Toolmesh MCP Server

MCP gateway with authorization, credential injection, audit logging, and output policies.

Remote serverstreamable-httpTypeScript

What is the Toolmesh MCP server?

MCP gateway with authorization, credential injection, audit logging, and output policies. The toolmesh mcp server wraps that behind the Model Context Protocol, so an assistant can use it through 2 defined tools rather than through you.

What it actually does

In practice, MCP servers only expose a fraction of the REST API they wrap — and you'll hit the gaps fast. ToolMesh lets you replace the wrapper layer with .dadl files — a declarative YAML format that describes any REST API as MCP tools. No wrapper server to build, deploy, or maintain.

Its toolset

Everything the assistant can do here goes through one of these:

  • key_hash — "$2a$10$..."
  • Logging — ToolMesh uses structured logging via slog. The default level is info. Set LOG_LEVEL=debug to trace the full MCP request/response flow when

Configuration

You will need 5 environment variables: TOOLMESH_API_KEY, OPENFGA_STORE_ID, TOOLMESH_METRICS_HOST, MEMORIZER_API_KEY, CREDENTIAL_MEMORIZER_API_KEY. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Adding it to your client

Being a remote server, there is no local install. You register the endpoint with your client, authorise it once, and the tools appear.

When to reach for it

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Toolmesh's toolset — key_hash, Logging — is a fair guide to whether it matches your workflow. It is maintained by DunkelCloud; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Caveats

  • Your data travels to the provider's service, so the usual questions apply about what you send and what they retain.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the toolmesh mcp server does with a few real requests.

Available tools

ToolWhat it does
key_hash"$2a$10$..."
LoggingToolMesh uses structured logging via slog. The default level is **info**. Set LOG_LEVEL=debug to trace the full MCP request/response flow when diagnosing a problem — but note that debug logs include complete request URLs

Configuration

VariableDescriptionRequired
TOOLMESH_API_KEYCredential the server authenticates with.Yes
OPENFGA_STORE_IDConfiguration value read at startup.Optional
TOOLMESH_METRICS_HOSTEndpoint or connection string the server talks to.Optional
MEMORIZER_API_KEYCredential the server authenticates with.Yes
CREDENTIAL_MEMORIZER_API_KEYCredential the server authenticates with.Yes

Example prompts to try

  • Use Toolmesh to key hash.
  • Use Toolmesh to Logging.

Frequently asked questions

It connects Toolmesh to MCP-compatible AI assistants such as Claude and Cursor, exposing 2 tools (key_hash, Logging) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Toolmesh directly.