A federated MCP gateway that consolidates multiple plain-HTTP backends into a single, OAuth-protected MCP server, enabling agents to access diverse tools through one endpoint with centralized authentication and audit.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.AUTH_EMAIL_FROMCORTEX_ALLOWED_ORIGINS— prod Web origins allowed (exact or .suffix)CORTEX_AUDIT_RETENTION_DAYSCORTEX_BACKENDS— + CORTEX_BACKEND_<ID>_URL yes Federated backendsCORTEX_CANONICAL_URI— prod Canonical MCP resource URI (RFC 9728), default JWT audienceCORTEX_DATABASE_URL— no PostgreSQL for audit persistence + gateway ticketsCORTEX_DEV_BYPASS_ROLECORTEX_DEV_BYPASS_SCOPES— mcp:demo:readCORTEX_DEV_BYPASS_TOKEN— dev-secretCORTEX_MCP_SERVERSCORTEX_RATE_LIMIT_PER_MINUTECORTEX_REQUIRED_POOLCORTEX_SERVER_NAMECORTEX_TECHNICAL_TOKEN— demo-technical-tokenCORTEX_TICKET_BACKENDSCORTEX_TICKET_WEBHOOK_URL— no Webhook for blocking missing-capability ticketsCORTEX_VAULT_KEYCRON_SECRETINTROSPECT_CLIENT_IDINTROSPECT_CLIENT_SECRETOAUTH_AUDIENCEOAUTH_INTROSPECT_CACHE_TTL_SECONDSOAUTH_INTROSPECT_CLIENT_IDOAUTH_INTROSPECT_CLIENT_SECRETOAUTH_INTROSPECT_URLOAUTH_ISSUER— In production you point at your OAuth 2.1 authorizationOAUTH_JWKS_URLOAUTH_KEY_IDOAUTH_MCP_AUDIENCERATE_LIMIT_DISABLEDRESEND_API_KEY[](https://m8ven.ai/mcp/wellknownmcp-cortex-gateway-1vrt6j)