barrel-platform/barrel_mcp
60.8
Adequate · 17 September 2026
21.7k
lines of production code
Erlang
primary language
1
measurement over time
What this system is
barrel\_mcp is an Erlang library that implements the Model Context Protocol (MCP), supporting both legacy handshake-based and modern stateless protocol versions. It provides core capabilities for pluggable authentication, including OAuth 2.1 and JWT, and features a multi-server tool aggregator that namespaces and routes tool calls from various MCP clients to a single LLM interface. The system also handles server-to-client sampling and async tool execution with progress events, validated through comprehensive conformance and interoperability tests.
Features
Initial project scaffolding and documentation
This change introduces the foundational project structure and documentation for the barrel\_mcp library. It adds AGENTS.md and CLAUDE.md to guide AI coding agents, a comprehensive CHANGELOG.md tracking the project history, and an Apache 2.0 LICENSE file. It also includes a Makefile to standardize build, test, and interop commands, updates .gitignore to exclude generated artifacts and IDE files, and refreshes README.md to reflect the current feature set and installation instructions. Additionally, it commits the rebar.lock file to ensure reproducible builds and updates rebar.config to switch dependencies from Cowboy to h1/h2 for HTTP transport, while adding configuration for erlfmt, elvis, and ex\_doc.
(repo-wide) · high confidence
New runnable examples for MCP federation, client tools, and server-to-client sampling
Added three self-contained Erlang examples in the \examples/\ directory to demonstrate core \barrel\_mcp\ capabilities. The \agent\_host\ example shows how to aggregate tools from multiple federated MCP clients into a single namespaced catalog and route calls back to the correct server. The \echo\_client\ example provides a minimal host that registers an echo tool, connects a client, and exercises the basic tool call flow. The \sampling\_host\ example demonstrates the server-to-client sampling round-trip, where a server-side tool triggers a client-side message sampling handler. Each example includes source code, build configuration, and Common Test suites to verify the end-to-end behavior.
examples · high confidence
New sampling\_host example demonstrating server-to-client LLM sampling
Added a new Erlang example application (sampling\_host) that implements a barrel\_mcp client handler to demonstrate a full server-to-client round-trip for LLM sampling. The example registers a tool that triggers a sampling request, waits for the connected client to provide a canned reply, and returns the result, specifically targeting the 2025-11-25 protocol version to illustrate the handshake-era behavior.
_examples/sampling\host · high confidence
Pluggable authentication and multi-server tool aggregation
The library now supports pluggable authentication for both server and client sides. On the server, a new \barrel\_mcp\_auth\ behaviour allows configuring providers such as Bearer (JWT), API Key, Basic, and custom modules, enabling secure access control. On the client, \barrel\_mcp\_client\_auth\ introduces OAuth 2.1 with PKCE, static Bearer tokens, and enterprise-managed authorization flows, handling token discovery, refresh, and DPoP binding. Additionally, \barrel\_mcp\_agent\ provides a multi-server tool aggregator that namespaces and routes tool calls from multiple MCP clients to a single LLM interface, supporting Anthropic and OpenAI formats.
src · high confidence
Behavioural changes
MCP protocol versioning expanded to support 2026-07-28 stateless era
The library now supports the MCP 2026-07-28 protocol revision alongside legacy handshake-based versions (2024-11-05 through 2025-11-25). This introduces a distinction between 'modern' stateless requests and 'legacy' handshake-based ones, with specific error codes (e.g., -32020 to -32022) and method sets defined for the new era. Legacy-only methods like \ping\ and \logging/setLevel\ are explicitly marked as unknown to modern clients, while modern-only methods like \subscriptions/listen\ and \tasks/update\ are introduced. The header mismatch and missing client capability errors are now standardized under the 2026-07-28 error code range.
include · high confidence
Test coverage
Added test suites for MCP agent, async tools, and authentication
Added comprehensive test coverage for the \barrel\_mcp\_agent\ integration suite, verifying that the aggregator correctly prefixes tool names and routes calls to the appropriate client instances. Added tests for async tool execution, covering cancellation, progress event emission, and error handling. Added tests for authentication mechanisms, including modern hash formats (PBKDF2-SHA256 for basic auth, HMAC-SHA256 for API keys), OAuth client authorization flows, and client-side authentication dispatch.
test · high confidence
Dependencies
Add MCP conformance and interop test dependencies
Added the official MCP conformance suite (version 0.2.0-alpha.11) and the reference server (version 2026.8.18) to the test/conformance directory, enabling automated validation of server compliance. Additionally, configured Python interop test environments with specific MCP SDK versions (1.27.x and 2.0.0) and HTTP/2 libraries (h2, httpx\[http2\]) to support protocol-level interoperability testing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 61.
Lenses
- Code Health 91
- Architecture 100
- Maturity 66
- Readiness 78
- Security 100
- Event-Driven 41
- Event Sourcing 100
Changes since last survey
- 223 commits — 209 feature/other, 14 fixes
By area
- (root) — 99 commits
- (repo) — 58 commits
- test/interop — 7 commits
- src/barrel_mcp.erl — 5 commits
- src/barrel_mcp_http_engine.erl — 5 commits
- src/barrel_mcp_protocol.erl — 5 commits
- src/barrel_mcp_client.erl — 3 commits
- test/barrel_mcp_conformance_SUITE.erl — 3 commits
- test/conformance — 3 commits
- guides/authentication.md — 2 commits
- include/barrel_mcp.hrl — 2 commits
- src/barrel_mcp_jsonschema.erl — 2 commits
- src/barrel_mcp_session.erl — 2 commits
- test/barrel_mcp_agent_SUITE.erl — 2 commits
- test/barrel_mcp_client_modern_SUITE.erl — 2 commits
- examples/agent_host — 1 commit
- guides/building-a-client.md — 1 commit
- guides/features.md — 1 commit
- guides/glossary.md — 1 commit
- guides/http-stream.md — 1 commit
Notable commits
- fix: 2.0.1: transport review fixes (#52)
- fix: Critical correctness + security fixes
- fix: Fix unbalanced backticks in CHANGELOG so ex_doc builds clean
- fix: Mention the client reconnect fix in the 2.2.5 changelog
- fix: Merge pull request #12 from barrel-platform/fix/critical-correctness-and-spec-conformance
- fix: Merge pull request #13 from barrel-platform/fix/tasks-spec-2025-11-25
- fix: Merge pull request #25 from barrel-platform/fix/task-lastUpdatedAt
- fix: Merge pull request #29 from barrel-platform/fix/long-running-create-task-result
- fix: Merge pull request #70 from barrel-platform/deps-h1-h2-fix
- fix: Python MCP interop test harness + tasks-capability wire fix
- fix: Release 2.0.2: security fixes for the HTTP transport and auth (#53)
- fix: Streamable HTTP: cancellation race fix on tools/call
- fix: chore: fix changelog date 2024 -> 2025
- fix: fix: resolve dialyzer warnings
- change: Acquire client-credentials, enterprise and jwt-bearer tokens from a challenge, and bind tokens with DPoP
- change: Add SSE and stdio interop tests, and give stdio a session
- change: Add a Go interop suite, and stop the SSE pair advertising an era it lacks
- change: Add a glossary of the terms the code uses
- change: Add barrel_mcp_auth_custom for simplified custom authentication
- change: Add pluggable authentication and ex_doc documentation
- …and 203 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
barrel-platform/barrel_mcp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3d3c12864a92aee23e24ca0f0cef0c3f999ce134 — the exact code this score is about.
- Scored under rubric-2026.09.13 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1ef6c0bd534.