Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

MCPO — Model Context Protocol Orchestrator

Purpose

Orchestrates Model Context Protocol (MCP) servers, providing a centralized way to manage and expose multiple MCP servers.

Entry Point

Options

services.mcpo.apiTokenFile

Typenull or absolute path
Defaultnull

Path to a file containing the API token for the mcpo service. This file will be exposed to the service through a systemd credential named “apiToken”.


services.mcpo.configuration

Typeattribute set of (submodule)
Default{ }

This option has no description.


services.mcpo.configuration.<name>.args

Typelist of string
Default[ ]

Arguments to pass to the command.


services.mcpo.configuration.<name>.command

Typenull or string
Defaultnull

Command to render the config file.


services.mcpo.configuration.<name>.headers

Typeattribute set of string
Default{ }

Headers to pass to the command.


services.mcpo.configuration.<name>.type

Typenull or one of "sse", "streamable-http"
Defaultnull

This option has no description.


services.mcpo.configuration.<name>.url

Typenull or string
Defaultnull

This option has no description.


services.mcpo.enable

Typeboolean
Defaultfalse
Exampletrue

Whether to enable mcpo (Model Context Protocol Orchestrator) service.


services.mcpo.environment

Typeattribute set of string
Default{ }

Additional environment variables for the service.


services.mcpo.extraPackages

Typelist of package
Default[ ]

Additional packages to include in the service’s PATH.


services.mcpo.helpers

Typeattribute set
Default{ npxServer = <function>; npxServerWithArgs = <function>; uvxServer = <function>; uvxServerWithArgs = <function>; }

Helper functions for constructing mcpo server command blocks.


services.mcpo.package

Typepackage
Default<derivation mcpo-0.0.18>

Package providing the mcpo executable.


Architecture / Services / Scope

MCPO runs as a DynamicUser with a state directory at /var/lib/mcpo. The configuration is rendered via sops.templates and loaded into the service via systemd credentials. The service’s PATH includes bash, nodejs, and uv by default to support various MCP server types; additional packages can be added with services.mcpo.extraPackages.

Secrets

  • apiTokenFile (optional) — API token exposed to the service as the systemd credential apiToken.
  • Server configuration and environment are rendered through sops templates (mcpoConfiguration, mcpoEnvironment) and consumed via LoadCredential / EnvironmentFile.

Operational Notes / Assumptions

Usage Example

{ config, ... }: {
  services.mcpo = {
    enable = true;
    configuration = {
      everything = config.services.mcpo.helpers.npxServer "@modelcontextprotocol/server-everything";
    };
  };
}

Package Patches

  • mcpo-union-repr-compat.patch — Applied via overlay in overlays/patches/. Upstream test src/mcpo/tests/test_main.py asserts Union repr starts with "typing.Union[", but Python 3.12+ may stringify unions as str | float. Patch uses get_origin(result_type) is Union instead. Build/test compatibility only; no runtime impact.

References