CAPI Gateway MCP Server
io.github.surisoft-io/capi-core
Lightweight API Gateway with REST-to-MCP bridging for LLM agents via Apache Camel and Consul service discovery.
What is the CAPI Gateway MCP server?
The CAPI Gateway MCP server is a lightweight API Gateway built on Undertow that bridges REST APIs to the Model Context Protocol, enabling LLM agents to discover and invoke existing REST services as MCP tools without backend code changes. It uses HashiCorp Consul for automatic service discovery and supports OAuth2/OIDC authentication, distributed throttling, and observability features.
CAPI Gateway turns any existing REST API into an MCP tool that LLM agents like Claude and Cursor can discover and invoke. Services register themselves in Consul with MCP metadata, and CAPI automatically creates proxy handlers, applies security policies, and exposes them as a unified MCP endpoint. It also supports real MCP Server backends, aggregating both REST and native MCP services under one interface.
How to install CAPI Gateway
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
REST-to-MCP Bridging— Converts REST API endpoints into MCP tools discoverable by LLM agents via JSON-RPC 2.0 over HTTPService Discovery— Automatic service registration and route creation via HashiCorp ConsulOAuth2/OIDC Authentication— Multi-provider token validation with cookie-based auth supportAPI Key Authentication— Per-key throttling via Consul KVAuthorization— Fine-grained access control via Open Policy Agent (OPA)Distributed Throttling— Rate limiting with Hazelcast backend and Kubernetes discoveryLoad Balancing— Round Robin load balancing with failover supportDistributed Tracing— OpenTelemetry/OTLP integration for observabilityMetrics— Prometheus metrics collectionAdmin API— Health checks, metrics, and route inspection endpoints
Use cases
- Expose legacy REST APIs as MCP tools for Claude Desktop and Cursor without modifying backend code
- Aggregate multiple microservices into a single MCP endpoint for LLM agent discovery and invocation
- Implement OAuth2/OIDC authentication and per-API-key rate limiting across all exposed services
- Monitor API gateway performance and service health via Prometheus metrics and distributed tracing
- Route requests to gRPC or MCP Server backends transparently alongside REST services
CAPI Gateway MCP server FAQ
CAPI is a lightweight API Gateway that bridges REST APIs to the Model Context Protocol, allowing LLM agents to discover and call existing REST services as MCP tools without any backend code changes. It uses Consul for service discovery and handles authentication, throttling, and observability.
Yes, CAPI is open-source under the Apache 2.0 license.
CAPI runs as a Docker container or JAR. Set the CAPI_CONFIG_FILE environment variable to point to a YAML configuration file, then run `docker run -p 8380:8380 -p 8381:8381 -v $(pwd)/config/config.yaml:/capi/config/config.yaml -e CAPI_CONFIG_FILE=/capi/config/config.yaml surisoft/capi-core` or use the provided Helm chart for Kubernetes.
CAPI supports OAuth2/OIDC token validation (multi-provider with cookie-based auth) and API Key authentication with per-key throttling via Consul KV.
No, CAPI uses HashiCorp Consul for service discovery and configuration storage, with no separate database required.
CAPI listens on port 8380 (REST gateway), 8381 (admin/metrics), 8382 (WebSocket), 8383 (MCP Gateway), and 8384 (gRPC Gateway).
README (reference)
Source of truth, from the repository.
CAPI Gateway
Lightweight API Gateway
CAPI is a lightweight API Gateway and load balancer built on Undertow's async proxy architecture. Services register themselves in HashiCorp Consul, and CAPI automatically discovers them, creates proxy handlers, and applies security, throttling, and observability policies — no database required.
Features
- REST, WebSocket, and SSE gateway with fully async proxying (zero threads blocked during backend calls)
- Service discovery via HashiCorp Consul (automatic route creation and removal)
- OAuth2 / OIDC token validation (multi-provider, cookie-based auth supported)
- API Key authentication with per-key throttling (via Consul KV)
- Fine-grained authorization via OPA (Open Policy Agent, async policy evaluation)
- Distributed throttling (Hazelcast, with Kubernetes discovery)
- Load balancing (Round Robin) and Failover
- Distributed tracing (OpenTelemetry / OTLP)
- Prometheus metrics
- OpenAPI spec aggregation from upstream services
- TLS termination and dynamic truststore management (via Consul KV hot-reload)
- CORS management
- Admin API with health, metrics, and route inspection
- Multi-instance support (route targeting per CAPI instance)
- Reverse proxy headers (
X-Forwarded-*) - [Experimental] MCP Gateway — expose services as MCP tools for LLM agents (JSON-RPC 2.0 over Streamable HTTP)
- [Experimental] gRPC Gateway — transparent HTTP/2 reverse proxy for gRPC services with header-based routing
REST-to-MCP Bridging
CAPI's MCP Gateway turns any existing REST API into an MCP tool — no code changes on your backends.
Register a service in Consul with MCP metadata, and LLM agents (Claude Desktop, Cursor, custom agents) can discover and invoke it immediately. Your REST services don't need to know anything about MCP, JSON-RPC, or tool schemas. CAPI handles the translation:
LLM Agent CAPI Your REST API
(unchanged)
tools/list ──────────────► reads Consul metadata
◄────────────── returns tool catalog
tools/call ──────────────► extracts arguments
{"name":"..."} POST /endpoint ──────────────► handles request
wraps response ◄────────────── returns JSON
◄────────────── MCP-formatted result
CAPI also supports real MCP Server backends — services that already speak JSON-RPC 2.0. Register them with mcp-type: server and CAPI discovers their tools automatically via tools/list, then proxies tools/call requests transparently. Both REST and MCP Server backends are aggregated under one unified MCP endpoint.
Unlike dedicated MCP gateways that require all backends to be MCP Servers, CAPI bridges the gap between existing REST infrastructure and LLM-native protocols. See the MCP Gateway docs and the demo for a working example with both backend types.
Quickstart
CAPI requires the CAPI_CONFIG_FILE environment variable pointing to a valid configuration file.
Running from JAR
CAPI_CONFIG_FILE=config/config.yaml java -jar capi-core.jar
Running with Docker
docker run -p 8380:8380 -p 8381:8381 \
-v $(pwd)/config/config.yaml:/capi/config/config.yaml \
-e CAPI_CONFIG_FILE=/capi/config/config.yaml \
surisoft/capi-core
Running with Helm (Kubernetes)
A Helm chart is available in helm/capi-core/.
helm install capi-core helm/capi-core
# With custom values
helm install capi-core helm/capi-core -f my-values.yaml
# Enable SSL and truststore
helm install capi-core helm/capi-core \
--set capi.ssl.enabled=true \
--set capi.ssl.keystoreBase64=<base64-encoded-keystore> \
--set capi.ssl.password=changeit
See helm/capi-core/values.yaml for all available configuration options.
Ports
| Port | Description | Config key |
|---|---|---|
| 8380 | REST API gateway | capi.rest.port |
| 8381 | Admin / metrics | capi.adminPort |
| 8382 | WebSocket gateway | capi.websocket.port |
| 8383 | MCP Gateway (experimental) | capi.mcp.port |
| 8384 | gRPC Gateway (experimental) | capi.grpc.port |
Running Modes
The runningMode field controls which types of services CAPI will proxy:
| Mode | Description |
|---|---|
full | Proxies REST, WebSocket, and SSE services (default) |
websocket | Only proxies WebSocket services |
sse | Only proxies SSE services |
Documentation
| Document | Description |
|---|---|
| Service Registration | How to register services in Consul and configure routing, security, and throttling via metadata |
| Security | OAuth2/OIDC and OPA authorization configuration |
| Admin API | Admin endpoints reference (health, metrics, routes, OpenAPI) |
| Configuration Reference | Complete YAML configuration reference with all fields |
| MCP Gateway (Experimental) | MCP Gateway for LLM tool integration via JSON-RPC 2.0 |
| gRPC Gateway (Experimental) | Transparent gRPC reverse proxy with header-based routing |
Related MCP servers
Knowledge accumulation for AI coding agents. Records decisions, problems, and insights as context.
View repository →
Agent Almanac MCP
Search the Agent Almanac catalog of 9,000+ MCP servers from inside any MCP-aware agent.
40 MCP tools for 11 Indonesian government portals — BPOM, BPJPH, AHU, OJK, BMKG+
Watch US federal court cases for new filings and keep a Case Passport any AI assistant can load.

io.github.sustinbebustin/citadel-mcp
A growing Citadel of stack-specific docs, served as MCP tools for AI coding agents.

Codex Reset
Read-only Codex usage-limit reset data: 24/48h reset forecast, dated reset record, service status.

