{"id":30257414,"url":"https://github.com/VeriTeknik/pluggedin-app","last_synced_at":"2025-08-15T16:04:58.978Z","repository":{"id":284060758,"uuid":"953505475","full_name":"VeriTeknik/pluggedin-app","owner":"VeriTeknik","description":"The Crossroads for AI Data Exchanges. A unified, self-hostable web interface for discovering, configuring, and managing Model Context Protocol (MCP) servers—bringing together AI tools, workspaces, prompts, and logs from multiple MCP sources (Claude, Cursor, etc.) under one roof.","archived":false,"fork":false,"pushed_at":"2025-08-12T23:46:44.000Z","size":38638,"stargazers_count":47,"open_issues_count":1,"forks_count":10,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-08-13T00:23:29.499Z","etag":null,"topics":["ai","mcp","mcp-client","mcp-server","model-context-protocol","model-context-protocol-servers","oauth2","rag","vibe-coding"],"latest_commit_sha":null,"homepage":"https://plugged.in","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"metatool-ai/metatool-app","license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/VeriTeknik.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":"ROADMAP.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-03-23T14:26:23.000Z","updated_at":"2025-08-12T13:30:51.000Z","dependencies_parsed_at":"2025-07-03T00:19:03.080Z","dependency_job_id":"ecd63046-bb27-473e-9759-8b657217597e","html_url":"https://github.com/VeriTeknik/pluggedin-app","commit_stats":null,"previous_names":["veriteknik/pluggedin-app"],"tags_count":23,"template":false,"template_full_name":null,"purl":"pkg:github/VeriTeknik/pluggedin-app","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VeriTeknik%2Fpluggedin-app","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VeriTeknik%2Fpluggedin-app/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VeriTeknik%2Fpluggedin-app/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VeriTeknik%2Fpluggedin-app/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/VeriTeknik","download_url":"https://codeload.github.com/VeriTeknik/pluggedin-app/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VeriTeknik%2Fpluggedin-app/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":270594163,"owners_count":24612661,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-15T02:00:12.559Z","response_time":110,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai","mcp","mcp-client","mcp-server","model-context-protocol","model-context-protocol-servers","oauth2","rag","vibe-coding"],"created_at":"2025-08-15T16:02:05.116Z","updated_at":"2025-08-15T16:04:58.963Z","avatar_url":"https://github.com/VeriTeknik.png","language":"JavaScript","funding_links":[],"categories":["📚 Projects (1974 total)","TypeScript"],"sub_categories":["MCP Servers"],"readme":"# plugged.in App\n\n\u003cdiv align=\"center\"\u003e\n  \u003cimg src=\"https://plugged.in/_next/image?url=%2Fpluggedin-wl.png\u0026w=256\u0026q=75\" alt=\"plugged.in Logo\" width=\"256\" height=\"75\"\u003e\n  \u003ch3\u003eThe Crossroads for AI Data Exchanges\u003c/h3\u003e\n  \u003cp\u003eA unified management interface for all your MCP servers with RAG capabilities\u003c/p\u003e\n\n  [![Version](https://img.shields.io/badge/version-2.7.0-blue?style=for-the-badge)](https://github.com/VeriTeknik/pluggedin-app/releases)\n  [![GitHub Stars](https://img.shields.io/github/stars/VeriTeknik/pluggedin-app?style=for-the-badge)](https://github.com/VeriTeknik/pluggedin-app/stargazers)\n  [![License](https://img.shields.io/github/license/VeriTeknik/pluggedin-app?style=for-the-badge)](LICENSE)\n  [![Next.js](https://img.shields.io/badge/Next.js-15+-black?style=for-the-badge\u0026logo=next.js)](https://nextjs.org/)\n  [![MCP](https://img.shields.io/badge/MCP-Compatible-green?style=for-the-badge)](https://modelcontextprotocol.io/)\n\u003c/div\u003e\n\n## 📋 Overview\n\nThe plugged.in App is a comprehensive web application for managing Model Context Protocol (MCP) servers with integrated RAG (Retrieval-Augmented Generation) capabilities. It works in conjunction with the [plugged.in MCP Proxy](https://github.com/VeriTeknik/pluggedin-mcp) to provide a unified interface for discovering, configuring, and utilizing AI tools across multiple MCP servers while leveraging your own documents as context.\n\nThis application enables seamless integration with any MCP client (Claude, Cline, Cursor, etc.) while providing advanced management capabilities, document-based knowledge augmentation, and real-time notifications through an intuitive web interface.\n\n\u003e ⭐ **If you find this project useful, please consider giving it a star on GitHub!** It helps us reach more developers and motivates us to keep improving.\n\n## ✨ Key Features\n\n### 🎯 New in v2.7.0 (Registry v2)\n- **MCP Registry Integration**: Modified fork of the official [MCP Registry](https://github.com/modelcontextprotocol/registry) - users can now claim MCP servers with GitHub credentials\n- **Completely Rewritten Discovery Process**: Enhanced server detection and management with improved performance and reliability\n- **Full Streamable HTTP Support**: Complete implementation of Streamable HTTP transport protocol\n- **OAuth for MCP Servers**: OAuth authentication handled by plugged.in with state-of-the-art encryption - no client-side authentication needed anymore\n- **Trending Servers with Analytics**: Every MCP tool call via pluggedin-mcp is tracked and displayed in trending servers\n- **Bidirectional Notifications**: MCP proxy can now send, receive, mark as read, and delete notifications\n- **Smart Server Wizard**: Multi-step wizard with GitHub verification, environment detection, and registry submission\n- **Enhanced Security**: Comprehensive input validation with Zod schemas and XSS/SSRF protection\n\n### 🚀 Core Capabilities\n- **Multi-Workspace Support**: Switch between different sets of MCP configurations to prevent context pollution\n- **Interactive Playground**: Test and experiment with your MCP tools directly in the browser\n- **Tool Management**: Discover, organize, and manage AI tools from multiple sources\n- **Resource \u0026 Template Discovery**: View available resources and resource templates for connected MCP servers\n- **Custom Instructions**: Add server-specific instructions that can be used as MCP prompts\n- **Prompt Management**: Discover and manage prompts from connected MCP servers\n\n### 🔐 New in v2.2.0\n- **End-to-End Encryption**: All sensitive MCP server configuration data (commands, arguments, environment variables, URLs) is now encrypted at rest using AES-256-GCM\n- **Per-Profile Encryption**: Each profile has its own derived encryption key, ensuring complete isolation between workspaces\n- **Secure Server Sharing**: Shared servers use sanitized templates that don't expose sensitive credentials\n- **Transparent Operation**: Encryption and decryption happen automatically without affecting the user experience\n\n### 🤖 New in v2.8.0 - AI Document Exchange (RAG v2)\n- **AI-Generated Documents**: MCP servers can create and manage documents in your library with full attribution\n- **Document Preview Modal**: View PDFs, images, and text files directly in the browser with zoom controls\n- **Enhanced Document Viewer**: Navigate between documents, fullscreen mode, and metadata display\n- **Multi-Format Support**: Native rendering for PDFs, images, markdown, and various code file formats\n- **Model Attribution Tracking**: Complete history of which AI models created or updated each document\n- **Advanced Document Search**: Semantic search with filtering by AI model, date, tags, and source type\n- **Document Versioning**: Track changes and maintain version history for AI-generated content\n- **Multi-Source Support**: Documents from uploads, AI generation, or API integrations\n\n### 📚 Features from v2.1.0\n- **Document Library with RAG**: Upload and manage documents that serve as knowledge context for AI interactions\n- **Real-Time Notifications**: Get instant notifications for MCP activities with optional email delivery\n- **Progressive Server Initialization**: Faster startup with resilient server connections\n- **Enhanced Security**: Industry-standard sanitization and secure environment variable handling\n- **Improved UI/UX**: Redesigned playground, better responsive design, and theme customization\n\n### 🔧 Advanced Features\n- **Server Notes**: Add custom notes to each configured MCP server\n- **Extensive Logging**: Detailed logging capabilities for MCP interactions in the Playground\n- **Expanded Discovery**: Search for MCP servers across GitHub, Smithery, and npmjs.com\n- **Email Verification**: Secure account registration with email verification\n- **Self-Hostable**: Run your own instance with full control over your data\n\n## 🚀 Quick Start with Docker\n\nThe easiest way to get started with the plugged.in App is using Docker Compose:\n\n```bash\n# Clone the repository\ngit clone https://github.com/VeriTeknik/pluggedin-app.git\ncd pluggedin-app\n\n# Set up environment variables\ncp .env.example .env\n# Edit .env with your specific configuration\n\n# Start the application with Docker Compose\ndocker compose up --build -d\n```\n\nThen open http://localhost:12005 in your browser to access the plugged.in App.\n\n### 🔄 Upgrading to v2.1.0\n\nFor existing installations upgrading to v2.2.0:\n\n```bash\n# Quick upgrade for Docker users\ndocker pull ghcr.io/veriteknik/pluggedin-app:v2.2.0\ndocker-compose down \u0026\u0026 docker-compose up -d\n\n# The encryption will be applied automatically to existing servers\n```\n\n**Note**: Ensure you have the `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` environment variable set. If not present, generate one:\n```bash\npnpm generate-encryption-key\n```\n\n## 🔌 Connecting MCP Clients\n\n### Prerequisites\n\n- The plugged.in App running (either self-hosted or at https://plugged.in)\n- An API key from the plugged.in App (available in the API Keys page)\n- The plugged.in MCP Proxy installed\n\n### Claude Desktop Configuration\n\n```json\n{\n  \"mcpServers\": {\n    \"pluggedin\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@pluggedin/pluggedin-mcp-proxy@latest\"],\n      \"env\": {\n        \"PLUGGEDIN_API_KEY\": \"YOUR_API_KEY\",\n        \"PLUGGEDIN_API_BASE_URL\": \"http://localhost:12005\" // For self-hosted instances\n      }\n    }\n  }\n}\n```\n\n### Cursor Configuration\n\nFor Cursor, you can use command-line arguments:\n\n```bash\nnpx -y @pluggedin/pluggedin-mcp-proxy@latest --pluggedin-api-key YOUR_API_KEY --pluggedin-api-base-url http://localhost:12005\n```\n\n## 🏗️ System Architecture\n\nThe plugged.in ecosystem consists of integrated components working together to provide a comprehensive MCP management solution with RAG capabilities:\n\n```mermaid\nsequenceDiagram\n    participant MCPClient as MCP Client (e.g., Claude Desktop)\n    participant PluggedinMCP as plugged.in MCP Proxy\n    participant PluggedinApp as plugged.in App\n    participant MCPServers as Installed MCP Servers\n\n    MCPClient -\u003e\u003e PluggedinMCP: Request list tools/resources/prompts\n    PluggedinMCP -\u003e\u003e PluggedinApp: Get capabilities via API\n    PluggedinApp -\u003e\u003e PluggedinMCP: Return capabilities (prefixed)\n\n    MCPClient -\u003e\u003e PluggedinMCP: Call tool/read resource/get prompt\n    alt Standard capability\n        PluggedinMCP -\u003e\u003e PluggedinApp: Resolve capability to server\n        PluggedinApp -\u003e\u003e PluggedinMCP: Return server details\n        PluggedinMCP -\u003e\u003e MCPServers: Forward request to target server\n        MCPServers -\u003e\u003e PluggedinMCP: Return response\n    else Custom instruction\n        PluggedinMCP -\u003e\u003e PluggedinApp: Get custom instruction\n        PluggedinApp -\u003e\u003e PluggedinMCP: Return formatted messages\n    end\n    PluggedinMCP -\u003e\u003e MCPClient: Return response\n\n    alt Discovery tool\n        MCPClient -\u003e\u003e PluggedinMCP: Call pluggedin_discover_tools\n        PluggedinMCP -\u003e\u003e PluggedinApp: Trigger discovery action\n        PluggedinApp -\u003e\u003e MCPServers: Connect and discover capabilities\n        MCPServers -\u003e\u003e PluggedinApp: Return capabilities\n        PluggedinApp -\u003e\u003e PluggedinMCP: Confirm discovery complete\n        PluggedinMCP -\u003e\u003e MCPClient: Return discovery result\n    end\n```\n\n## ⚙️ Configuration\n\n### Environment Variables\n\nThe plugged.in App supports various configuration options through environment variables:\n\n```bash\n# Core Configuration\nDATABASE_URL=postgresql://user:password@localhost:5432/pluggedin\nNEXTAUTH_URL=http://localhost:12005\nNEXTAUTH_SECRET=your-secret-key\n\n# Feature Flags (New in v2.1.0)\nENABLE_RAG=true                    # Enable RAG features\nENABLE_NOTIFICATIONS=true          # Enable notification system\nENABLE_EMAIL_VERIFICATION=true     # Enable email verification\n\n# Email Configuration (for notifications)\nEMAIL_SERVER_HOST=smtp.example.com\nEMAIL_SERVER_PORT=587\nEMAIL_SERVER_USER=your-email@example.com\nEMAIL_SERVER_PASSWORD=your-password\nEMAIL_FROM=noreply@example.com\n\n# RAG Configuration (optional)\nRAG_API_URL=http://localhost:8000  # Your RAG service endpoint\nRAG_CHUNK_SIZE=1000               # Document chunk size\nRAG_CHUNK_OVERLAP=200             # Chunk overlap for context\n\n# MCP Server Sandboxing (Linux)\nFIREJAIL_USER_HOME=/home/pluggedin\nFIREJAIL_LOCAL_BIN=/home/pluggedin/.local/bin\nFIREJAIL_APP_PATH=/home/pluggedin/pluggedin-app\nFIREJAIL_MCP_WORKSPACE=/home/pluggedin/mcp-workspace\n```\n\n### Feature Configuration\n\n#### Document Library \u0026 RAG v2\nThe plugged.in platform now features advanced RAG v2 capabilities with AI document exchange:\n\n**Core RAG Features:**\n1. Enable RAG in playground settings\n2. Upload documents through the Library page\n3. Documents are automatically indexed for context retrieval\n4. Supported formats: PDF, TXT, MD, DOCX, JSON, HTML, and more\n\n**New RAG v2 Features:**\n1. **AI Document Generation**: MCP servers can create documents directly in your library\n   - Full model attribution tracking (which AI created/updated the document)\n   - Version history with change tracking\n   - Content deduplication via SHA-256 hashing\n   \n2. **Advanced Document Sources**:\n   - `upload`: Traditional file uploads\n   - `ai_generated`: Documents created by AI models via MCP\n   - `api`: Documents created via API integrations\n   \n3. **Smart Document Search**:\n   - Semantic search with relevance scoring\n   - Filter by AI model, provider, date range, tags, and source\n   - Automatic snippet generation with keyword highlighting\n   \n4. **Document Management**:\n   - Visibility levels: private, workspace, or public\n   - Parent-child relationships for document versions\n   - Profile-based organization alongside project-based scoping\n\n**Example: AI Creating a Document via MCP**\n```json\nPOST /api/documents/ai\n{\n  \"title\": \"Analysis Report\",\n  \"content\": \"# Market Analysis\\n\\nDetailed findings...\",\n  \"format\": \"md\",\n  \"tags\": [\"analysis\", \"market\"],\n  \"category\": \"report\",\n  \"metadata\": {\n    \"model\": {\n      \"name\": \"Claude\",\n      \"provider\": \"Anthropic\",\n      \"version\": \"3\"\n    },\n    \"visibility\": \"workspace\"\n  }\n}\n```\n\n#### Notifications\n1. Real-time notifications for MCP activities\n2. Optional email delivery for important alerts\n3. Configurable notification preferences per profile\n4. Activity logging for debugging and monitoring\n\n### API Examples for RAG v2\n\n#### Creating AI-Generated Documents\n\n```bash\n# AI model creates a document\ncurl -X POST https://your-domain.com/api/documents/ai \\\n  -H \"Authorization: Bearer YOUR_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"title\": \"Technical Analysis Report\",\n    \"content\": \"# Technical Analysis\\n\\n## Summary\\n\\nThis document contains...\",\n    \"format\": \"md\",\n    \"tags\": [\"technical\", \"analysis\", \"ai-generated\"],\n    \"category\": \"report\",\n    \"metadata\": {\n      \"model\": {\n        \"name\": \"Claude 3 Opus\",\n        \"provider\": \"Anthropic\",\n        \"version\": \"20240229\"\n      },\n      \"context\": \"User requested technical analysis of system architecture\",\n      \"visibility\": \"private\"\n    }\n  }'\n\n# Response\n{\n  \"success\": true,\n  \"documentId\": \"550e8400-e29b-41d4-a716-446655440000\",\n  \"message\": \"Document successfully created\",\n  \"url\": \"/library/550e8400-e29b-41d4-a716-446655440000\"\n}\n```\n\n#### Searching Documents with AI Filters\n\n```bash\n# Search for documents created by specific AI models\ncurl -X POST https://your-domain.com/api/documents/search \\\n  -H \"Authorization: Bearer YOUR_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"query\": \"system architecture\",\n    \"filters\": {\n      \"modelName\": \"Claude 3 Opus\",\n      \"modelProvider\": \"Anthropic\",\n      \"source\": \"ai_generated\",\n      \"dateFrom\": \"2024-01-01T00:00:00Z\",\n      \"tags\": [\"technical\"]\n    },\n    \"limit\": 10,\n    \"offset\": 0\n  }'\n\n# Response\n{\n  \"results\": [\n    {\n      \"id\": \"550e8400-e29b-41d4-a716-446655440000\",\n      \"title\": \"Technical Analysis Report\",\n      \"description\": \"AI-generated report by Claude 3 Opus\",\n      \"snippet\": \"...system architecture analysis shows that...\",\n      \"relevanceScore\": 0.85,\n      \"source\": \"ai_generated\",\n      \"aiMetadata\": {\n        \"model\": {\n          \"name\": \"Claude 3 Opus\",\n          \"provider\": \"Anthropic\",\n          \"version\": \"20240229\"\n        }\n      },\n      \"tags\": [\"technical\", \"analysis\", \"ai-generated\"],\n      \"modelAttributions\": [\n        {\n          \"model_name\": \"Claude 3 Opus\",\n          \"model_provider\": \"Anthropic\",\n          \"contribution_type\": \"created\"\n        }\n      ]\n    }\n  ],\n  \"total\": 1,\n  \"limit\": 10,\n  \"offset\": 0,\n  \"hasMore\": false\n}\n```\n\n#### Document Upload Progress Tracking\n\nWhen uploading large documents, track the RAG processing progress:\n\n```bash\n# Check upload status\ncurl -X GET https://your-domain.com/api/documents/upload-status/UPLOAD_ID \\\n  -H \"Authorization: Bearer YOUR_API_KEY\"\n\n# Response\n{\n  \"success\": true,\n  \"progress\": {\n    \"status\": \"processing\",\n    \"progress\": {\n      \"step\": \"embeddings\",\n      \"current\": 45,\n      \"total\": 100,\n      \"step_progress\": {\n        \"chunks_processed\": 45,\n        \"total_chunks\": 100,\n        \"percentage\": 45,\n        \"estimated_remaining_time\": \"2m 30s\"\n      }\n    },\n    \"message\": \"Generating embeddings for document chunks...\"\n  }\n}\n```\n\n## 💻 Production Deployment\n\n### System Requirements\n\n- Node.js v18+ (recommended v20+)\n- PostgreSQL 15+\n- PNPM package manager\n- Nginx web server (for production deployments)\n- Systemd (for service management)\n\n### Production Setup\n\n1. Clone the repository:\n   ```bash\n   git clone https://github.com/VeriTeknik/pluggedin-app.git /home/pluggedin/pluggedin-app\n   cd /home/pluggedin/pluggedin-app\n   ```\n\n2. Install dependencies:\n   ```bash\n   pnpm install\n   ```\n\n3. Set up environment variables:\n   ```bash\n   cp .env.example .env\n   # Edit .env with your specific configuration\n   ```\n\n4. Run database migrations:\n   ```bash\n   pnpm db:migrate:auth\n   pnpm db:generate\n   pnpm db:migrate\n   ```\n\n5. Build the application for production:\n   ```bash\n   NODE_ENV=production pnpm build\n   ```\n\n6. Create a systemd service file at `/etc/systemd/system/pluggedin.service`:\n   ```ini\n   [Unit]\n   Description=plugged.in Application Service\n   After=network.target postgresql.service\n   Wants=postgresql.service\n\n   [Service]\n   User=pluggedin\n   Group=pluggedin\n   WorkingDirectory=/home/pluggedin/pluggedin-app\n   ExecStart=/usr/bin/pnpm start\n   Restart=always\n   RestartSec=10\n   StandardOutput=append:/var/log/pluggedin/pluggedin_app.log\n   StandardError=append:/var/log/pluggedin/pluggedin_app.log\n   Environment=PATH=/usr/bin:/usr/local/bin\n   Environment=NODE_ENV=production\n   Environment=PORT=12005\n\n   [Install]\n   WantedBy=multi-user.target\n   ```\n\n7. Set up Nginx as a reverse proxy:\n   ```nginx\n   # HTTPS Server\n   server {\n       listen 443 ssl;\n       server_name your-domain.com;\n\n       # SSL configuration\n       ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;\n       ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;\n\n       # Next.js static files\n       location /_next/static/ {\n           alias /home/pluggedin/pluggedin-app/.next/static/;\n           expires 365d;\n           add_header Cache-Control \"public, max-age=31536000, immutable\";\n       }\n\n       # Proxy settings for Node.js application\n       location / {\n           proxy_pass http://localhost:12005;\n           proxy_http_version 1.1;\n           proxy_set_header Upgrade $http_upgrade;\n           proxy_set_header Connection 'upgrade';\n           proxy_set_header Host $host;\n           proxy_cache_bypass $http_upgrade;\n       }\n   }\n\n   # HTTP redirect to HTTPS\n   server {\n       listen 80;\n       server_name your-domain.com;\n       return 301 https://$host$request_uri;\n   }\n   ```\n\n8. Enable and start the service:\n   ```bash\n   sudo systemctl daemon-reload\n   sudo systemctl enable pluggedin.service\n   sudo systemctl start pluggedin.service\n   ```\n\n### Security Considerations\n\n**Enhanced Security Features**\n\nThe plugged.in App implements comprehensive security measures to protect your data and prevent common vulnerabilities:\n\n1. **Input Validation \u0026 Sanitization**\n   - **URL Validation**: SSRF protection blocks private IPs, localhost, and dangerous ports\n   - **Command Allowlisting**: Only approved commands (node, npx, python, python3, uv, uvx, uvenv)\n   - **Header Validation**: RFC 7230 compliant with injection prevention\n   - **HTML Sanitization**: All user inputs sanitized with `sanitize-html`\n   - **Environment Variables**: Secure parsing with proper quote handling\n\n2. **MCP Server Security**\n   - **Sandboxing (Linux/Ubuntu)**: STDIO servers wrapped with `firejail --quiet`\n   - **Transport Validation**: Security checks for STDIO, SSE, and Streamable HTTP\n   - **Session Management**: Secure session handling for Streamable HTTP\n   - **Error Sanitization**: Prevents information disclosure\n\n3. **API Security**\n   - **Rate Limiting**: Tiered limits for different endpoint types\n   - **Authentication**: JWT-based with 30-day session expiry\n   - **CORS Protection**: Properly configured for all endpoints\n   - **Audit Logging**: Comprehensive activity tracking\n\n4. **Data Protection**\n   - **Encryption at Rest**: AES-256-GCM for sensitive server data\n   - **Per-Profile Keys**: Isolated encryption per workspace\n   - **Secure Sharing**: Sanitized templates without credentials\n   - **HTTPS Enforcement**: Required in production\n\nTo enable sandboxing, install Firejail:\n\n```bash\nsudo apt update \u0026\u0026 sudo apt install firejail\n```\n\n## 🔄 Cloud vs. Self-Hosted\n\n| Feature | Self-Hosted | Cloud (plugged.in) |\n|---------|------------|-------------------|\n| Cost | Free | Free tier available |\n| Data Privacy | Full control | Server-side encryption |\n| Authentication | Optional | Built-in |\n| Session Context | Basic | Enhanced |\n| Hosting | Your infrastructure | Managed service |\n| Updates | Manual | Automatic |\n| Latency | Depends on your setup | Optimized global CDN |\n\n## 🧩 Integration with plugged.in MCP Proxy\n\nThe plugged.in App is designed to work seamlessly with the [plugged.in MCP Proxy](https://github.com/VeriTeknik/pluggedin-mcp), which provides:\n\n- A unified interface for all MCP clients\n- Tool discovery and reporting\n- Request routing to the appropriate MCP servers\n- Support for the latest MCP specification including Streamable HTTP transport\n- Compatible with STDIO, SSE, and Streamable HTTP server types\n\n## 📚 Related Resources\n\n- [plugged.in MCP Proxy Repository](https://github.com/VeriTeknik/pluggedin-mcp)\n- [Model Context Protocol (MCP) Specification](https://modelcontextprotocol.io/)\n- [Claude Desktop Documentation](https://docs.anthropic.com/claude/docs/claude-desktop)\n- [Cline Documentation](https://docs.cline.bot/)\n\n## 🤝 Contributing\n\nContributions are welcome! Please feel free to submit a Pull Request.\n\n## 📄 License\n\nThis project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.\n\n## 🔮 Roadmap\n\nThe plugged.in project is actively developing several exciting features:\n\n- **Testing Infrastructure**: Comprehensive test coverage for core functionality\n- **Playground Optimizations**: Improved performance for log handling\n- **Embedded Chat (Phase 2)**: Generate revenue through embeddable AI chat interfaces\n- **AI Assistant Platform (Phase 3)**: Create a social network of specialized AI assistants\n- **Privacy-Focused Infrastructure (Phase 4)**: Dedicated RAG servers and distributed GPU services\n- **Retrieval-Augmented Generation (RAG)**: Integration with vector databases like Milvus\n- **Collaboration \u0026 Sharing**: Multi-user sessions and embeddable chat widgets\n\n## 📝 Recent Updates\n\n### Latest Development\n\n#### 🚀 Streamable HTTP Transport Support\n\n- **Full MCP Streamable HTTP Support**: Added support for the new MCP Streamable HTTP transport protocol\n- **OAuth 2.1 Integration**: Support for OAuth-based authentication flows\n- **Enhanced Configuration**: Custom headers and session management for Streamable HTTP servers\n- **Multi-Language Support**: Updated translations for all supported languages\n\nSee [CHANGELOG.md](./CHANGELOG.md) for the latest updates.\n\n### Version 2.1.0 (June 2025)\n\n#### 🎯 Major Features\n\n- **Document Library with RAG Integration**: Upload and manage documents that enhance AI context\n- **Real-Time Notification System**: Get instant updates on MCP activities with email support\n- **Progressive Server Initialization**: Faster, more resilient MCP server connections\n- **Enhanced Playground UI**: Redesigned layout with better responsiveness and streaming indicators\n\n#### 🔒 Security Enhancements\n\n- **Improved RAG Query Security**: Replaced custom sanitization with `sanitize-html` library for robust XSS protection\n- **Secure Environment Variable Parsing**: Implemented `dotenv` library for proper handling of quotes, multiline values, and special characters\n- **Enhanced Input Validation**: Added comprehensive validation for all user inputs across the application\n- **Strengthened API Security**: Implemented rate limiting and improved authentication checks\n\n#### 🐛 Bug Fixes\n\n- Fixed JSON-RPC protocol interference in MCP proxy\n- Resolved memory leaks in long-running playground sessions\n- Corrected streaming message handling\n- Fixed localhost URL validation for development environments\n\nSee [Release Notes](./RELEASE_NOTES_v2.1.0.md) for complete details.\n\n## Discovery Performance Optimizations\n\n### Smart Discovery Throttling\nThe app now includes intelligent throttling mechanisms to prevent redundant discovery calls:\n\n- **Tools API (`/api/tools`)**: Implements 5-minute throttling to avoid repeated discovery attempts\n- **Discovery API (`/api/discover`)**: Uses 2-minute throttling for explicit discovery requests\n- **In-memory caching**: Tracks recent discovery attempts to prevent duplicate calls\n- **Failure recovery**: Clears throttle cache on discovery failures to allow faster retries\n\n### Optimized Database Queries\n- **Single query optimization**: Fetches server data and tool counts in one query using LEFT JOIN\n- **Reduced database load**: Eliminates redundant tool count queries\n- **Indexed lookups**: Uses existing database indexes for faster server and tool queries\n\n### Background Processing\n- **Asynchronous discovery**: All discovery processes run in background without blocking API responses\n- **Error handling**: Comprehensive error handling with automatic retry mechanisms\n- **Status tracking**: Provides clear feedback on discovery progress and throttling status\n\n### Performance Benefits\n- **Reduced API latency**: Faster response times for tools API calls\n- **Lower database load**: Fewer redundant queries and optimized data fetching\n- **Better user experience**: Prevents duplicate work and provides instant feedback\n- **Scalable architecture**: Can handle multiple concurrent discovery requests efficiently\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FVeriTeknik%2Fpluggedin-app","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FVeriTeknik%2Fpluggedin-app","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FVeriTeknik%2Fpluggedin-app/lists"}