Running Strake Server with MCP Integration¶
The Strake Federation Engine now supports a hybrid Python Sidecar MCP architecture. This allows AI agents (like Claude Desktop or the OpenAI SDK) to interact seamlessly with your data sources using the Model Context Protocol.
Architecture¶
We use a Code Mode architecture. Instead of exposing hundreds of individual "tools" to the LLM context, we expose a single tool: a sandboxed Python runtime (run_python).
When you enable the MCP feature, the Rust server (strake-server) acts as a "Supervisor." It automatically spawns a child Python process running the strake.mcp module, which manages the sandbox.
classDiagram
class StrakeServer {
+Flight SQL (50051)
+Spawns Sidecar
}
class PythonMCPSidecar {
+stdio/SSE Transport
+Manages Sandbox
}
class Sandbox {
+execute_python()
}
StrakeServer --> PythonMCPSidecar : Spawns
PythonMCPSidecar --> Sandbox : Runs Agent Code
Sandbox --> StrakeServer : Queries (Flight SQL / Zero Copy)
Prerequisites¶
- Rust Toolchain: To build the server.
- Python Environment: The server requires
python3(orpython) in the path with thestrakelibrary installed.
Running the Server¶
Start the Enterprise server with the --mcp flag:
Verification¶
You should see logs indicating the sidecar has started:
Connecting an Agent (Example: OpenAI)¶
We provide a sample OpenAI agent script demonstrating how to connect to this MCP server over stdio (or you can connect to the running sidecar if you adjusted the mode).
1. Configure the Agent¶
Edit mcp/openai_strake_agent.py to ensure it points to your server:
2. Run the Agent¶
Note: The agent script itself runs the MCP server as a subprocess (Stdio Mode). This is useful for standalone agent scripts that don't need the full strake-enterprise server running in the background, OR if they are connecting to a remote server passed via STRAKE_URL.
# Install dependencies
pip install mcp openai azure-identity
# Run the agent
python mcp/openai_strake_agent.py
Claude Desktop Integration¶
To add Strake to Claude Desktop, edit your claude_desktop_config.json:
{
"mcpServers": {
"strake": {
"command": "python",
"args": [
"-m",
"strake.mcp"
],
"env": {
"STRAKE_URL": "grpc://127.0.0.1:50051"
}
}
}
}
Ensure that the strake-enterprise server is running separately on port 50051 so the sidecar can connect to it.
Security Guards (Design Note)¶
Strake’s prompt-injection / exfiltration guardrails are intended to be agent-only protections: they should activate for queries executed inside an MCP tool call context (LLM in the loop), and stay off for direct SDK/CLI/batch usage (no LLM, no injection threat).
Internal design details and rollout modes (disabled / dry_run / enforce) live in agent-guard-activation.md.