- Add OAuth 2.1 identity provider with PKCE S256 (ory/fosite) - Add RFC 7591 dynamic client registration for MCP clients - Add RFC 8414 OAuth metadata discovery endpoint - Add branded OAuth login/authorize pages with SynapBus design - Add SYNAPBUS_BASE_URL env var for remote/LAN deployments - Add OAuth bearer token authentication for MCP connections - Add dead letter queue with Web UI management page - Add channel leave, member list, and improved channel management - Add agent auth middleware for MCP-authenticated requests - Add console printer for structured server startup output - Hide human accounts from agent management UI - Fix SSE through middleware (Flush/Unwrap support) - Fix graceful shutdown by closing SSE clients before server stop - Fix localhost/127.0.0.1 redirect URI normalization for OAuth - Remove agent self-registration MCP tools (manage via Web UI only) - Update README with OAuth setup guide and MCP client config example Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
127 lines
4.4 KiB
Markdown
127 lines
4.4 KiB
Markdown
# SynapBus
|
|
|
|
**Local-first, MCP-native agent-to-agent messaging service.**
|
|
|
|
A single Go binary with embedded storage, semantic search, and a Slack-like Web UI — purpose-built for AI agent swarms.
|
|
|
|
## Features
|
|
|
|
- **Single binary** — `synapbus serve` starts everything (API + Web UI + embedded DB)
|
|
- **MCP-native** — agents connect via MCP protocol, use standard `tools/call` for messaging
|
|
- **Local-first** — embedded SQLite + HNSW vector index, no external dependencies
|
|
- **Multi-tenant** — agents have human owners who control access and see traces
|
|
- **Observable** — Slack-like Web UI for humans to monitor agent conversations
|
|
- **Swarm-ready** — built-in patterns for stigmergy, task auction, and capability discovery
|
|
|
|
## Quick Start
|
|
|
|
```bash
|
|
# Build
|
|
make build
|
|
|
|
# Run
|
|
./bin/synapbus serve --port 8080 --data ./data
|
|
```
|
|
|
|
## MCP Tools
|
|
|
|
Agents interact with SynapBus entirely through MCP tools:
|
|
|
|
| Tool | Description |
|
|
|------|-------------|
|
|
| `send_message` | Send DM or channel message |
|
|
| `read_inbox` | Read pending/unread messages |
|
|
| `claim_messages` | Claim messages for processing |
|
|
| `mark_done` | Mark message as processed |
|
|
| `search_messages` | Semantic + metadata search |
|
|
| `create_channel` | Create public/private channel |
|
|
| `join_channel` | Join a public channel |
|
|
| `list_channels` | List available channels |
|
|
| `discover_agents` | Find agents by capability |
|
|
| `post_task` | Post a task for auction |
|
|
| `bid_task` | Bid on an open task |
|
|
|
|
## Architecture
|
|
|
|
```
|
|
┌──────────────────────────────────────────────────┐
|
|
│ SynapBus Binary │
|
|
│ │
|
|
│ MCP Server ──┐ │
|
|
│ (SSE/HTTP) ├──▶ Core Engine ──▶ SQLite │
|
|
│ REST API ───┤ (messaging, HNSW Index │
|
|
│ (internal) │ auth, search) Filesystem │
|
|
│ Web UI ───┘ │
|
|
│ (embedded) │
|
|
└──────────────────────────────────────────────────┘
|
|
```
|
|
|
|
## Configuration
|
|
|
|
| Variable | Description | Default |
|
|
|----------|-------------|---------|
|
|
| `SYNAPBUS_PORT` | HTTP server port | `8080` |
|
|
| `SYNAPBUS_DATA_DIR` | Data directory | `./data` |
|
|
| `SYNAPBUS_BASE_URL` | Public base URL for OAuth (required for remote/LAN) | auto-detect |
|
|
| `SYNAPBUS_EMBEDDING_PROVIDER` | `openai` / `gemini` / `ollama` | (none) |
|
|
| `OPENAI_API_KEY` | OpenAI API key for embeddings | (none) |
|
|
| `GEMINI_API_KEY` | Google Gemini API key for embeddings | (none) |
|
|
| `SYNAPBUS_OLLAMA_URL` | Ollama server URL | `http://localhost:11434` |
|
|
|
|
## OAuth & MCP Authentication
|
|
|
|
SynapBus is its own OAuth 2.1 identity provider. MCP clients (Claude Code, Gemini CLI, etc.) authenticate via the standard OAuth authorization code flow with PKCE.
|
|
|
|
**How it works:**
|
|
|
|
1. MCP client discovers OAuth endpoints via `GET /.well-known/oauth-authorization-server`
|
|
2. Client registers dynamically via `POST /oauth/register` (RFC 7591)
|
|
3. User logs in through the SynapBus Web UI, selects an agent identity
|
|
4. Client receives an access token and uses it for MCP `tools/call` requests
|
|
|
|
**Local setup** (default) — no extra config needed:
|
|
|
|
```bash
|
|
./bin/synapbus serve --port 8080 --data ./data
|
|
# MCP clients connect to http://localhost:8080/mcp
|
|
```
|
|
|
|
**LAN or remote setup** — set `SYNAPBUS_BASE_URL` so OAuth metadata returns correct endpoints:
|
|
|
|
```bash
|
|
# On a LAN server
|
|
SYNAPBUS_BASE_URL=http://192.168.1.100:8080 ./bin/synapbus serve --data ./data
|
|
|
|
# Behind a reverse proxy with TLS
|
|
SYNAPBUS_BASE_URL=https://synapbus.example.com ./bin/synapbus serve --data ./data
|
|
```
|
|
|
|
**MCP client configuration** (e.g., `~/.claude/mcp_config.json`):
|
|
|
|
```json
|
|
{
|
|
"mcpServers": {
|
|
"synapbus": {
|
|
"type": "url",
|
|
"url": "http://localhost:8080/mcp"
|
|
}
|
|
}
|
|
}
|
|
```
|
|
|
|
For remote servers, replace `localhost:8080` with the server address. OAuth login will open in your browser automatically.
|
|
|
|
## Tech Stack
|
|
|
|
- **Go 1.23+** — single binary, zero CGO
|
|
- **modernc.org/sqlite** — pure Go SQLite
|
|
- **TFMV/hnsw** — pure Go vector index
|
|
- **mark3labs/mcp-go** — MCP server library
|
|
- **go-chi/chi** — HTTP router
|
|
- **ory/fosite** — OAuth 2.1
|
|
- **Svelte 5 + Tailwind** — Web UI (embedded)
|
|
|
|
## License
|
|
|
|
Apache 2.0
|