@nordio/server-kit
v0.8.0
Published
The shared library every MCP server reuses — so no server hand-rolls plumbing (guideline hard rule 12).
Readme
@nordio/server-kit
The shared library every MCP server reuses — so no server hand-rolls plumbing (guideline hard rule 12).
What exists today
createMcpServer(opts)— build a client-agnostic server fromToolDef[](title, agent-written description, ZodinputSchema, annotations, handler with{ mock, log }context, error-to-isErrorwrapping, automatic per-call instrumentation with duration + redacted args), optionalResourceDef[](<domain>://referencemanuals — query syntax, field maps, examples) and optionalPromptDef[](registered canonical workflows, e.g.monthly_review)- Typed annotation vocabulary:
readOnlyLocal·readOnlyExternal·writeCreate·writeUpdate·writeDelete·writeIrreversible— semantics reasoned once, one-liner per tool runStdio(server)— stdio transport (local dev via.mcp.json,.mcpbpackaging)createHttpApp(makeServer)— Streamable HTTP via Express (remote/Vercel; stateless, fresh server+transport per request; add OAuth middleware in front ofPOST /mcpbefore production)createLogger()— structured JSON logging to stderr with redaction by key AND by value-shape (long opaque strings under innocent keys), and child loggersCache— volatility-aware caching ({ immutable }→ cache hard ·{ ttlMs }→ expire ·{}→ no-cache), hit/miss/entries metrics, injectable clock (ported from bankingMCP'sTtlCache)FileTokenStore— per-account AES-256-GCM encrypted token store under the state dir (§2c; key in a0600keyfile),get/set/delete/list, account names hashed;TokenStoreinterfacegeneratePkce·runLoopbackOAuth·exchangeCode·refreshTokens— OAuth 2.1 Authorization-Code + PKCE loopback for local tools (the gmail-cli/banking pattern, generalized)Ledger— append-only JSONL audit ledger (§2c):record/recent(forundo),seen(idempotent re-runs),hashPayload,redactForModel(LLM-safe reads) — the write-safety core
Planned (not yet implemented — don't reference these as available)
- Multi-tenant / remote auth — per-client consent + fail-closed OAuth middleware in front of
POST /mcp(the commercial / service-operation tier; the localoauth+FileTokenStoreabove cover the single-user default) - OS-keychain token store — Keychain/DPAPI/libsecret backing, stronger than the file+
0600baseline - Correlation ids end-to-end
- Entitlement checks (for the optional commercialization layer)
- Out-of-band approval for irreversible remote writes (the local
Ledger+--confirmcovers the CLI/local path) - Log forwarding to the client (
capabilities: {logging}+sendLoggingMessage) — port from bankingMCP
Distribution
Published to public npm as @nordio/server-kit on every factory tag (release.yml).
Consumers npm install @nordio/server-kit (no registry config) and depend on a version range —
Dependabot delivers updates as PRs. Vendoring into the project's own workspace remains an option
for fully self-contained scaffolds. Improvements flow back to the factory, not into forks.
