Demo application showcasing how to build and secure MCP servers and clients with Pomerium using contextual access policies.
How Does It Work MCP server is a locally run integration for AI assistants that speak the Model Context Protocol. Demo application showcasing how to build and secure MCP servers and clients with Pomerium using contextual access policies.
Welcome to the Pomerium Chat, a minimal chat application for showcasing remote Model Context Protocol servers secured with Pomerium.
Once How Does It Work is connected, these are the calls the assistant has available:
from — https://my-mcp-server.your-domain.comtrue — The user has all required internal tokens from upstream OAuth providers, or none are required for this serverfalse — The user needs to authenticate with the upstream OAuth provider before accessing this MCP serverrequest-id — useremail — mcp-methodmcp-tool — mcp-tool-parametersType — safe routing with TanStack RouterTesting — Now you should be able to navigate to https://mcp-app-demo.YOUR-DOMAIN/. A sign-in page would open. After you signed in, you should be redirected toThe server ships on npm as shadcn, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
You will need one environment variable: OPENAI_API_KEY. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.
Plenty of team communication servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. How Does It Work's toolset — from, true, false and 5 more — is a fair guide to whether it matches your workflow. It is maintained by pomerium; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| from | https://my-mcp-server.your-domain.com |
| true | The user has all required internal tokens from upstream OAuth providers, or none are required for this server. |
| false | The user needs to authenticate with the upstream OAuth provider before accessing this MCP server. |
| request-id | user |
| mcp-method | |
| mcp-tool | mcp-tool-parameters |
| Type | safe routing with TanStack Router |
| Testing | Now you should be able to navigate to https://mcp-app-demo.YOUR-DOMAIN/. A sign-in page would open. After you signed in, you should be redirected to the application itself. |
{
"mcpServers": {
"app-demo": {
"command": "npx",
"args": ["-y", "shadcn"],
"env": {
"OPENAI_API_KEY": "your-value"
}
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
| Variable | Description | Required |
|---|---|---|
| OPENAI_API_KEY | Credential the server authenticates with. | Yes |
Your assistant inside the workspace — read channels, search history, post messages and tame the noise.
Inbox intelligence — search, read, draft and send Gmail through your assistant with OAuth auto-setup.
Read and write Jira, Confluence, Bitbucket, JSM and Compass from your AI client — with your own permissions.
Read and send Telegram messages through your assistant — chats, channels and history via the client API.
Enables Discord bot integration with Model Context Protocol (MCP) compatible applications like Claude Desktop.
Exposes REST APIs defined by OpenAPI specifications as Model Context Protocol (MCP) tools, facilitating seamless integration into MCP-based workflows.