AgentHubAgentHub

rebar 工单对账 MCP配置与使用教程

MCP ServerMCP Registry官方收录

io.github.navapbc/rebar · v0.13.1

事件溯源的工单跟踪与 Jira 对账工具,以 Python 库、CLI 和 MCP 服务器三种形式提供。

原文名称:rebar

原文描述:Event-sourced ticket tracker + Jira reconciler, exposed as a Python library, CLI, and MCP server.

建议先在本页复制安装配置,再到上游核对文档与权限。

产品介绍

事件溯源的工单跟踪与 Jira 对账工具,以 Python 库、CLI 和 MCP 服务器三种形式提供。 rebar 工单对账 是一个MCP Server,收录自 官方 MCP Registry。支持 stdio 传输。本页提供产品介绍、配置教程、安装命令与适用场景,支持 Trae、通义灵码、Cursor、Claude Code、VS Code 等。

适用场景

AgentHub Verified 可用性验证技术测试通过

自动化测试流水线已校验安装命令、传输协议与客户端兼容性

最近校验时间2026-10-04
安装配置格式测试有效CLI 与 mcpServers JSON 语法校验通过
协议连接与握手响应正常支持标准 JSON-RPC 2.0 规格规范
上游数据源存活来源 official-mcp-registry,可正常下载依赖
测试可用客户端Claude Code、Claude Desktop、Cursor 等
安全等级: A+ 级 · 官方认证推荐 (A+)·该工具由官方或知名生态团队维护,源码遵循标准开源许可协议,可安全接入 Cursor / Claude。

按平台快速复制

选择你的平台查看安装方式

  1. 打开项目根目录下的 .cursor/mcp.json(没有就新建)
  2. 点击「复制配置」粘贴进去;若已有其他 MCP,只合并 mcpServers 里的本条目
  3. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  4. 保存后按 Cmd+Shift+P(Windows:Ctrl+Shift+P)→ 输入 Reload Window 并执行

预填环境变量与密钥(可选)

隐私安全承诺:所有参数与密钥仅在您本机的浏览器前端进行实时文本替换,AgentHub 绝不向任何服务器上传或存储您的敏感凭据。
点击「复制配置」直接粘贴到客户端
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

配置教程

  1. 打开 rebar 工单对账 详情页,确认这是你需要的 MCP Server(来源 官方 MCP Registry)。
  2. 按客户端选择 Trae、通义灵码、Cursor、Claude Code 或 VS Code,复制 JSON 配置或 CLI 命令。
  3. 将配置合并进 mcpServers,并把环境变量占位符替换为真实密钥。
  4. 重载窗口后,在 Agent 对话中调用该 MCP 提供的工具。

安装命令

以下安装命令与配置步骤已写入页面 HTML,搜索引擎与未启用 JavaScript 的浏览器均可直接读取。

Claude Code(本地)

  1. 确保已安装 Claude Code CLI
  2. 复制下方命令,将 <占位符> 替换为真实环境变量值后,在终端执行
  3. 若下方列出了环境变量,请对照填写
claude mcp add rebar -- uvx nava-rebar

Cursor — .cursor/mcp.json(本地)

  1. 打开项目根目录下的 .cursor/mcp.json(没有就新建)
  2. 点击「复制配置」粘贴进去;若已有其他 MCP,只合并 mcpServers 里的本条目
  3. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  4. 保存后按 Cmd+Shift+P(Windows:Ctrl+Shift+P)→ 输入 Reload Window 并执行
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

VS Code — .vscode/mcp.json(本地)

  1. 确保 VS Code 已安装 GitHub Copilot 扩展并支持 MCP
  2. 打开项目根目录下的 .vscode/mcp.json(没有就新建)
  3. 点击「复制配置」粘贴;若已有其他 MCP,只合并 mcpServers 里的本条目
  4. 将 env 中的 <占位符> 替换为真实密钥(见下方「环境变量」)
  5. 保存后重新加载 VS Code 窗口
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

Claude Desktop — claude_desktop_config.json(本地)

  1. 打开 Claude Desktop 的 claude_desktop_config.json(路径见远程指引)
  2. 点击「复制配置」合并到 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥
  4. 完全退出并重启 Claude Desktop
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

Trae — .trae/mcp.json(本地)

  1. 打开 Trae → 设置 → MCP,或编辑 .trae/mcp.json / 全局 mcp.json
  2. 点击「复制配置」粘贴并合并 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥
  4. 保存后重载 Trae 窗口
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

Cherry Studio — MCP 设置(本地)

  1. 打开 Cherry Studio → 设置 → MCP 服务器 → 添加(STDIO)
  2. 也可直接导入下方 JSON:点击「复制配置」合并到 mcpServers
  3. 将 env 中的 <占位符> 替换为真实密钥,并确保本机已安装 Node.js / uv(npx、uvx)
  4. 启用服务并查看工具列表是否加载成功
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

通义灵码 — MCP 配置(本地)

  1. 通义灵码:个人设置 → MCP 服务 → 「+」→ 手工添加(STDIO)或配置文件添加
  2. 点击「复制配置」合并 mcpServers;命令/参数/环境变量与 JSON 一致
  3. 将 env 中的 <占位符> 替换为真实密钥;本机需 Node.js 18+(npx)或已安装 uv(uvx)
  4. 确认服务状态为已连接后再在智能体对话中调用
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

Windsurf — mcp_config.json(本地)

  1. 编辑 ~/.codeium/windsurf/mcp_config.json
  2. 点击「复制配置」合并 mcpServers(本地 stdio 与 Cursor 格式相同)
  3. 将 env 中的 <占位符> 替换为真实密钥后保存并刷新 Cascade
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

Cline — MCP Servers(本地)

  1. Cline 面板 → 设置 → MCP Servers
  2. 点击「复制配置」粘贴并合并
  3. 将 env 中的 <占位符> 替换为真实密钥后保存
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

WorkBuddy — .workbuddy/mcp.json(本地)

  1. 编辑 ~/.workbuddy/mcp.json(用户级)或项目目录 .workbuddy/mcp.json
  2. 也可在界面:插件 → MCP 服务器 → 配置 MCP,粘贴下方 JSON
  3. 将 env 中的 <占位符> 替换为真实密钥;Windows 下 command/脚本路径建议用绝对路径
  4. 保存并重启 WorkBuddy,确认连接器状态为绿色
{
  "mcpServers": {
    "rebar": {
      "command": "uvx",
      "args": [
        "nava-rebar"
      ]
    }
  }
}

常见报错排查与运行避坑 (Troubleshooting)FAQ

针对 rebar 工单对账 在 Cursor、Claude Code 中的常见连接错误与解决办法

在 Cursor / Claude Code 中配置 rebar 提示 connection closed 或 exit code 1?

通常由本地运行时环境缺失或命令路径未被 IDE 继承引起。排查步骤: 1. 确认已安装 Node.js 18+(支持 npx)或 Python 3.10+(支持 uvx); 2. 尝试在终端运行 which npx 或 which uvx,把配置文件中的 "command" 字段改为完整绝对路径; 3. 修改 mcp.json 后,必须完全重载或重启客户端窗口。

Fix Snippet
# 终端测试命令是否存在:
which npx
node -v
提示 spawn npx ENOENT 或 command not found?

这是因为编辑器后台进程未加载完整的终端环境变量(PATH)。解决方案:在全局安装该包(如 npm install -g 包名),或在配置文件中将 command 设置为系统的实际路径(如 Windows 下的 C:\Program Files\nodejs\npx.cmd,Mac 下的 /usr/local/bin/npx)。

提示 Missing required environment variable 或 API 认证失败?

rebar 依赖环境变量(如 REBAR_ROOT、REBAR_MCP_READONLY、REBAR_MCP_ALLOW_LLM、REBAR_MCP_ALLOW_JIRA_SYNC、REBAR_MCP_TRANSPORT、REBAR_MCP_HTTP_HOST、REBAR_MCP_HTTP_PORT、REBAR_MCP_HTTP_PATH、REBAR_MCP_HTTP_ALLOWED_HOSTS、REBAR_MCP_HTTP_ALLOWED_ORIGINS、REBAR_MCP_HTTP_TLS_AT_EDGE、REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP、REBAR_MCP_AUTH_ENABLED、REBAR_MCP_AUTH_STRATEGIES、REBAR_MCP_AUTH_ISSUER_URL、REBAR_MCP_AUTH_RESOURCE_SERVER_URL、REBAR_MCP_AUTH_REQUIRED_SCOPES、REBAR_MCP_AUTH_STATIC_TOKENS_FILE、REBAR_MCP_AUTH_JWT_JWKS_URI、REBAR_MCP_AUTH_JWT_ISSUER、REBAR_MCP_AUTH_JWT_ALGORITHMS、REBAR_MCP_AUTH_JWT_LEEWAY、REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN、REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT、REBAR_MCP_AUTH_JWT_EXPECTED_TYP、REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST、REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT、REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID、REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV、REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST、REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD、REBAR_MCP_AUTH_PROXY_SECRET_ENV、REBAR_MCP_AUTH_PROXY_SECRET_HEADER、REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER、REBAR_MCP_AUTH_PROXY_SCOPES、REBAR_MCP_AUTH_CUSTOM_IMPORT)。请在客户端配置文件的 "env" 对象中填入有效密钥,注意不要包含多余空格或未闭合的双引号。

Fix Snippet
// .cursor/mcp.json 或 claude_desktop_config.json
{
  "env": {
    "API_KEY": "your_actual_key_here"
  }
}

免安装模拟调用 (Playground)

仿真环境

rebar 核心接口调用仿真 · 无需配置本地环境,直接预览调用参数与返回格式

沙盒就绪 (Virtual Mock)
fn: rebarEvent-sourced ticket tracker + Jira reconciler, exposed as a Python library, CLI, and MCP server.
请求入参 (Arguments)JSON Schema
{
  "target": "rebar",
  "action": "execute",
  "options": {
    "mode": "standard",
    "timeoutMs": 5000
  }
}
💡Agent 在规划任务时会自动生成并传递上述入参
Agent Tool Output

点击上方「模拟运行」按钮

查看该工具在 Agent 内部的返回数据格式

测试环境:AgentHub Virtual SandboxJSON-RPC 2.0

选型与决策建议(为什么选它?)

帮助你快速判断该资源是否契合当前项目,避免盲目折腾

适合什么任务?
  • PR 自动审查
  • 生成 changelog
  • 跨仓库 Issue 检索
什么时候不建议用?
  • 替代人工安全审计
  • 在无授权仓库上操作
推荐工作流搭配:查看完整场景 →

rebar + 对应场景 Prompt → 组成标准 Agent 自动化任务

MCP 实战教程:从安装到看见效果

按完整实例走一遍(含期望效果与对比验收)。装完本页资源后,用教程里的提示词核对是否真正生效。

打开教程 →

相关资源

常搭配使用

LinkedIn

v1.2.6

SkillClawHub13.5k

io.clawhub.byungkyu/linkedin-api

通过托管 OAuth 集成 LinkedIn API。分享帖子、管理资料、访问 LinkedIn 功能。当用户想在 LinkedIn 分享内容、获取资料/组织信息或与 LinkedIn 平台交互时使用。广告功能(营销活动、广告账户)需要额外的 OAuth 权限,使用前请核实已授予的权限。其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。需要网络访问和有效的 Maton API key。调用通过 `maton` CLI 配合 OAuth 登录,或在无法安装 CLI 时通过原始 HTTP 配合 Maton API key 执行。每次调用都以用户连接身份认证,仅访问该连接授权允许的资源,由服务商在每次请求时强制执行;此处记录的端点是本技能所使用的,应用的其他任何端点都需要用户指名要求才可调用。默认使用读取和列表调用,每次写入或新建连接前都与用户确认。

source

WhatsApp Business

v1.2.8

SkillClawHub24.1k

io.clawhub.byungkyu/whatsapp-business

WhatsApp Business API 集成,采用托管式 OAuth。发送消息、管理模板并处理会话。当用户需要与 WhatsApp Business 交互时使用本技能;其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。调用通过 `maton` CLI 配合 OAuth 登录执行,或在无法安装 CLI 时凭 Maton API Key 走原始 HTTP。每次调用都以用户连接身份认证,仅能访问该连接授权范围内的数据,服务端对每个请求强制执行鉴权;此处记录的端点即本技能所用端点,若需该应用的其他端点,须由用户点名提出。默认只做读取与列表调用,任何写入或新连接都需经用户确认。本文件还按使用顺序记录把 WhatsApp Business 连接变成自动化的三个构件:连接(第一步)、通过 Maton SDK 执行 WhatsApp Business 操作的托管函数,以及……(原文截断)

source

Salesforce

v1.2.7

SkillClawHub20.1k

io.clawhub.byungkyu/salesforce-api

Salesforce CRM API 集成,采用托管式 OAuth。仅在需要管理 Salesforce CRM 时安装。请以可用的最小权限连接,破坏性或批量操作优先使用沙箱组织,每次请求前核对目标连接 ID,并及时吊销未使用的连接。本集成可能修改 CRM 记录——仅在核对确切的 sObject、记录 ID 及影响后,再批准具体写操作。其他第三方应用请使用 api-gateway 技能(https://clawhub.ai/byungkyu/api-gateway)。调用通过 `maton` CLI 配合 OAuth 登录执行,或在无法安装 CLI 时凭 Maton API Key 走原始 HTTP。每次调用都以用户连接身份认证,仅能访问该连接授权范围内的数据,服务端对每个请求强制执行鉴权;此处记录的端点即本技能所用端点,若需该应用的其他端点,须由用户点名提出。默认只做读取与列表调用,任何写……(原文截断)

source

继续逛 AgentHub

大多数人安装前还会对比同类工具或看场景方案——下面这些能帮你少走弯路。

收录徽章:把 AgentHub 挂到你的官网

复制下面任意一段代码到项目主页、官网或 GitHub README。徽章是 SVG 热链,无需上传文件,链接指向本页,访客可由此直接找到安装方式。

预览AgentHub 已收录:rebar 工单对账
HTML
<a href="https://myagenthub.cn/p/io.github.navapbc/rebar" title="AgentHub 已收录:rebar 工单对账" target="_blank" rel="noopener">
  <img src="https://myagenthub.cn/badge/io.github.navapbc/rebar" alt="AgentHub 已收录:rebar 工单对账" height="20" style="border:0"/>
</a>
Markdown(GitHub README)
[![AgentHub 已收录:rebar 工单对账](https://myagenthub.cn/badge/io.github.navapbc/rebar)](https://myagenthub.cn/p/io.github.navapbc/rebar)

徽章由 /badge/<资源ID> 动态生成,名称与收录状态变化后自动更新;请保留链接指向,它是收录来源的判定依据。

统一 Manifest

{
  "id": "io.github.navapbc/rebar",
  "type": "mcp-server",
  "version": "0.13.1",
  "displayName": "rebar",
  "description": "Event-sourced ticket tracker + Jira reconciler, exposed as a Python library, CLI, and MCP server.",
  "repository": {
    "url": "https://github.com/navapbc/rebar",
    "source": "github"
  },
  "distribution": {
    "packages": [
      {
        "registryType": "pypi",
        "identifier": "nava-rebar",
        "version": "0.13.1",
        "runtimeHint": "uvx",
        "transport": "stdio",
        "environmentVariables": [
          {
            "name": "REBAR_ROOT",
            "description": "Path to the repo root that holds the .tickets-tracker store (defaults to the git toplevel of the working dir)."
          },
          {
            "name": "REBAR_MCP_READONLY",
            "description": "Set to 1 to expose only the read tools (no write/mutation tools)."
          },
          {
            "name": "REBAR_MCP_ALLOW_LLM",
            "description": "Set to 1 to enable the billable LLM tools (review_code / scan_spec / verify_completion / review_plan); off by default."
          },
          {
            "name": "REBAR_MCP_ALLOW_JIRA_SYNC",
            "description": "Set to 1 to allow the live (mutating) Jira reconcile mode; otherwise reconcile is dry-run only."
          },
          {
            "name": "REBAR_MCP_TRANSPORT",
            "description": "Transport for the MCP server: 'stdio' (default) or 'http' (the optional Streamable-HTTP transport)."
          },
          {
            "name": "REBAR_MCP_HTTP_HOST",
            "description": "Bind host for the Streamable-HTTP transport (default 127.0.0.1)."
          },
          {
            "name": "REBAR_MCP_HTTP_PORT",
            "description": "Bind port for the Streamable-HTTP transport (1-65535; default 8000)."
          },
          {
            "name": "REBAR_MCP_HTTP_PATH",
            "description": "URL path the Streamable-HTTP transport serves on (default /mcp)."
          },
          {
            "name": "REBAR_MCP_HTTP_ALLOWED_HOSTS",
            "description": "Comma-separated allowlist of exact host:port values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback."
          },
          {
            "name": "REBAR_MCP_HTTP_ALLOWED_ORIGINS",
            "description": "Comma-separated allowlist of exact Origin values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback."
          },
          {
            "name": "REBAR_MCP_HTTP_TLS_AT_EDGE",
            "description": "Set to 1 to acknowledge TLS is terminated at the edge; required to bind the Streamable-HTTP transport to a non-loopback host."
          },
          {
            "name": "REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP",
            "description": "Set to 1 to acknowledge running the Streamable-HTTP transport without a token verifier; required to boot the HTTP transport while auth is off."
          },
          {
            "name": "REBAR_MCP_AUTH_ENABLED",
            "description": "Set to 1 to enable MCP authentication (the composite token verifier + Resource-Server wiring); off by default."
          },
          {
            "name": "REBAR_MCP_AUTH_STRATEGIES",
            "description": "Comma-separated, ordered list of token-verifier strategies to compose (closed set: static, jwt, introspection, proxy, custom)."
          },
          {
            "name": "REBAR_MCP_AUTH_ISSUER_URL",
            "description": "OAuth authorization-server issuer URL advertised in the Protected-Resource Metadata (RFC 9728) when auth is enabled."
          },
          {
            "name": "REBAR_MCP_AUTH_RESOURCE_SERVER_URL",
            "description": "The single resource identifier (RFC 8707 audience) for this server; the composite verifier re-checks every accepted token against it."
          },
          {
            "name": "REBAR_MCP_AUTH_REQUIRED_SCOPES",
            "description": "Comma-separated scopes a caller must hold; the SDK returns 403 insufficient_scope when a principal lacks one."
          },
          {
            "name": "REBAR_MCP_AUTH_STATIC_TOKENS_FILE",
            "description": "Path to the JSON secrets file for the static-bearer verifier (stores only SHA-256 digests of the accepted tokens)."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_JWKS_URI",
            "description": "HTTPS JWKS endpoint the `jwt` verifier fetches signing keys from (an OIDC provider's .well-known/jwks.json)."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_ISSUER",
            "description": "Expected `iss` claim for the `jwt` verifier; falls back to REBAR_MCP_AUTH_ISSUER_URL when unset."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_ALGORITHMS",
            "description": "Comma-separated PINNED, asymmetric-only JWS algorithms for the `jwt` verifier (default RS256,ES256); a symmetric algorithm on a JWKS source is refused."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_LEEWAY",
            "description": "Clock-skew leeway in seconds applied to exp/nbf validation by the `jwt` verifier (default 60)."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN",
            "description": "Minimum seconds between JWKS refetches triggered by an unknown key id (the concurrency-safe flood guard; default 30)."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT",
            "description": "HTTP timeout in seconds for the `jwt` verifier's JWKS fetch (default 10)."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_EXPECTED_TYP",
            "description": "When set, the `jwt` verifier requires the JWT header `typ` to equal this (e.g. at+JWT per RFC 9068); unset skips the check."
          },
          {
            "name": "REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST",
            "description": "Set to 1 to permit a private/link-local/loopback JWKS host (SSRF guard is on by default); off by default."
          },
          {
            "name": "REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT",
            "description": "The `introspection` verifier's RFC 7662 endpoint URL (must be https://); the opaque token is POSTed here on every request (no caching)."
          },
          {
            "name": "REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID",
            "description": "The client id the `introspection` verifier presents to the Authorization Server via HTTP Basic (client_secret_basic)."
          },
          {
            "name": "REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV",
            "description": "The NAME of the env var holding the introspection client secret (never the secret itself); must be present + non-empty at startup or the server refuses to start (fail-closed)."
          },
          {
            "name": "REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST",
            "description": "Set to 1 to permit a private/link-local/loopback introspection endpoint host (SSRF guard is on by default); off by default."
          },
          {
            "name": "REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD",
            "description": "Set to 1 to accept an active introspection response that OMITS `aud` (many AS do); off by default (fail-closed reject)."
          },
          {
            "name": "REBAR_MCP_AUTH_PROXY_SECRET_ENV",
            "description": "The NAME of the env var holding the trusted-proxy shared secret (never the secret itself); must be present + non-empty at startup or the `proxy` verifier refuses to start (fail-closed)."
          },
          {
            "name": "REBAR_MCP_AUTH_PROXY_SECRET_HEADER",
            "description": "The header the fronting proxy sends its shared secret on; the identity is trusted only when this matches (constant-time; default x-proxy-auth)."
          },
          {
            "name": "REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER",
            "description": "The header carrying the proxy-authenticated principal identity, trusted only when the secret header validates (default x-forwarded-user)."
          },
          {
            "name": "REBAR_MCP_AUTH_PROXY_SCOPES",
            "description": "Comma-separated fixed scope set granted to proxy-authenticated principals; empty by default (the principal holds no scopes)."
          },
          {
            "name": "REBAR_MCP_AUTH_CUSTOM_IMPORT",
            "description": "The `custom` strategy's `module:factory` import string, resolving to a factory that returns a TokenVerifier; a TRUSTED operator config value that loads and executes the operator-configured code at startup (fail-closed on any load error)."
          }
        ]
      }
    ],
    "remotes": []
  },
  "dependencies": [],
  "installTargets": [
    "claude-code",
    "claude-desktop",
    "cursor",
    "vscode",
    "trae",
    "cherry-studio",
    "lingma",
    "windsurf",
    "cline",
    "workbuddy"
  ],
  "keywords": [],
  "provenance": {
    "origin": "official-mcp-registry",
    "originalId": "io.github.navapbc/rebar",
    "originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.navapbc%2Frebar/versions/latest",
    "isOfficial": true,
    "status": "active"
  }
}