mcpo
A simple, secure MCP-to-OpenAPI proxy server
Decision gist · record as of 2026-08-14
Yes. mcpo solves a real interoperability problem (MCP servers are stdio-only, most tools expect OpenAPI) with low install friction, active maintenance, and no known vulnerabilities. The license treatment is unclear, so verify the actual license before use. For any workflow where you need to expose MCP tools to REST clients or LLM agents, this is the right tool.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Low friction: pure Python wheel with no compiled dependencies.
- Active maintenance (latest release 2026-02-27).
License · maintenance · safety
(unclear) — License treatment is unclear—no SPDX identifier or raw license text provided in metadata. Verify the actual license (description mentions MIT) before use in proprietary or restricted contexts.
last release 2026-02-27 (168 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 289,951 downloads/mo, #7,995 on PyPI
Alternatives
Verify before relying
pip install mcpo
mcpo --port 8000 --api-key "secret" -- your_mcp_server_command
# Access OpenAPI docs at http://localhost:8000/docs- License metadata shows 'unclear' treatment despite description claiming MIT—confirm actual license terms before deployment.
- No documented security audit or threat model for the proxy layer itself; verify authentication and token handling for production use.
- OAuth 2.1 support mentioned in description but not reflected in runtime dependencies—confirm implementation completeness.
What it is and what it does
mcpo is a proxy server that translates MCP (Model Context Protocol) servers—which typically communicate over stdio—into standard HTTP/OpenAPI endpoints. This solves a fundamental compatibility gap: MCP servers are inherently insecure and incompatible with tools expecting REST APIs, but mcpo bridges that gap by wrapping any MCP server command and exposing its tools via FastAPI with auto-generated interactive documentation, authentication, and standard HTTP semantics.
You run mcpo with an MCP server command (or point it to an SSE or HTTP-based MCP endpoint), and it immediately serves an OpenAPI schema at `/docs` and proxy routes for each tool. It supports single servers via command-line flags, multiple servers via a Claude Desktop–compatible config file with hot-reload, and OAuth 2.1 for protected endpoints. The proxy adds security (API keys, auth), stability (HTTP error handling), and interoperability (any OpenAPI client can now call your MCP tools) without requiring custom glue code.
Use it for
- Integrate MCP tools (like mcp-server-time) with LLM agents or applications that only understand OpenAPI, enabling tool use without protocol translation.
- Expose a suite of MCP servers behind a single HTTP gateway with per-tool routing and authentication, suitable for multi-tenant or shared environments.
- Serve MCP tools behind a reverse proxy or subpath in production using `--root-path`, with hot-reload config for zero-downtime updates.
- Provide interactive API documentation and testing UI for MCP tools via the auto-generated `/docs` endpoint, improving discoverability and debugging.
- Secure stdio-based MCP servers by wrapping them in an authenticated HTTP layer with API keys or OAuth 2.1, preventing unauthorized access.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
mcpo solves a real interoperability problem (MCP servers are stdio-only, most tools expect OpenAPI) with low install friction, active maintenance, and no known vulnerabilities. The license treatment is unclear, so verify the actual license before use. For any workflow where you need to expose MCP tools to REST clients or LLM agents, this is the right tool.
Install
mcpo on PyPI
Before you install
Low friction: pure Python wheel with no compiled dependencies. Active maintenance (latest release 2026-02-27). Depends on well-established libraries (FastAPI, Uvicorn, Pydantic, Click, Typer) with no known security issues.
Requires Python 3.11 or later.
License in practice
License treatment is unclear—no SPDX identifier or raw license text provided in metadata. Verify the actual license (description mentions MIT) before use in proprietary or restricted contexts.
Quickstart
pip install mcpo
mcpo --port 8000 --api-key "secret" -- your_mcp_server_command
# Access OpenAPI docs at http://localhost:8000/docs
Verify before relying
- License metadata shows 'unclear' treatment despite description claiming MIT—confirm actual license terms before deployment.
- No documented security audit or threat model for the proxy layer itself; verify authentication and token handling for production use.
- OAuth 2.1 support mentioned in description but not reflected in runtime dependencies—confirm implementation completeness.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 10 packagesclickfastapimcppasslibpydanticpyjwtpython-dotenvtyperuvicornwatchdog |
| Maintenance | Actively maintained 168 days since the last release |
| First released | |
| Downloads | 289,951 / month, #7,995 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: mcpo-0.0.20-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “mcp to openapi proxy”
- mcpoExposes MCP (Model Context Protocol) servers as OpenAPI-compatible…
- mcp-proxy-for-awsBridges MCP clients to AWS-hosted MCP servers using AWS IAM…
- mcp-proxymcp-proxy bridges Model Context Protocol (MCP) servers and clients…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also llama-index-tools-mcp · mcp · mcp-proxy · mcp-server-time · fastapi-mcp · databricks-mcp · awslabs.aws-api-mcp-server · excel-mcp-server · lean-lsp-mcp · mcpadapt