MCP in Worker
Expose a read-only MCP server inside your Cloudflare Worker: POST /mcp, deploys with the site, no separate server.
- What
- Expose a read-only MCP server inside your Cloudflare Worker: POST /mcp, deploys with the site, no separate server.
- Cost
- Free
- Needs
- Add an MCP endpoint to your Cloudflare Worker in five steps. You need: an existing Worker with a data API (search + record detail).
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
MCP in Worker gives AI assistants direct tools into your data without running separate MCP infrastructure. A single POST /mcp endpoint inside your existing Cloudflare Worker speaks MCP over streamable HTTP (JSON-RPC 2.0) and reuses your tested API handlers. It is proven live with three tools, bilingual, and zero auth: search, record detail, and action payload. The pattern is deliberately small. You define three to five read-only tools with tight JSON schemas: search takes the user's words untranslated (capped at ~120 chars), detail returns the full record, and the action tool returns a copy-paste payload the user confirms elsewhere. Instead of reimplementing search, you synthesize an internal Request to your own tested endpoint and forward the caller's headers, so IP-based rate limits, ranking, synonyms, and logging behave identically. The worker entry wires three routes before any other handler: POST /mcp is the JSON-RPC dispatcher (initialize, tools/list, tools/call, ping), GET /mcp returns a human-readable info page describing the endpoint and its tools, and OPTIONS /mcp answers the CORS preflight because MCP clients are cross-origin. Tool results are plain text or structured content the model can quote, never HTML. Operating rules keep it safe: read-only, no tool writes, deletes, or spends. Tool descriptions are self-contained because the calling model never sees your site, only these strings. CORS allows Content-Type, Accept, and Mcp-Session-Id. The endpoint is public by design, so it never logs or echoes secrets, and it gets its own rate limit like the underlying API since MCP clients retry aggressively. If your deploy pipeline strips routes, exempt /mcp explicitly and re-verify after every deploy.
Version:
Install
Copy the install package below, then paste it into MuseCommunity-built. Skill Harbor doesn't audit code — review the source before installing.
Add an MCP endpoint to your Cloudflare Worker in five steps. You need: an existing Worker with a data API (search + record detail). 1. Define 3 to 5 read-only tools with tight JSON schemas. The classic trio: search_items (q, limit), get_item (id), get_action_payload (id). Keep free-text inputs capped (~120 chars) and pass user wording through untranslated. 2. Reuse your existing handlers: inside each tool implementation, synthesize an internal Request to your own tested API route and forward the caller's headers, so rate limits and logging stay accurate. Do not reimplement ranking or search. 3. Wire the routes in the worker entry BEFORE other handlers: POST /mcp to an async JSON-RPC dispatcher handling initialize, tools/list, tools/call, and ping; GET /mcp to a human-readable info page; OPTIONS /mcp to a 204 with CORS headers (Allow-Origin *, Allow-Headers Content-Type, Accept, Mcp-Session-Id). 4. Rate-limit the tools like the underlying API (e.g. 60/hour). Return tool results as plain text or structured content, JSON-RPC 2.0 with your protocol version string. Never log secrets; the endpoint is public by design. 5. Verify live with curl against the deployed hostname: POST tools/list, then one tools/call, then GET /mcp. Re-verify after every deploy, especially if your pipeline strips or neutralizes routes. Rules: read-only tools only. If an action is needed, return a payload or link the user confirms elsewhere.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.