Skip to content
mcp/skillhub

Integrity MCP Server

com.bluecat/integritymcpv26.1.0

BlueCat Integrity MCP Server (formerly bammcp)

Dockerremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active15d ago

Install Integrity MCP server

No published package or hosted endpoint yet — see the project homepage for build-from-source instructions.

Configuration

VariableRequiredSecretDescription
BAM_BASE_URLyes—BAM base URL (e.g., https://bam.bluecat.com).
BAM_USERNAME——BAM service-account username. Required unless the SSO pair (BAM_SSO_USERNAME + BAM_SSO_PASSWORD) is used instead — the server needs exactly one of the two pairs.
BAM_PASSWORD—yesBAM service-account password. Required alongside BAM_USERNAME, unless the SSO pair is used instead.
BAM_SSO_USERNAME——BAM SSO username. Alternative to BAM_USERNAME + BAM_PASSWORD; the server needs exactly one of the two pairs.
BAM_SSO_PASSWORD—yesBAM SSO password. Required alongside BAM_SSO_USERNAME when using the SSO pair.
MCP_AUTH_MODEyes—Client authentication mode for the /mcp endpoint. One of: none | static-key | signed-key | resource-server. Required at runtime — the server refuses to start without it (no default).
MCP_API_KEY—yesStatic bearer token clients present as `Authorization: Bearer <key>`. Required only when MCP_AUTH_MODE=static-key.
MCP_REQUEST_STATE_KEY—yesHMAC key (at least 32 bytes) sealing the approval-gated write tools' requestState on MCP 2026-07-28 connections (#1031). Optional: unset uses a random per-process key, which is fine for a single replica; set the same value on every replica of a multi-replica deployment.
MCP_REQUEST_STATE_KEY_PREVIOUS—yesSecond requestState HMAC key, accepted for opening a sealed plan but never for sealing one: two-key rotation of MCP_REQUEST_STATE_KEY (#1032). Optional, and only valid together with MCP_REQUEST_STATE_KEY. When rolling the key across replicas set this to the old key, and remove it two minutes after the last replica restarted.
MCP_ED25519_PUBLIC_KEY——Ed25519 public key (base64url) that MCP_AUTH_MODE=signed-key verifies license tokens against. DEFAULTS TO A SHARED DEMO KEY, which authenticates a token holder rather than a customer — every BlueCat-issued token for this server verifies against it. For anything beyond a trial, generate a per-deployment key pair (license-keygen --gen-key) and set this to its public half.
MCP_SIGNED_KEY_AUDIENCE——When set, a license token must carry exactly this audience or it is rejected — a declarative scope check on top of the key, so a token minted for another deployment fails even if it verifies. Unset means the aud claim is not checked. Only meaningful with MCP_AUTH_MODE=signed-key.
MCP_OAUTH_ISSUER——Token issuer URL, matched against the iss claim of incoming JWTs. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it.
MCP_OAUTH_JWKS_URI——JWKS endpoint whose public keys verify the signature on every incoming Bearer JWT. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it.
MCP_OAUTH_AUDIENCE——Expected JWT aud claim for MCP_AUTH_MODE=resource-server. A token carrying a different audience, or no aud claim at all, is rejected. Unset skips audience validation entirely.
ACCEPT_EULAyes—Set to Y (or Yes/YES, any casing) to accept the BlueCat End User License Agreement. The container refuses to start without it.

Freshness

Active — last maintenance signal 15d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    no data · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-24 · 15d ago · official registry · v26.1.0

FAQ

›Does Integrity require an API key?

Yes. It expects BAM_BASE_URL, MCP_AUTH_MODE, ACCEPT_EULA, BAM_PASSWORD, BAM_SSO_PASSWORD, MCP_API_KEY, MCP_REQUEST_STATE_KEY, MCP_REQUEST_STATE_KEY_PREVIOUS, of which 5 are secrets.

›Can I use Integrity as a remote (hosted) MCP server?

Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.

›Is Integrity in the official MCP registry?

Yes, as com.bluecat/integritymcp.