memory, finish

Links & Resources