PluginBench
MCP Server
Active
Apache-2.0

io.github.navapbc/rebar MCP Server

io.github.navapbc/rebar

What is the io.github.navapbc/rebar MCP server?

Event-sourced ticket tracker + Jira reconciler, exposed as a Python library, CLI, and MCP server.

How to install io.github.navapbc/rebar

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • REBAR_ROOT

    Path to the repo root that holds the .tickets-tracker store (defaults to the git toplevel of the working dir).

  • REBAR_MCP_READONLY

    Set to 1 to expose only the read tools (no write/mutation tools).

  • REBAR_MCP_ALLOW_LLM

    Set to 1 to enable the billable LLM tools (review_code / scan_spec / verify_completion / review_plan); off by default.

  • REBAR_MCP_ALLOW_JIRA_SYNC

    Set to 1 to allow the live (mutating) Jira reconcile mode; otherwise reconcile is dry-run only.

  • REBAR_MCP_TRANSPORT

    Transport for the MCP server: 'stdio' (default) or 'http' (the optional Streamable-HTTP transport).

  • REBAR_MCP_HTTP_HOST

    Bind host for the Streamable-HTTP transport (default 127.0.0.1).

  • REBAR_MCP_HTTP_PORT

    Bind port for the Streamable-HTTP transport (1-65535; default 8000).

  • REBAR_MCP_HTTP_PATH

    URL path the Streamable-HTTP transport serves on (default /mcp).

  • REBAR_MCP_HTTP_ALLOWED_HOSTS

    Comma-separated allowlist of exact host:port values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback.

  • REBAR_MCP_HTTP_ALLOWED_ORIGINS

    Comma-separated allowlist of exact Origin values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback.

  • REBAR_MCP_HTTP_TLS_AT_EDGE

    Set to 1 to acknowledge TLS is terminated at the edge; required to bind the Streamable-HTTP transport to a non-loopback host.

  • REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP

    Set to 1 to acknowledge running the Streamable-HTTP transport without a token verifier; required to boot the HTTP transport while auth is off.

  • REBAR_MCP_AUTH_ENABLED

    Set to 1 to enable MCP authentication (the composite token verifier + Resource-Server wiring); off by default.

  • REBAR_MCP_AUTH_STRATEGIES

    Comma-separated, ordered list of token-verifier strategies to compose (closed set: static, jwt, introspection, proxy, custom).

  • REBAR_MCP_AUTH_ISSUER_URL

    OAuth authorization-server issuer URL advertised in the Protected-Resource Metadata (RFC 9728) when auth is enabled.

  • REBAR_MCP_AUTH_RESOURCE_SERVER_URL

    The single resource identifier (RFC 8707 audience) for this server; the composite verifier re-checks every accepted token against it.

  • REBAR_MCP_AUTH_REQUIRED_SCOPES

    Comma-separated scopes a caller must hold; the SDK returns 403 insufficient_scope when a principal lacks one.

  • REBAR_MCP_AUTH_STATIC_TOKENS_FILE

    Path to the JSON secrets file for the static-bearer verifier (stores only SHA-256 digests of the accepted tokens).

  • REBAR_MCP_AUTH_JWT_JWKS_URI

    HTTPS JWKS endpoint the `jwt` verifier fetches signing keys from (an OIDC provider's .well-known/jwks.json).

  • REBAR_MCP_AUTH_JWT_ISSUER

    Expected `iss` claim for the `jwt` verifier; falls back to REBAR_MCP_AUTH_ISSUER_URL when unset.

  • REBAR_MCP_AUTH_JWT_ALGORITHMS

    Comma-separated PINNED, asymmetric-only JWS algorithms for the `jwt` verifier (default RS256,ES256); a symmetric algorithm on a JWKS source is refused.

  • REBAR_MCP_AUTH_JWT_LEEWAY

    Clock-skew leeway in seconds applied to exp/nbf validation by the `jwt` verifier (default 60).

  • REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN

    Minimum seconds between JWKS refetches triggered by an unknown key id (the concurrency-safe flood guard; default 30).

  • REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT

    HTTP timeout in seconds for the `jwt` verifier's JWKS fetch (default 10).

  • REBAR_MCP_AUTH_JWT_EXPECTED_TYP

    When set, the `jwt` verifier requires the JWT header `typ` to equal this (e.g. at+JWT per RFC 9068); unset skips the check.

  • REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST

    Set to 1 to permit a private/link-local/loopback JWKS host (SSRF guard is on by default); off by default.

  • REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT

    The `introspection` verifier's RFC 7662 endpoint URL (must be https://); the opaque token is POSTed here on every request (no caching).

  • REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID

    The client id the `introspection` verifier presents to the Authorization Server via HTTP Basic (client_secret_basic).

  • REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV

    The NAME of the env var holding the introspection client secret (never the secret itself); must be present + non-empty at startup or the server refuses to start (fail-closed).

  • REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST

    Set to 1 to permit a private/link-local/loopback introspection endpoint host (SSRF guard is on by default); off by default.

  • REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD

    Set to 1 to accept an active introspection response that OMITS `aud` (many AS do); off by default (fail-closed reject).

  • REBAR_MCP_AUTH_PROXY_SECRET_ENV

    The NAME of the env var holding the trusted-proxy shared secret (never the secret itself); must be present + non-empty at startup or the `proxy` verifier refuses to start (fail-closed).

  • REBAR_MCP_AUTH_PROXY_SECRET_HEADER

    The header the fronting proxy sends its shared secret on; the identity is trusted only when this matches (constant-time; default x-proxy-auth).

  • REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER

    The header carrying the proxy-authenticated principal identity, trusted only when the secret header validates (default x-forwarded-user).

  • REBAR_MCP_AUTH_PROXY_SCOPES

    Comma-separated fixed scope set granted to proxy-authenticated principals; empty by default (the principal holds no scopes).

  • REBAR_MCP_AUTH_CUSTOM_IMPORT

    The `custom` strategy's `module:factory` import string, resolving to a factory that returns a TokenVerifier; a TRUSTED operator config value that loads and executes the operator-configured code at startup (fail-closed on any load error).

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ],
      "env": {
        "REBAR_ROOT": "<YOUR_REBAR_ROOT>",
        "REBAR_MCP_READONLY": "<YOUR_REBAR_MCP_READONLY>",
        "REBAR_MCP_ALLOW_LLM": "<YOUR_REBAR_MCP_ALLOW_LLM>",
        "REBAR_MCP_ALLOW_JIRA_SYNC": "<YOUR_REBAR_MCP_ALLOW_JIRA_SYNC>",
        "REBAR_MCP_TRANSPORT": "<YOUR_REBAR_MCP_TRANSPORT>",
        "REBAR_MCP_HTTP_HOST": "<YOUR_REBAR_MCP_HTTP_HOST>",
        "REBAR_MCP_HTTP_PORT": "<YOUR_REBAR_MCP_HTTP_PORT>",
        "REBAR_MCP_HTTP_PATH": "<YOUR_REBAR_MCP_HTTP_PATH>",
        "REBAR_MCP_HTTP_ALLOWED_HOSTS": "<YOUR_REBAR_MCP_HTTP_ALLOWED_HOSTS>",
        "REBAR_MCP_HTTP_ALLOWED_ORIGINS": "<YOUR_REBAR_MCP_HTTP_ALLOWED_ORIGINS>",
        "REBAR_MCP_HTTP_TLS_AT_EDGE": "<YOUR_REBAR_MCP_HTTP_TLS_AT_EDGE>",
        "REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP": "<YOUR_REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP>",
        "REBAR_MCP_AUTH_ENABLED": "<YOUR_REBAR_MCP_AUTH_ENABLED>",
        "REBAR_MCP_AUTH_STRATEGIES": "<YOUR_REBAR_MCP_AUTH_STRATEGIES>",
        "REBAR_MCP_AUTH_ISSUER_URL": "<YOUR_REBAR_MCP_AUTH_ISSUER_URL>",
        "REBAR_MCP_AUTH_RESOURCE_SERVER_URL": "<YOUR_REBAR_MCP_AUTH_RESOURCE_SERVER_URL>",
        "REBAR_MCP_AUTH_REQUIRED_SCOPES": "<YOUR_REBAR_MCP_AUTH_REQUIRED_SCOPES>",
        "REBAR_MCP_AUTH_STATIC_TOKENS_FILE": "<YOUR_REBAR_MCP_AUTH_STATIC_TOKENS_FILE>",
        "REBAR_MCP_AUTH_JWT_JWKS_URI": "<YOUR_REBAR_MCP_AUTH_JWT_JWKS_URI>",
        "REBAR_MCP_AUTH_JWT_ISSUER": "<YOUR_REBAR_MCP_AUTH_JWT_ISSUER>",
        "REBAR_MCP_AUTH_JWT_ALGORITHMS": "<YOUR_REBAR_MCP_AUTH_JWT_ALGORITHMS>",
        "REBAR_MCP_AUTH_JWT_LEEWAY": "<YOUR_REBAR_MCP_AUTH_JWT_LEEWAY>",
        "REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN": "<YOUR_REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN>",
        "REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT": "<YOUR_REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT>",
        "REBAR_MCP_AUTH_JWT_EXPECTED_TYP": "<YOUR_REBAR_MCP_AUTH_JWT_EXPECTED_TYP>",
        "REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST": "<YOUR_REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST>",
        "REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT": "<YOUR_REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT>",
        "REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID": "<YOUR_REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID>",
        "REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV": "<YOUR_REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV>",
        "REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST": "<YOUR_REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST>",
        "REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD": "<YOUR_REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD>",
        "REBAR_MCP_AUTH_PROXY_SECRET_ENV": "<YOUR_REBAR_MCP_AUTH_PROXY_SECRET_ENV>",
        "REBAR_MCP_AUTH_PROXY_SECRET_HEADER": "<YOUR_REBAR_MCP_AUTH_PROXY_SECRET_HEADER>",
        "REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER": "<YOUR_REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER>",
        "REBAR_MCP_AUTH_PROXY_SCOPES": "<YOUR_REBAR_MCP_AUTH_PROXY_SCOPES>",
        "REBAR_MCP_AUTH_CUSTOM_IMPORT": "<YOUR_REBAR_MCP_AUTH_CUSTOM_IMPORT>"
      }
    }
  }
}

Related MCP servers

Grocery meal planning, budgets, and flyer deals for Canadian households. Auth required.

0

Canadian grocery flyer deals and recipes by item, store, postal code, cuisine, or diet. No auth.

FOForemerge logo

Foremerge

Active

Coordination protocol for parallel coding agents that detects intent conflicts before code conflicts using Git worktrees and semantic declarations.

521
Rust
Apache-2.0
View repository →

Read and search FranklyMail email and prepare drafts, replies, and forwards for human approval.

View repository →

Self-hosted MCP server for Android Health Connect — 34 metrics, daily rollups, dedup, 5 LLM tools.

1
Python
MIT
View repository →

Self-hosted remote MCP memory server for ChatGPT and AI agents.

2
TypeScript
MIT
View repository →