
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@edgegap/mcp
Advanced tools
Deploy game servers on Edgegap from your coding agent. Runs locally; your API token never leaves your machine.
An MCP server that lets a coding agent take a developer from "I have a game server container" to "players are connected to it" without the developer reading the API reference.
Ten tools, hand-picked. Not generated from the OpenAPI spec — see Scope for why.
One line in your MCP client config. Nothing to clone, nothing to build.
{
"mcpServers": {
"edgegap": {
"command": "npx",
"args": ["-y", "@edgegap/mcp"]
}
}
}
Works in Claude Code, Cursor, Codex, and VS Code. Pin a version in production
(@edgegap/mcp@0.1.0) rather than floating on latest.
Node version: the server itself needs Node 18+. Deploying the optional Cloudflare Worker needs Node 22+, because
wranglerrequires it.
There is no Edgegap-hosted component. This server runs as a process on your own computer, spawned by your editor. The first tool call asks you for a token, shows what it authorises, and requires an explicit acknowledgement before accepting it. Where that token then lives, exhaustively:
That is the whole list. Not on disk. Not in a config file. Not in logs. Not on
any Edgegap server — the only thing sent to Edgegap is the API call itself,
exactly as if you had run curl. Closing your editor revokes this server's
access completely.
Generate a token at https://app.edgegap.com/user-settings?tab=tokens.
Setting EDGEGAP_API_TOKEN still works and takes precedence, for CI and for
clients that cannot show prompts. Do not pass a token as a command-line
argument — arguments are visible to other processes via ps, and the server
warns if it detects one.
Why this is not hosted. A hosted server would have to either store your
token or receive it on every request. "We don't store it" and "we never see it"
are different claims, and only a local process makes the second one. See
worker/DECISION.md for the full reasoning and the conditions under which a
hosted version becomes worth building.
The Edgegap API token cannot be scoped. One token authorises every application, every version, every running deployment, and your usage across the whole organization. There is no deploy-only token and no per-application token.
Consequences worth being deliberate about:
Recommended setup, in decreasing order of caution:
| Situation | Setup |
|---|---|
| Unattended or autonomous agent | Separate non-production organization, plus EDGEGAP_READ_ONLY=1 |
| Supervised agent, live game in the org | EDGEGAP_APP_ALLOWLIST scoped to the app being worked on, plus EDGEGAP_MAX_DURATION_MINUTES |
| Solo developer, no production workload | Defaults are fine; revoke the token when finished |
The allowlist and read-only flag are enforced in this server, which means they protect against an agent that makes a mistake, not against one that has been compromised into calling the API directly. They narrow the blast radius; they do not remove it.
| Variable | Default | Purpose |
|---|---|---|
EDGEGAP_API_TOKEN | (prompted) | API token. Optional — omit it and the developer is asked at first use. The token prefix is added for you. |
EDGEGAP_READ_ONLY | 0 | Set to 1 and the five mutating tools are never registered. The agent cannot see them, so it cannot be talked into calling them. |
EDGEGAP_APP_ALLOWLIST | (empty) | Comma-separated application names. When set, every tool refuses to touch anything else. |
EDGEGAP_MAX_DURATION_MINUTES | 60 | Ceiling on max_duration the agent may set on a version. Caps runaway cost from an unattended agent. |
EDGEGAP_TIMEOUT_MS | 30000 | Per-request HTTP timeout. |
Ordered along the golden path.
| # | Tool | Mutating | What it's for |
|---|---|---|---|
| 1 | edgegap_list_apps | Orient before doing anything. Prevents duplicate applications. | |
| 2 | edgegap_create_app | ● | Create the container for versions. |
| 3 | edgegap_list_app_versions | Find a deployable version, or copy settings from a working one. | |
| 4 | edgegap_create_app_version | ● | Register a container image with CPU, memory, and ports. |
| 5 | edgegap_deploy | ● | Start one instance near specified players. |
| 6 | edgegap_get_deployment | Single status read. | |
| 7 | edgegap_wait_for_deployment | Poll to ready with backoff, then return the connection address. | |
| 8 | edgegap_list_deployments | Find orphaned servers from earlier sessions. | |
| 9 | edgegap_stop_deployment | ● | Graceful SIGTERM, one deployment at a time. |
| 10 | edgegap_get_deployment_logs | Container output and crash exit code after a failure. |
Curated, not generated. The Edgegap API has roughly sixty operations. Auto-generating one tool per operation puts all sixty descriptions into the agent's context on every turn and measurably degrades tool selection. These ten cover the path that converts a new developer.
wait_for_deployment is a tool, not a loop. Left to itself an agent will
call a status endpoint in a tight loop, burn turns, and give up early. Folding
the polling and backoff into one call removes the most common failure in
agent-driven deploys.
Errors are written for self-correction. A 424 comes back saying the image could not be pulled and which fields to check. A 422 says to try different coordinates or lower the resource request. The agent can act on these without a round trip to the human.
Local validation before the wire. The memory-to-CPU ratio and the missing player location are caught here rather than surfacing as an opaque 400.
Bulk operations are deliberately absent. stop takes one request_id.
There is no bulk-stop tool, because an agent with a filter expression and a bug
can stop a production fleet.
Not exposed, on purpose: matchmaking, relays, private fleets, smart fleets, endpoint storage, ACL/whitelist entries, deployment tags, metrics, container registry management, DNS configuration.
These are real capabilities, but they belong to studios already operating on the platform, not to a developer deploying their first server. Adding them would trade the conversion path for surface area.
The MCP specification says servers should not use elicitation to collect sensitive data, and an API token is sensitive. This server does it anyway, because requiring a token in a config file before anything works is the largest drop in the onboarding funnel, and the whole point of the server is to remove setup friction.
That is a deliberate trade rather than a pattern to copy. What makes it
defensible is the set of mitigations in src/auth.ts — memory-only storage,
plain-language disclosure, required acknowledgement, redaction from all output,
and the environment variable always winning when present. Removing any of them
breaks the trade.
The real fix is on Edgegap's side: scoped, revocable, deploy-only credentials, issued through OAuth rather than pasted as a secret. Until those exist, the interactive prompt is a workaround and is labelled as one in the code.
npm run typecheck
node smoke.mjs # handshake, tool registration, read-only mode
node guards.mjs # local validation and allowlist enforcement
node elicit.mjs # token prompt: accept, refuse acknowledgement, decline, no support
None of these make network calls. elicit.mjs asserts that the prompt states
the org-wide scope, that the acknowledgement is required, that the token never
appears in tool output, and that declining produces a stop-and-report message
rather than a retry loop.
FAQs
Deploy game servers on Edgegap from your coding agent. Runs locally; your API token never leaves your machine.
The npm package @edgegap/mcp receives a total of 50 weekly downloads. As such, @edgegap/mcp popularity was classified as not popular.
We found that @edgegap/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.