@mcpfn/datafn
v0.1.4
Published
Explicit, deny-by-default DataFn resource exposure for McpFn
Readme
McpFn DataFn Adapter
@mcpfn/datafn turns explicitly approved DataFn operations into stable MCP tools. It is deny-by-default:
- no resource is exposed unless named in
expose; - every read uses a fixed output projection;
- filters and sort fields are allowlisted;
- writes require explicit writable fields and a caller-supplied idempotency key;
- principal and namespace context comes from the server, never tool arguments;
- all calls execute through
DatafnExecutor, preserving DataFn validation, permissions, hooks, authorization, namespace isolation, rate limits, and idempotency.
import { createMcpFnServer } from "@mcpfn/core";
import { createDatafnMcpRegistry } from "@mcpfn/datafn";
const registry = createDatafnMcpRegistry({
schema,
executor: datafnServer.executor,
context: (mcpContext) => ({
workspaceId: mcpContext.workspaceId,
actorId: mcpContext.actorId,
}),
clientId: (mcpContext) => `mcp:${mcpContext.credentialId}`,
expose: {
skills: {
fields: ["id", "slug", "name", "updatedAt"],
list: {
filterFields: ["slug", "name"],
sortFields: ["updatedAt", "id"],
maxLimit: 50,
},
get: true,
},
},
});
const server = createMcpFnServer({
info: { name: "skills-data", version: "1.0.0" },
registry,
context: async (extra) => authenticateMcpRequest(extra.requestInfo),
transports: ["stdio", "streamable-http"],
});This adapter is appropriate for bounded data operations. Domain workflows with additional authorization, auditing, asset grants, or version-resolution semantics should remain explicit McpFn tools.
Exposure reference
fieldsis the fixed list/get projection and must be non-empty, unique, and allowed by DataFn read policy.listandgetdefault to enabled after the resource itself is explicitly present inexpose; passfalseto disable either one.list.filterFieldsdefaults tofields;sortFieldsdefaults toid;defaultLimitdefaults to50;maxLimitdefaults to100.create,update, anddeletedefault off. Create/update require a writablefieldsallowlist. All writes requiremutationIdand use the trustedclientIdresolver.- Default names are
datafn_<resource>_<operation>;toolPrefix, per-operationname, and descriptions can be overridden.
Adapter construction fails before serving if a resource or field is unknown, unreadable, read-only, or not writable under the resolved DataFn capabilities.
