gitlab-mcp
A Model Context Protocol (MCP) server for GitLab
Crawler Summary
OpenClaw agent: mcp-server MCP Server Demo: OAuth, TypeScript & Firestore Patterns $1 This repository provides a stripped-down, illustrative implementation of a Model Context Protocol (MCP) server. It showcases the architectural patterns, security considerations (OAuth 2.0), and development practices (TypeScript, Firestore, Zod) detailed in our accompanying article: **➡️ Read the full story: "$1"** This demo focuses on the **MCP Resource Serve Published capability contract available. No trust telemetry is available yet. 10 GitHub stars reported by the source. Last updated 2/24/2026.
Freshness
Last checked 2/22/2026
Best For
Contract is available with explicit auth and schema references.
Not Ideal For
mcp-server is not ideal for teams that need stronger public trust telemetry, lower setup complexity, or more explicit contract coverage before production rollout.
Evidence Sources Checked
editorial-content, capability-contract, runtime-metrics, public facts pack
OpenClaw agent: mcp-server MCP Server Demo: OAuth, TypeScript & Firestore Patterns $1 This repository provides a stripped-down, illustrative implementation of a Model Context Protocol (MCP) server. It showcases the architectural patterns, security considerations (OAuth 2.0), and development practices (TypeScript, Firestore, Zod) detailed in our accompanying article: **➡️ Read the full story: "$1"** This demo focuses on the **MCP Resource Serve
Public facts
7
Change events
1
Artifacts
0
Freshness
Feb 22, 2026
Published capability contract available. No trust telemetry is available yet. 10 GitHub stars reported by the source. Last updated 2/24/2026.
Trust score
Unknown
Compatibility
MCP
Freshness
Feb 22, 2026
Vendor
Portal Labs Infrastructure
Artifacts
0
Benchmarks
0
Last release
1.0.0
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Published capability contract available. No trust telemetry is available yet. 10 GitHub stars reported by the source. Last updated 2/24/2026.
Setup snapshot
git clone https://github.com/portal-labs-infrastructure/mcp-server-blog.gitSetup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Portal Labs Infrastructure
Protocol compatibility
MCP
Auth modes
mcp, api_key, oauth
Machine-readable schemas
OpenAPI or schema references published
Adoption signal
10 GitHub stars
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
text
[Client / LLM with MCP Client SDK]
|
| (HTTPS Request with Bearer Token)
v
[This MCP Resource Server (Node.js / TypeScript)]
| 1. MCP SDK Middleware (parses request, extracts token)
| 2. `withWorkspaceAccess` HOC
| a. Using the userId associated with the token
| b. Validates the user can access the workspace_id in the request
| 3. Tool Handler Execution (interacts with Firestore based on validated context)
|
v
[Google Firestore (Database)]bash
git clone https://github.com/portal-labs-infrastructure/mcp-server-blog
cd mcp-server-blogbash
npm install
# or
yarn installbash
cp .env.example .env
dotenv
# Firestore Configuration
# If using Firestore Emulator, these might not all be strictly needed,
# but ensure your gcloud CLI is configured or provide necessary emulator host.
PROJECT_ID="your-gcp-project-id"
# FIRESTORE_EMULATOR_HOST="localhost:8081" # Uncomment if using emulator and not relying on gcloud config
# OAuth 2.0 Configuration (for this Resource Server to validate tokens)
# This depends on your OAuth Authorization Server's setup.
OAUTH_ISSUER_URL="https_your_auth_server_com"
# MCP Server Configuration
BASE_URL="http://localhost:8080" # URL this server is accessible atbash
npm run dev
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB MCP
Editorial quality
ready
OpenClaw agent: mcp-server MCP Server Demo: OAuth, TypeScript & Firestore Patterns $1 This repository provides a stripped-down, illustrative implementation of a Model Context Protocol (MCP) server. It showcases the architectural patterns, security considerations (OAuth 2.0), and development practices (TypeScript, Firestore, Zod) detailed in our accompanying article: **➡️ Read the full story: "$1"** This demo focuses on the **MCP Resource Serve
This repository provides a stripped-down, illustrative implementation of a Model Context Protocol (MCP) server. It showcases the architectural patterns, security considerations (OAuth 2.0), and development practices (TypeScript, Firestore, Zod) detailed in our accompanying article:
➡️ Read the full story: "Building a Production-Ready MCP Server with OAuth, TypeScript, and Our Battle Scars"
This demo focuses on the MCP Resource Server component and assumes you have a separate OAuth 2.0 Authorization Server.
Update: MCP SDK version 1.12.0 introduced the Authorization Server Metadata (/.well-known/oauth-authorization-server) support and removes the need to proxy the oauth calls through the MCP resource server.
This repository is intended as a learning resource to:
This is NOT a production-ready, plug-and-play server for all use cases. It omits specific business logic and assumes a pre-existing OAuth Authorization Server.
workspace_id in tool arguments.withWorkspaceAccess Higher-Order Component (HOC) for authentication and workspace authorization.fetchResourceList for DRY data fetching.throw new Error() for clear error propagation.This demo represents the MCP Resource Server. It expects OAuth 2.0 Bearer tokens issued by a separate OAuth Authorization Server.
[Client / LLM with MCP Client SDK]
|
| (HTTPS Request with Bearer Token)
v
[This MCP Resource Server (Node.js / TypeScript)]
| 1. MCP SDK Middleware (parses request, extracts token)
| 2. `withWorkspaceAccess` HOC
| a. Using the userId associated with the token
| b. Validates the user can access the workspace_id in the request
| 3. Tool Handler Execution (interacts with Firestore based on validated context)
|
v
[Google Firestore (Database)]
The OAuth Authorization Server (which you would provide or have existing) is responsible for:
This Resource Server then validates the tokens received from clients.
Clone the repository:
git clone https://github.com/portal-labs-infrastructure/mcp-server-blog
cd mcp-server-blog
Install dependencies:
npm install
# or
yarn install
Set up Environment Variables:
Copy the .env.example file to a new file named .env:
cp .env.example .env
Now, edit .env and fill in the required configuration values:
# Firestore Configuration
# If using Firestore Emulator, these might not all be strictly needed,
# but ensure your gcloud CLI is configured or provide necessary emulator host.
PROJECT_ID="your-gcp-project-id"
# FIRESTORE_EMULATOR_HOST="localhost:8081" # Uncomment if using emulator and not relying on gcloud config
# OAuth 2.0 Configuration (for this Resource Server to validate tokens)
# This depends on your OAuth Authorization Server's setup.
OAUTH_ISSUER_URL="https_your_auth_server_com"
# MCP Server Configuration
BASE_URL="http://localhost:8080" # URL this server is accessible at
Important: The OAuth configuration is crucial. This server needs to know how to validate tokens issued by your Authorization Server. Consult your Auth Server's documentation.
(Optional) Seed Firestore Data: If you have seed scripts or want to manually add some sample users, OAuth tokens (matching what your Auth server would issue), and workspace data to your Firestore instance/emulator, do so now. This will make testing the tools more meaningful.
npm run dev
bash npm run build npm start
The server will typically start on http://localhost:8080 (or the port specified in .env).gcloud emulators firestore start --host-port=localhost:8081
(Adjust port if needed and update FIRESTORE_EMULATOR_HOST in .env or ensure your application automatically detects it via gcloud environment variables).Look for these patterns in the src directory:
src/index.ts: Main MCP server setup.src/controllers/mcpController.ts: Tool registration and MCP controller handling incoming requests.src/services/: Service layer for handling Firestore interactions.src/tools/: Example tool definitions.
inputSchema (Zod) and a handler.withWorkspaceAccess.src/utils/withWorkspaceAccess.ts: The Higher-Order Component for workspace checks.src/utils/fetchResourceList.ts: Example of reusable data fetching utility.src/utils/types.ts: Shared TypeScript types and Zod schemas (e.g., for EntityType, ResourceType)..
├── src/
│ ├── tools/ # Tool definitions
│ │ ├── getAgentTool.ts
│ │ └── ...
│ ├── utils/ # Shared utilities, HOCs, types
│ │ ├── withWorkspaceAccess.ts
│ │ ├── types.ts
│ │ └── ...
│ ├── services/ # Interaction logic
│ │ ├── firestoreService.ts # Firestore interaction logic
│ │ └── ...
│ ├── config/ # Configuration loading
│ └── index.ts # Main server setup
├── .env.example # Example environment variables
├── .env # Your local environment variables (ignored by git)
├── package.json
├── tsconfig.json
└── ...
This is primarily a demo repository. However, if you find bugs or have suggestions for improving the clarity of the demonstrated patterns, feel free to open an issue or submit a pull request.
This project is licensed under the MIT License - see the LICENSE file for details.
This demo is heavily inspired by the experiences and patterns discussed in the article: "Building a Production-Ready MCP Server with OAuth, TypeScript, and Our Battle Scars".
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
ready
Auth
mcp, api_key, oauth
Streaming
No
Data region
global
Protocol support
Requires: mcp, lang:typescript
Forbidden: none
Guardrails
Operational confidence: medium
curl -s "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract"
curl -s "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
A Model Context Protocol (MCP) server for GitLab
A Model Context Protocol (MCP) server for GitLab
This agent researches trends, scripts videos, sets up engagement automation, and compiles everything into a shareable document.
This agent analyzes Reddit data to generate trending content concepts tailored to your audience.
Contract JSON
{
"contractStatus": "ready",
"authModes": [
"mcp",
"api_key",
"oauth"
],
"requires": [
"mcp",
"lang:typescript"
],
"forbidden": [],
"supportsMcp": true,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": "https://github.com/portal-labs-infrastructure/mcp-server-blog#input",
"outputSchemaRef": "https://github.com/portal-labs-infrastructure/mcp-server-blog#output",
"dataRegion": "global",
"contractUpdatedAt": "2026-02-24T19:46:45.789Z",
"sourceUpdatedAt": "2026-02-24T19:46:45.789Z",
"freshnessSeconds": 19550505
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"MCP"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_MCP",
"generatedAt": "2026-10-09T02:28:31.125Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "MCP",
"type": "protocol",
"support": "supported",
"confidenceSource": "contract",
"notes": "Confirmed by capability contract"
}
],
"flattenedTokens": "protocol:MCP|supported|contract"
}Facts JSON
[
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "MCP",
"href": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:46:45.789Z",
"isPublic": true
},
{
"factKey": "auth_modes",
"category": "compatibility",
"label": "Auth modes",
"value": "mcp, api_key, oauth",
"href": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:46:45.789Z",
"isPublic": true
},
{
"factKey": "schema_refs",
"category": "artifact",
"label": "Machine-readable schemas",
"value": "OpenAPI or schema references published",
"href": "https://github.com/portal-labs-infrastructure/mcp-server-blog#input",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:46:45.789Z",
"isPublic": true
},
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Portal Labs Infrastructure",
"href": "https://github.com/portal-labs-infrastructure/mcp-server-blog",
"sourceUrl": "https://github.com/portal-labs-infrastructure/mcp-server-blog",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-24T19:43:14.176Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "10 GitHub stars",
"href": "https://github.com/portal-labs-infrastructure/mcp-server-blog",
"sourceUrl": "https://github.com/portal-labs-infrastructure/mcp-server-blog",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-24T19:43:14.176Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-portal-labs-infrastructure-mcp-server-blog/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to mcp-server and adjacent AI workflows.