pub struct McpServerConfig {
pub name: String,
pub command: String,
pub args: Vec<String>,
pub env: BTreeMap<String, String>,
pub env_passthrough: Vec<String>,
pub sandbox: bool,
pub network: Option<bool>,
pub capabilities: CapabilityOverride,
pub disabled: bool,
}Fields§
§name: StringPrefixed onto every tool the server exposes, so two servers can both
have a search without colliding.
command: String§args: Vec<String>§env: BTreeMap<String, String>Values handed to the server explicitly. Use this for a token the server needs, so granting it is a decision written down rather than a side-effect of what happened to be exported.
env_passthrough: Vec<String>Variables inherited from mecha’s own environment, by name.
Empty by default, and that default is the point: an MCP server is
third-party code, and a process that inherits your whole environment
inherits every provider key in it. PATH, HOME, LANG, LC_ALL and
TZ always pass through — without them most runtimes cannot start.
sandbox: boolConfine this server with the configured [sandbox] backend.
Off by default because a confined server sees only the workspace and, unless allowed, no network — which is wrong for most of the servers people actually run. Worth turning on for anything you did not write.
network: Option<bool>Network for this server alone, overriding [sandbox] network.
The case this exists for: a third-party server that has to reach its own
API, confined, while shell still has no way off the machine. With one
shared switch you would have to open shell to satisfy the server.
capabilities: CapabilityOverrideCapabilities forced onto every tool this server exposes, on top of whatever it declares for itself.
MCP capability flags come from the server’s own annotations, which
means a third-party server decides how much the interlock distrusts it.
An unannotated tool is treated as private-but-trusted — wrong in the
dangerous direction for anything that reaches the open world. A Google
Docs server is the worked example: a document someone shared with you is
third-party text, and writing into a document an attacker can read is an
exfiltration channel, so it is all three legs at once and says none of
them.
Only ever widens — see crate::tool::Capabilities::union.
disabled: boolSkip this server without deleting its config.
Trait Implementations§
Source§impl Clone for McpServerConfig
impl Clone for McpServerConfig
Source§fn clone(&self) -> McpServerConfig
fn clone(&self) -> McpServerConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more