MCP Server
MCP
OPA MCP
Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client.
Install
npx -y @orygn/[email protected]
Configuration Example
{
"remotes": [],
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@orygn/opa-mcp",
"version": "0.3.0",
"runtimeHint": "npx",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Base URL of a running OPA server. Required only for opa_* runtime tools, not for rego_* language tools.",
"default": "http://localhost:8181",
"name": "OPA_URL"
},
{
"description": "Bearer token for OPA running with --authentication=token.",
"isSecret": true,
"name": "OPA_TOKEN"
},
{
"description": "Path to the opa binary. Defaults to 'opa' on PATH.",
"default": "opa",
"name": "OPA_BINARY"
},
{
"description": "Path to the regal binary (optional, used by rego_lint). Defaults to 'regal' on PATH.",
"default": "regal",
"name": "REGAL_BINARY"
},
{
"description": "Path to the conftest binary (optional, used by conftest_* tools). Defaults to 'conftest' on PATH.",
"default": "conftest",
"name": "CONFTEST_BINARY"
},
{
"description": "Comma-separated list of root directories tools may read/write. When unset, file-based tools refuse to access the disk.",
"name": "OPA_MCP_ALLOWED_PATHS"
},
{
"description": "GitHub personal access token with the \"gist\" scope. Required only for rego_playground_share.",
"isSecret": true,
"name": "GITHUB_TOKEN"
}
]
},
{
"registryType": "oci",
"identifier": "docker.io/orygn/opa-mcp:0.3.0",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Base URL of a running OPA server.",
"default": "http://host.docker.internal:8181",
"name": "OPA_URL"
},
{
"description": "Bearer token for OPA authentication.",
"isSecret": true,
"name": "OPA_TOKEN"
},
{
"description": "GitHub personal access token with the \"gist\" scope. Required only for rego_playground_share.",
"isSecret": true,
"name": "GITHUB_TOKEN"
}
]
}
]
}
mcp
model-context-protocol
npm
oci
By
Comments
Sign in to leave a comment