Sea Haven MCP platform — trust-tiered MCP servers + Cognito/Google auth broker, replacing seahaven-slack-bot and exec-aide (design phase)
Find a file
2026-07-06 18:27:22 -04:00
.github chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#20) 2026-07-06 18:27:22 -04:00
.security-review Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
auth chore(deps-dev): bump @types/node from 22.7.4 to 26.1.0 (#14) 2026-07-06 18:17:11 -04:00
docs docs: add sh-mcp-auth deploy runbook (#5) 2026-07-02 15:53:22 -04:00
infra chore(deps-dev): bump typescript from 5.9.3 to 6.0.3 in /infra (#11) 2026-07-06 21:56:32 +00:00
packages chore(deps-dev): bump @types/node from 22.7.4 to 26.1.0 (#14) 2026-07-06 18:17:11 -04:00
servers chore(deps-dev): bump @types/node from 22.7.4 to 26.1.0 (#14) 2026-07-06 18:17:11 -04:00
.editorconfig Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
.gitignore Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
.prettierignore Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
.prettierrc Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
cdk.json Phase 2a: Cognito auth substrate (CDK) + pre-token & group-sync Lambdas (#4) 2026-06-26 14:33:46 -04:00
eslint.config.js Phase 2a: Cognito auth substrate (CDK) + pre-token & group-sync Lambdas (#4) 2026-06-26 14:33:46 -04:00
package-lock.json chore(deps-dev): bump @types/node from 22.7.4 to 26.1.0 (#14) 2026-07-06 18:17:11 -04:00
package.json chore(deps-dev): bump @types/node from 22.7.4 to 26.1.0 (#14) 2026-07-06 18:17:11 -04:00
README.md docs: link Confluence AWS Architecture Map (INFRA-53) (#18) 2026-07-06 17:44:42 -04:00
tsconfig.base.json Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
tsconfig.json Phase 2a: Cognito auth substrate (CDK) + pre-token & group-sync Lambdas (#4) 2026-06-26 14:33:46 -04:00
vitest.config.ts Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00

sh-mcp

CI TypeScript Node AWS CDK Slack

Sea Haven MCP platform. A TypeScript monorepo of trust-tiered MCP servers that expose Sea Haven's proprietary integrations as tools, plus the Cognito/Google auth broker and the rebuilt scheduled jobs. This service replaces seahaven-slack-bot and exec-aide, which are deprecated completely; the conversational surface becomes a configurable Slack task agent.

Status: BUILDING. Platform + auth substrate built; nothing deployed to AWS yet. Phase 0b (monorepo + @sh-mcp/shared core), Phase 1 (runnable sh-mcp-ops / sh-mcp-finance over MCP + OpenAPI), and Phase 2a (the Cognito auth substrate CDK stack + pre-token/group-sync Lambdas) are on main. The servers run locally (SH_MCP_ENV=local); SH_MCP_ENV=aws is wired but not yet deployed. The authoritative spec is docs/design.md.

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's sh-mcp-auth, sh-mcp-ops, and sh-mcp-finance stacks are represented there as Mermaid subgraphs.

Auth substrate (Phase 2a — infra/ + auth/)

infra/ is the root CDK app; cdk synth builds the sh-mcp-auth stack: a Google-federated Cognito user pool (ESSENTIALS feature plan), per-tier app clients whose AllowedOAuthScopes are the trust-tier boundary (sh-agentforce-ops / -finance / -exec), a suppress-only V2 pre-token Lambda (auth/pre-token-gen), a 5-minute group-sync Lambda (auth/group-sync), and the sync-state + deny-list tables.

Revocation has two layers. Group membership (Google → Cognito, 5-min cadence) is the primary entitlement control, with a fail-closed 30-minute freshness window: if group-sync stalls, the pre-token Lambda drops every caller to base ops:read. The sh-mcp-deny-list table is a hard-kill overlay the pre-token Lambda consults on every mint — a sub listed there is stripped to no tier scopes immediately (TTL-expiring), ahead of the next sync. The deny-list read is fail-open (a DynamoDB blip logs deny_list_read_failed and does not lock everyone out, since group membership + its fail-closed window remain authoritative). The finance app client additionally caps its refresh token at 8h (vs 30d for ops/exec) so a stolen finance refresh token cannot ride past the short access-token TTL for a month.

Deploy is gated on two manual prerequisites (owner: Adam):

  1. Google Cloud OAuth 2.0 web client (Cognito federation) → Secrets Manager sh-mcp/google-oidc ({client_id, client_secret}).
  2. Google Workspace service account w/ domain-wide delegation (Directory groups.readonly) → Secrets Manager sh-mcp/google-directory-sa.

App-client OAuth callback URLs are a placeholder (-c callbackUrls=...) until the conversational surface (Agentforce vs Bolt) is chosen — the substrate is surface-agnostic. The optional alias/seahaven-logs CMK for the Lambda log groups is supplied at deploy via -c logsKmsArn=....

Shape (planned)

  • MCP servers (trust-tiered, remote HTTP, per-server IAM):
    • sh-mcp-ops — read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps, Gmail/Calendar, tasks, reminders).
    • sh-mcp-finance — sensitive, read-only, audited (QBO vendor search, payment lookups).
    • sh-mcp-physical — DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
  • Auth — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
  • Jobs — rebuilt proactive Lambdas (email classify/digest, KB syncs).
  • Language — TypeScript everywhere (servers, packages, CDK, jobs).

Open decisions

  • Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant (design §12). Drives the model + guardrail story.
  • Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.

Layout (target)

packages/   shared + one package per integration
servers/    sh-mcp-ops, sh-mcp-finance  (CDK stacks)
auth/       cognito, pre-token-lambda, group-sync-lambda
jobs/       rebuilt scheduled Lambdas
docs/       design.md  (the canonical plan)

See docs/design.md for the authoritative spec.