Run and manage your team's MCP servers from one place
Open-source · Self-hosted · MCP Gateway & Control Plane
MCPlama is a self-hosted MCP gateway and control plane for developers and teams who want to run multiple MCP servers without scattered credentials, duplicated client configuration, or unclear access.
Use it to centralize MCP server lifecycle, credentials, access policies, connections, and audit events while your AI clients connect through controlled MCP endpoints.
Instead of giving every AI client direct access to MCP servers and their credentials, configure your servers once in MCPlama and give each user a controlled connection URL.
MCP is easy to start with, but running multiple MCP servers across a team gets messy fast.
Without a control plane:
- 🔐 Credentials end up scattered across developer machines
- 🔌 Every client needs its own MCP configuration
- 👥 Access becomes difficult to grant and revoke
- 📋 Teams have little visibility into MCP activity
- 🐳 MCP servers still need somewhere to run and be managed
- 🛡️ Runtime access needs to be isolated from the gateway
MCPlama gives you one control point:
- 🌐 Controlled MCP connection URLs for your AI clients
- 🔐 Centralized OAuth and API credentials
- 👥 User and server access policies
- 📋 Audit logs for MCP activity
- 📦 MCP server catalog and lifecycle management
- 🛡️ Separate broker boundary for MCP container execution
Start locally with Docker. Move to shared team infrastructure when you need it.
See the docs directory for architecture, security, deployment, API, and development documentation.
This quickstart will show you how to:
- Start MCPlama locally with Docker
- Add and authorize an MCP server
- Connect an MCP client through MCPlama
Pull and run the published image:
docker pull mcplama/mcplama:latest
docker run -d --name mcplama \
-p 8080:8080 \
-v mcplama-data:/var/lib/postgresql \
-v /var/run/docker.sock:/var/run/docker.sock \
mcplama/mcplama:latestOpen:
http://localhost:8080
Complete the setup wizard to create your admin account.
There is no default admin account.
- Open Catalog
- Choose one of the pre-configured MCP servers
- Click Install
- Open the server's Authorization tab
- Follow the setup steps and provide the required credentials
- Click Authorize
Open the server's Connect tab and create a connection token.
MCPlama gives you a URL like:
http://localhost:8000/connect/mcp_your_token
Each user × server pair gets its own connection token. The underlying API credentials stay in MCPlama instead of being copied into the AI client's configuration.
You now have an MCP server running behind MCPlama with centralized credentials, access control, and auditing.
Team members can see and connect to the MCP servers available to them without receiving the underlying service credentials.
When an AI client connects through MCPlama, the gateway:
- Resolves the connection token to a user and server
- Validates the request origin
- Checks access policies
- Injects OAuth/API credentials
- Writes the audit log
- Proxies the request to the MCP server
MCP server containers are started by a separate broker process.
The broker is the only component with Docker socket access in the recommended multi-container deployment. The gateway itself has no Docker access, and runner containers never receive the Docker socket.
See Architecture and Security model for the full design.
Your connection URL can also be used with other MCP clients.
Claude Desktop
{
"mcpServers": {
"notion": {
"url": "http://localhost:8000/connect/mcp_your_token"
}
}
}Restart Claude Desktop after updating the configuration.
VS Code + GitHub Copilot
Create .vscode/mcp.json:
{
"servers": {
"notion": {
"url": "http://localhost:8000/connect/mcp_your_token"
}
}
}Requires VS Code 1.99+ with GitHub Copilot.
Cursor
Edit ~/.cursor/mcp.json:
{
"mcpServers": {
"notion": {
"url": "http://localhost:8000/connect/mcp_your_token"
}
}
}The quickstart is intended for evaluating MCPlama locally.
For production deployments, provide your own secrets and put an HTTPS reverse proxy in front of MCPlama.
See Docker deployment and Security model before exposing MCPlama outside a trusted environment.
Contributions and feedback are welcome.
If you're already running MCP infrastructure for a team, feedback around credentials, access control, deployment, auditing, and MCP server lifecycle is especially useful.
MCPlama is licensed under the GNU Affero General Public License, version 3 or any later version. See LICENSE.
Third-party dependencies remain under their respective licenses. See THIRD-PARTY-NOTICES.



