Unified MCP server that bridges Tavily and Brave Search APIs with key management, rate limiting, and an admin UI for monitoring and configuration.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
process.env. You'll be asked to provide them before it can run.ADMIN_API_TOKEN— Edit .env to set your and other configurationsADMIN_KEYS_EXPORT_RATE_LIMIT_PER_MINUTEADMIN_KEYS_IMPORT_RATE_LIMIT_PER_MINUTEADMIN_KEY_REVEAL_RATE_LIMIT_PER_MINUTE— Max key reveal attempts per minute in the Admin UI. 20BRAVE_API_KEY— A Brave Search API key. If set, this single key will be used. For multi-key support, add keys via the Admin UI. ""BRAVE_HTTP_TIMEOUT_MS— Per-request HTTP timeout for the Brave API. 20000BRAVE_MAX_QPS— Max requests per second to the Brave API to stay within rate limits. 1BRAVE_MAX_QUEUE_MS— Max time a request can wait in the queue before failing or falling back to Tavily. 30000BRAVE_MIN_INTERVAL_MS— Overrides BRAVE_MAX_QPS with a fixed minimum interval between requests. ""BRAVE_OVERFLOW— Behavior when the request queue is full: fallback_to_tavily (default), queue (wait), or error. fallback_to_tavilyBRAVE_USAGE_CLEANUP_PROBABILITYBRAVE_USAGE_HASH_SECRETBRAVE_USAGE_LOG_MODEBRAVE_USAGE_RETENTION_DAYSBRAVE_USAGE_SAMPLE_RATEDATABASE_URL— Connection string for the database. For local setups, a file-based SQLite DB is recommended. file:./tavily_bridge.dbDEFAULT_PARAMETERSENABLE_QUERY_AUTH— If true, also allow passing the MCP client token via query string (?tavilyApiKey=... / ?token=...) instead of Authorization: Bearer .... (Not recommended for production.) falseENABLE_TAVILY_CREDITS_CHECKHOST— The host address for the server to listen on. 0.0.0.0MCP_COOLDOWN_MS— Cooldown period in milliseconds for an upstream API key after a failure. 60000MCP_GLOBAL_RATE_LIMIT_PER_MINUTE— Max requests per minute across all clients. 600MCP_MAX_RETRIES— Maximum number of retries for failed upstream requests. 2MCP_RATE_LIMIT_PER_MINUTE— Max requests per minute per client token. 60PORT— The port for the server to listen on. 8787SEARCH_SOURCE_MODE— When =combined:SERVER_SETTINGS_REFRESH_MSTAVILY_BRIDGE_BASE_URL— Set to your deployment URL (for local Docker Compose: http://localhost:8787).TAVILY_BRIDGE_MCP_TOKEN— "": "<client_token>"TAVILY_BRIDGE_MCP_URLTAVILY_CREDITS_CACHE_TTL_MS— Duration to cache Tavily credit information before it's considered stale. 60000TAVILY_CREDITS_COOLDOWN_MS— Cooldown duration for a key that has fallen below the minimum credit threshold. 300000 (5m)TAVILY_CREDITS_MIN_REMAINING— Credit threshold at which a Tavily key will be automatically put into cooldown status. 1TAVILY_CREDITS_REFRESH_LOCK_MS— Lock duration to prevent concurrent credit refreshes for the same key. 15000TAVILY_CREDITS_REFRESH_MAX_RETRIESTAVILY_CREDITS_REFRESH_RETRY_DELAY_MSTAVILY_CREDITS_REFRESH_TIMEOUT_MS— Timeout for the upstream Tavily credits API request. 5000TAVILY_CREDITS_STALE_GRACE_MSTAVILY_KEY_SELECTION_STRATEGYTAVILY_RESEARCH_ENABLEDTAVILY_USAGE_CLEANUP_PROBABILITY— The probability (0.0 to 1.0) that a cleanup of old usage logs is triggered on a new usage event. 0.001TAVILY_USAGE_HASH_SECRET— Optional secret for creating a keyed HMAC-SHA256 hash of queries instead of a plain SHA256. Recommended for privacy. ""TAVILY_USAGE_LOG_MODE— Log level for Tavily tool usage: none, hash (query hash only), preview (redacted query), or full query. previewTAVILY_USAGE_RETENTION_DAYS— Optional retention period for usage logs. If set, old logs will be periodically cleaned up. ""TAVILY_USAGE_SAMPLE_RATE— Optional sampling rate (0.0 to 1.0) for logging usage events. Empty string means log all events. ""VITE_ADMIN_UI_PROXY_TARGET[](https://m8ven.ai/mcp/greenchannel-mcp-nexus-05rjos)