vibe coded with ❤️
Concept app · v0.1.0 · Notarized

macMCP

A local MCP server for macOS that an admin rolls out and controls completely by MDM. It gives AI clients — Claude Desktop, Claude Code, VS Code, Cursor — tools for your organisation's systems: Jira Data Center, Confluence Data Center and Jamf Pro to start with. MDM decides which connectors and tools exist, where the servers are and which credentials they use, and switches them on or off at runtime.

Concept app. macMCP explores whether MCP access to internal systems can be administered like any other managed setting instead of per-user config files. Version 0.1.0 is signed and notarized, but the connectors haven't been run against real Jira, Confluence or Jamf Pro servers yet, and the package hasn't been tested on a managed Mac. It has been tested in a demo environment only, not in production. Read Where things stand first.

MCP for your systems, managed like everything else

🧩

Declarative Connectors

A connector is data, not code: auth methods and tools as templated REST calls with JSON-schema arguments, run by one generic engine. New systems arrive through a signed public catalog without a new app release.

🎛️

Controlled by MDM

Connectors, base URLs, credentials, single tools, write tools and a master switch live in one managed-preferences domain. Changes take effect within about 30 seconds — no restart, no reinstall.

🔐

Encrypted Secrets

MACMCP-ENC envelopes (P-256 ECDH + AES-GCM) with your organisation key — the same scheme as Gimle and Mimir, so one key can serve all three. Plaintext secrets in profiles are refused by default.

👤

Your Own Token, Your Own Permissions

For Jira and Confluence, users can add their own personal access token in the app (stored in their login keychain), so actions run with their rights rather than a service account's. MDM can forbid it per connector.

✍️

Read-Only Unless Allowed

Every tool that changes data is a write tool, and write tools stay off until a connector sets AllowWriteTools — enforced in the binary, so a catalog can't bypass it.

🛡️

A Catalog That Can't Go Rogue

Ed25519-signed, rollback-protected, pinnable. Even a validly signed catalog can't send requests off the configured base URL, set auth headers, or follow a redirect to another host.

🔌

stdio and HTTP

Started by an AI client with --stdio, or serving POST /mcp on loopback with a bearer token and an Origin check. A non-loopback address needs an explicit switch and always a token.

🧍

Agent or Daemon

A per-user LaunchAgent by default; a whole-Mac LaunchDaemon on request (profile credentials only). Both are registered by the app, with a ready-made background-items profile.

🧰

macmcpctl

Admin CLI to check settings, encrypt secrets, list catalog tools, print client snippets and generate settings, background-item and privacy (PPPC) profiles. Plus an offline encrypt.html.

🍎

Native, No AI, No Telemetry

Swift only — no Python or Node runtime. There's no AI in the app and no telemetry; it talks only to the servers an admin configures and to GitHub for the signed catalog.

What the first catalog offers

Jira Data Center

Read: search issues, get an issue, list projects, get transitions.

Write (opt-in): add comment, create issue, transition issue.

Confluence Data Center

Read: search, get a page, list spaces, get children.

Write (opt-in): create page.

Jamf Pro

Read: search computers and mobile devices, get a computer, list scripts, computer groups and policies, get a policy.

Write (opt-in): redeploy framework. Authenticates with an API client from the profile.

Client wiring

The catalog also documents how to wire macMCP into Claude Desktop, Claude Code, VS Code and Cursor — with the Mimir harness ID, so organisations that use Mimir can push those entries centrally.

All connectors and clients are marked experimental in the catalog (release 2026.10.03.1), which is public on GitHub as Spectrechen/macMCP-catalog.

Admin Guide & Design

Deployment steps, every managed setting and connector key, encrypted secrets, per-user credentials, privacy profiles, the catalog trust model and the threat model.

📖 Read the Documentation

Where things stand

System Requirements

macOS 26 or later, Apple silicon.

An MDM that can install custom configuration profiles (a Jamf Pro custom schema is included).

Build Status

Version 0.1.0, catalog 2026.10.03.1. Signed with a Developer ID certificate and notarized by Apple.

45 unit tests pass in 11 suites.

What's Verified

During development: the server over stdio and HTTP, enabling and disabling a connector at runtime, the Origin check, loading the bundled signed catalog, and that encrypt.html and the Swift code decrypt each other's values.

Not Yet Verified

No run against a real Jira Data Center, Confluence Data Center or Jamf Pro server. The package on a managed Mac, switching between agent and daemon, the background-items and privacy profiles, and an org key delivered by MDM haven't been tested either.

There's no app icon or screenshots yet.

Want to try the concept?

Concept app · Free · Signed & Notarized · macOS 26+ · Apple Silicon · 0.9 MB

Download macMCP