Product-neutral reference implementation for Cloudflare Worker MCP Server v1 and Security v1.
This repository demonstrates an SDK-backed Streamable HTTP MCP endpoint on Cloudflare Workers with authorization, protected resource metadata, Zod input validation, permission checks, audit-ready mutation evidence, environment-specific bindings, and CI gates.
If you only need to learn Cloudflare Workers or MCP, start with the official sources:
- Cloudflare Workers templates
- Cloudflare Workers template repository
- MCP TypeScript SDK
- MCP Streamable HTTP transport
This repo is not a replacement for those examples. It is a VCQA reference fixture that combines the official MCP SDK's Web Standard Streamable HTTP transport with Worker-boundary authorization, scoped tool permissions, Zod validation, audit events, runbooks, CI gates, and a tracked VCQA report.
corepack enable
pnpm install
pnpm lint
pnpm typecheck
pnpm test
pnpm build| Standard | Role |
|---|---|
| Cloudflare Worker MCP Server v1 | Remote MCP on Workers |
| Security v1 | Authorization, secrets, output safety, CI |
The standard is the source of truth. This repo is a forkable implementation example.
The tracked report lives at docs/vcqa-report.md.