by samanhappy
Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.
# Add to your Claude Code skills
git clone https://github.com/samanhappy/mcphubGuides for using mcp servers skills like mcphub.
Last scanned: 4/25/2026
{
"issues": [
{
"type": "npm-audit",
"message": "better-auth: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "hono: hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "next: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "typeorm: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
}
],
"status": "PASSED",
"scannedAt": "2026-04-25T05:49:52.951Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how mcphub compares with popular alternatives.
mcphub is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by samanhappy. Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers. It has 2,513 GitHub stars.
Yes. mcphub passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/samanhappy/mcphub" and add it to your Claude Code skills directory (see the Installation section above).
mcphub is primarily written in TypeScript. It is open-source under samanhappy on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh mcphub against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
An open-source, self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.
MCPHub provides a unified control point between AI clients and MCP servers. Connect local and remote MCP servers once, organize and route their capabilities through stable endpoints, control access with authentication, scoped credentials, and per-user visibility, and operate everything with centralized logs, activity tracking, and health monitoring.
It works with MCP clients such as Claude Code, Cursor, Cherry Studio, OpenWebUI, and other MCP-compatible applications.

>=20.0.0 and pnpm 10.12.4 — only needed to run from source or develop locally (see Local Development)docker run -p 3000:3000 -v ./data:/app/data samanhappy/mcphub
Open http://localhost:3000 and log in with username admin. On first launch, if no ADMIN_PASSWORD environment variable is set, a random password is generated and printed to the server logs.
Settings, users, and credential bindings persist in ./data by default.
Want your own servers? Before the first launch, create data/mcp_settings.json (see Configuration). After launch, add servers in the dashboard or edit the existing file and restart MCPHub.
Create data/mcp_settings.json before the first launch:
{
"mcpServers": {
"time": {
"command": "npx",
"args": ["-y", "time-mcp"]
},
"fetch": {
"command": "uvx",
"args": ["mcp-server-fetch"]
}
}
}
📖 See Configuration Guide for full options including OAuth, environment variables, and more.
See Start with Docker for the copy-paste command. Keep ./data mounted so settings, users, and credential bindings survive container recreation.
Two image variants are published under samanhappy/mcphub:
latest — the default image. Includes Node.js/pnpm, Python, uv/uvx, Git, and build tools. Covers most MCP servers.latest-full — the extended image. Adds Rust toolchain (Cargo/rustc), Docker Engine, and Playwright browsers (Chrome + Firefox, amd64 only). Use this for Rust-based servers or container-in-container workflows. Larger download.See Docker Setup for build options and Docker-in-Docker configuration.
Open http://localhost:3000 (see Start with Docker for login details). You can also pre-set the password:
# Docker: set admin password via environment variable
docker run -p 3000:3000 -v ./data:/app/data -e ADMIN_PASSWORD=your-secure-password samanhappy/mcphub
Tip: Change the admin password after first login for security.
Headless mode: Set
DISABLE_WEB=trueto skip serving the bundled dashboard UI and run MCPHub with only the backend/API and MCP endpoints. This is useful when you want to manage servers directly frommcp_settings.json.
Connect AI clients (Claude Desktop, Cursor, etc.) via:
http://localhost:3000/mcp # All servers
http://localhost:3000/mcp/{group} # Specific group
http://localhost:3000/mcp/{server} # Specific server
http://localhost:3000/mcp/$smart # Smart routing
http://localhost:3000/mcp/$smart/{group} # Smart routing within group
Security note: MCP endpoints require authentication by default to prevent accidental exposure. To allow unauthenticated MCP access, disable Enable Bearer Authentication in the Keys section. Skip Authentication only affects dashboard login. Use only in trusted environments.
📖 See API Reference for detailed endpoint documentation.
| Topic | Description |
|---|---|
| Quick Start | Get started in 5 minutes |
| Configuration | MCP server configuration options |
| Database Mode | PostgreSQL setup for production |
| OAuth | OAuth 2.0 client and server setup |
| Smart Routing | AI-powered tool discovery |
| MCP Apps | Interactive Apps transparent proxy |
| CLI Guide | Manage and call the hub from a terminal |
| Docker Setup | Docker deployment guide |
git clone https://github.com/samanhappy/mcphub.git
cd mcphub
pnpm install
pnpm dev
Local development uses admin / admin123 and stores its writable settings copy at data/mcp_settings.dev.json, so the repository mcp_settings.json stays credential-free.
For Windows users, start backend and frontend separately:
pnpm backend:dev,pnpm frontend:dev
📖 See Development Guide for detailed setup instructions.
mcp_settings.json by default; PostgreSQL via TypeORM with pgvector for Smart Routing@node-oauth/oauth2-server); optional Better Auth for GitHub/Google loginRunning MCPHub in production?
Work directly with the maintainer on production architecture, OAuth/OIDC, identity and access control, credential management, audit, Kubernetes, and HA readiness.
Contributions welcome! See our Discord community for discussions and support.
Chinese users can also support via WeChat Pay — see 中文版.