The production-grade, TypeScript-first framework for building MCP servers — decorators, DI, auth, and Streamable HTTP, batteries included.
Docs • Quickstart • API Reference • Discord
FrontMCP turns the Model Context Protocol into a
typed, declarative framework. You write clean @Tool, @Resource, and @App
classes; FrontMCP handles the protocol, transport, dependency injection, sessions,
auth, and execution flow — and the same server runs locally and ships to
production unchanged.
import'reflect-metadata';import{FrontMcp,LogLevel}from'@frontmcp/sdk';importHelloAppfrom'./hello.app';
@FrontMcp({info: {name: 'Demo',version: '0.1.0'},apps: [HelloApp],http: {port: 3000},logging: {level: LogLevel.Info},})exportdefaultclassServer{}- Typed by default — decorators + Zod schemas give end-to-end types from input to output, with editor autocomplete and compile-time checks.
- Batteries included — auth (OAuth/JWKS/DCR), sessions, transport, discovery, and DI are built in, not bolted on.
- Ship anywhere — one codebase deploys to Node, Vercel, AWS Lambda, Cloudflare Workers, or a serverless bundle.
- Production-minded — stateful/stateless sessions, high-availability transport, structured observability, and a 95%+ tested core.
- Extensible — plugins, lifecycle hooks, OpenAPI adapters, and external MCP sub-apps when you outgrow the defaults.
Node.js 24+ required.
# New project (recommended)
npx frontmcp create my-app
# Existing project
npm i -D frontmcp @types/node@^24
npx frontmcp initFull setup guide: Installation · Quickstart
Build — decorator-configured @FrontMcp server and @App
domains; typed @Tool, @Resource, and
@Prompt primitives; @Agent multi-step chains; and
scoped Providers / DI.
Secure — Remote & Local OAuth, JWKS, DCR, per-app auth with stateful / stateless sessions (JWT or UUID transport IDs).
Connect & operate — Streamable HTTP + SSE transport,
every MCP protocol revision from 2024-11-05 through
2026-07-28 on one endpoint, capability discovery,
elicitation, hooks, HTTP-discoverable
skills, tool UI / MCP Apps, an in-process
Direct Client (connectOpenAI / connectClaude), and
first-class deployment.
Extend & tooling — official plugins (Cache, Remember, CodeCall,
Dashboard), the OpenAPI adapter, a UI library (HTML/React
widgets, SSR, MCP Bridge), an E2E testing framework, and a
CLI (create, init, dev, build, inspect, doctor).
→ Full reference: docs.agentfront.dev/frontmcp
You install frontmcp (the CLI) and @frontmcp/sdk. Everything else is either
pulled in for you or opt-in.
| Package | Description |
|---|---|
frontmcp | The CLI — create, init, dev, build, inspect, doctor |
@frontmcp/sdk | Core framework — decorators, DI, flows, transport, MCP protocol |
@frontmcp/auth | Authentication, OAuth, JWKS, DCR/CIMD, credential vault |
@frontmcp/testing | E2E test framework with fixtures and matchers |
| Package | Description |
|---|---|
@frontmcp/plugins | Plugin authoring toolkit + official plugin re-exports |
@frontmcp/adapters | OpenAPI adapter — generate tools from an OpenAPI spec |
@frontmcp/skills | Curated SKILL.md catalog for scaffolding and skills install |
@frontmcp/guard | Policy/guard rules for tool inputs and outputs |
@frontmcp/observability | Structured logging, metrics, and tracing helpers |
| Package | Description |
|---|---|
@frontmcp/react | React hooks + client for talking to a FrontMCP server |
@frontmcp/ui | React components, SSR renderers, MCP Bridge |
@frontmcp/uipack | React-free themes, build tools, platform adapters |
| Package | Description |
|---|---|
@frontmcp/edge | Run a server on Cloudflare Workers / V8 isolates from a config |
@frontmcp/storage-sqlite | SQLite-backed session, task, and elicitation stores |
@frontmcp/nx | Nx generators and executors for FrontMCP workspaces |
Published so the packages above resolve, but not intended for direct use:
| Package | Description |
|---|---|
@frontmcp/protocol | The single boundary to the upstream MCP SDK — protocol types |
@frontmcp/di | Dependency injection container |
@frontmcp/utils | Shared utilities — naming, URI, crypto, FS |
@frontmcp/lazy-zod | Lazily-loaded Zod wrapper that keeps cold starts small |
| Package | Description |
|---|---|
@frontmcp/plugin-cache | Cache tool results with a TTL |
@frontmcp/plugin-remember | Per-session memory (this.remember) |
@frontmcp/plugin-approval | Human approval gates before a tool runs |
@frontmcp/plugin-codecall | Let the model compose tool calls as code |
@frontmcp/plugin-dashboard | Built-in web dashboard |
@frontmcp/plugin-feature-flags | Toggle tools and apps at runtime |
@frontmcp/plugin-skilled-openapi | OpenAPI → skills + meta-tools for large APIs |
Keep all @frontmcp/* packages on the same version. A clear "version mismatch" error is thrown at boot if versions drift. (Production Build)
PRs welcome! See CONTRIBUTING.md for workflow, coding standards, and the PR checklist.