Stdio + HTTP MCP gateway: SSRF-hardened web_fetch, web_search, metis_verify, market_search.
📖 Read-only mirror.
aimarket-mcpis published from the canonical AI-Factory monorepo. Pull requests are not accepted — any commit pushed here is overwritten byscripts/mirror_satellites.shon the next sync. 🐞 Found a bug or have a request? Please open an issue.
🟢 Just want to try the marketplace? Install nothing.
Paste
https://modelmarket.dev/mcpinto your MCP client and you havemarket_search
market_invokeagainst the live hub, with a few free trial invokes per caller and a signed receipt for each — no wallet, no key, no install. →docs/hosted-mcp-endpoint.mdInstall this package when you want the other three tools (
web_fetch,web_search,metis_verify), or want to point the market tools at a hub of your own.
One MCP gateway. Five hardened tools. Shared by Metis, ARGUS, and the ecosystem.
Transport: stdio (aimarket_mcp/stdio_server.py) for Glama / Claude Desktop / Cursor, built with the
official Model Context Protocol Python SDK (mcp, FastMCP).
Also ships Streamable-HTTP on :9090 for self-hosted deployments (aimarket-mcp-http, Docker Compose).
| Item | Location |
|---|---|
| MCP entrypoint (stdio) | aimarket_mcp/stdio_server.py |
| MCP gateway (HTTP) | aimarket_mcp/server.py |
| Tool handlers + security | aimarket_mcp/tools.py, aimarket_mcp/security.py |
| Glama / Docker (stdio) | Dockerfile, glama.json |
| Self-host HTTP | Dockerfile.http, docker-compose.yml |
Compatible hosts: Claude Desktop, Cursor, Glama, and any MCP client that supports stdio or Streamable-HTTP.
| Tool | What it does | Hardening |
|---|---|---|
web_fetch | Fetch a URL, return main text (readability-lite) | SSRF-guarded; output sanitized + <untrusted>-wrapped |
web_search | Live DuckDuckGo search → top snippets | output sanitized + <untrusted> |
metis_verify | Metis cognition + verification envelope | returns answer + verify_score / verified gate |
market_search | Discover priced capabilities on an AIMarket hub | free; no wallet, key or channel; the hub lists only what it can execute |
market_invoke | Run one on the hub's free trial tier | returns the signed receipt nonce; reports the hub's 402 verbatim when the allowance is spent |
market_search_tool(intent="gaia weather open-meteo")
market_invoke_tool(
capability_id="gaia.weather.read@v1",
product_id="gaia.gateway",
source_hub="https://iot.modelmarket.dev",
# input JSON with device_id om-wx-01 — see tool schema / hub docs
)
Or the same HTTP the tool wraps:
curl -s -X POST "${AIMARKET_HUB_URL:-https://modelmarket.dev}/ai-market/v2/invoke" \
-H 'Content-Type: application/json' \
-H 'X-AIMarket-Sandbox-Visitor: vis_mcp_om_wx' \
-d '{"capability_id":"gaia.weather.read@v1","product_id":"gaia.gateway",
"source_hub":"https://iot.modelmarket.dev","input":{"device_id":"om-wx-01"}}'
That is the easy path (trial/sandbox). Proving an external wallet paid on-chain
is a separate escrow flow (openChannel → DebitAuthorization → hub debit/settle) —
see docs/onchain-journal.md §3l–§3m and
gaia/docs/LIVE-RELAYS.md.
Why a gateway (not per-agent tools): generic capabilities are written once; the security core lives in one audited place. Ecosystem-specific capabilities live in their own MCP servers (aimarket-oracle-gateway, aimarket-plugins).
| var | meaning |
|---|---|
AIMARKET_METIS_URL | Metis verify API base (default https://metis.modelmarket.dev) |
AIMARKET_METIS_KEY | optional bearer for Metis verify |
AIMARKET_SEARCH_URL | DuckDuckGo HTML endpoint override |
AIMARKET_HUB_URL | AIMarket hub for market_search / market_invoke (default https://modelmarket.dev) |
AIMARKET_SANDBOX_VISITOR | Trial identity for market_invoke; random per install, set it to keep an allowance across reinstalls |
AIMARKET_MCP_KEY | HTTP only — bearer auth key |
AIMARKET_MCP_PRODUCTION | HTTP only — 1 requires AIMARKET_MCP_KEY (fail-closed) |
AIMARKET_MCP_RATE | HTTP only — requests/min per key/IP (default 120) |
AIMARKET_MCP_PORT | HTTP only — listen port (default 9090) |
Claude Desktop (mcpServers entry) — no clone, no working directory to get wrong:
{
"mcpServers": {
"aimarket-mcp": {
"command": "uvx",
"args": ["aimarket-mcp"]
}
}
}
uvx fetches the published package and runs its aimarket-mcp console script, which is
the stdio server. With the package already installed, "command": "aimarket-mcp" and no
args does the same thing.
From a checkout, for development:
pip install -e .
python -m aimarket_mcp.stdio_server
pip install -e .
AIMARKET_MCP_KEY=sk-... AIMARKET_MCP_PRODUCTION=1 aimarket-mcp-http # :9090
# or: docker compose up -d (uses Dockerfile.http)
{
"mcpServers": {
"aimarket-web": {
"type": "streamable-http",
"url": "http://127.0.0.1:9090/mcp",
"headers": {
"Authorization": "Bearer YOUR_AIMARKET_MCP_KEY"
}
}
}
}
Listing: glama.ai/mcp/servers/alexar76/aimarket-mcp
Same pattern as aimarket-oracle-gateway (working on Glama): repo-root glama.json + Dockerfile + python -m aimarket_mcp.stdio_server.
| Field | Value |
|---|---|
| Dockerfile | Dockerfile (from repo — not Glama debian/uv template) |
| Command | python -m aimarket_mcp.stdio_server |
| Placeholder parameters | {} |
| Pinned SHA | empty (latest) |
Do not use the auto-generated debian:trixie-slim + uv sync + mcp-proxy -- aimarket-mcp template — that was the broken HTTP/ENOENT path.
enable_mcp_tools: true
mcp_ecosystem_presets: [aimarket-web]
argus.config.json mcpServers (see that repo).pip install -e '.[dev]' && pytest -q
Glama ignores repo Dockerfiles — set Build steps in admin/dockerfile:
["bash scripts/glama_install.sh"]
CMD: [".venv/bin/python", "-m", "aimarket_mcp.stdio_server"]. Pin main or tag glama-build (not a
fixed SHA). Details: docs/GLAMA.md.
| Registry | Listing |
|---|---|
| Glama | glama.ai/mcp/servers/alexar76/aimarket-mcp |
| Official MCP Registry | io.github.alexar76/aimarket-mcp — server.json + GitHub Actions |
| PyPI | pip install aimarket-mcp |
| GitHub Releases | github.com/alexar76/aimarket-mcp/releases |
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx aimarket-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-alexar76-aimarket-mcp": {
"command": "uvx",
"args": [
"aimarket-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceAIMarket MCP Gateway works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.