Integrity MCP Server
com.bluecat/integritymcpv26.1.0
BlueCat Integrity MCP Server (formerly bammcp)
context tax
queued
security
queued
cold start
queued
freshness
Active15d ago
Install Integrity MCP server
No published package or hosted endpoint yet — see the project homepage for build-from-source instructions.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| BAM_BASE_URL | yes | — | BAM base URL (e.g., https://bam.bluecat.com). |
| BAM_USERNAME | — | — | BAM service-account username. Required unless the SSO pair (BAM_SSO_USERNAME + BAM_SSO_PASSWORD) is used instead — the server needs exactly one of the two pairs. |
| BAM_PASSWORD | — | yes | BAM service-account password. Required alongside BAM_USERNAME, unless the SSO pair is used instead. |
| BAM_SSO_USERNAME | — | — | BAM SSO username. Alternative to BAM_USERNAME + BAM_PASSWORD; the server needs exactly one of the two pairs. |
| BAM_SSO_PASSWORD | — | yes | BAM SSO password. Required alongside BAM_SSO_USERNAME when using the SSO pair. |
| MCP_AUTH_MODE | yes | — | Client authentication mode for the /mcp endpoint. One of: none | static-key | signed-key | resource-server. Required at runtime — the server refuses to start without it (no default). |
| MCP_API_KEY | — | yes | Static bearer token clients present as `Authorization: Bearer <key>`. Required only when MCP_AUTH_MODE=static-key. |
| MCP_REQUEST_STATE_KEY | — | yes | HMAC key (at least 32 bytes) sealing the approval-gated write tools' requestState on MCP 2026-07-28 connections (#1031). Optional: unset uses a random per-process key, which is fine for a single replica; set the same value on every replica of a multi-replica deployment. |
| MCP_REQUEST_STATE_KEY_PREVIOUS | — | yes | Second requestState HMAC key, accepted for opening a sealed plan but never for sealing one: two-key rotation of MCP_REQUEST_STATE_KEY (#1032). Optional, and only valid together with MCP_REQUEST_STATE_KEY. When rolling the key across replicas set this to the old key, and remove it two minutes after the last replica restarted. |
| MCP_ED25519_PUBLIC_KEY | — | — | Ed25519 public key (base64url) that MCP_AUTH_MODE=signed-key verifies license tokens against. DEFAULTS TO A SHARED DEMO KEY, which authenticates a token holder rather than a customer — every BlueCat-issued token for this server verifies against it. For anything beyond a trial, generate a per-deployment key pair (license-keygen --gen-key) and set this to its public half. |
| MCP_SIGNED_KEY_AUDIENCE | — | — | When set, a license token must carry exactly this audience or it is rejected — a declarative scope check on top of the key, so a token minted for another deployment fails even if it verifies. Unset means the aud claim is not checked. Only meaningful with MCP_AUTH_MODE=signed-key. |
| MCP_OAUTH_ISSUER | — | — | Token issuer URL, matched against the iss claim of incoming JWTs. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it. |
| MCP_OAUTH_JWKS_URI | — | — | JWKS endpoint whose public keys verify the signature on every incoming Bearer JWT. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it. |
| MCP_OAUTH_AUDIENCE | — | — | Expected JWT aud claim for MCP_AUTH_MODE=resource-server. A token carrying a different audience, or no aud claim at all, is rejected. Unset skips audience validation entirely. |
| ACCEPT_EULA | yes | — | Set to Y (or Yes/YES, any casing) to accept the BlueCat End User License Agreement. The container refuses to start without it. |
Freshness
Active — last maintenance signal 15d ago. The newest of the signals below sets the band.
Last commit (default branch)
no data · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-09-24 · 15d ago · official registry · v26.1.0
FAQ
›Does Integrity require an API key?
Yes. It expects BAM_BASE_URL, MCP_AUTH_MODE, ACCEPT_EULA, BAM_PASSWORD, BAM_SSO_PASSWORD, MCP_API_KEY, MCP_REQUEST_STATE_KEY, MCP_REQUEST_STATE_KEY_PREVIOUS, of which 5 are secrets.
›Can I use Integrity as a remote (hosted) MCP server?
Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.
›Is Integrity in the official MCP registry?
Yes, as com.bluecat/integritymcp.