One PAT, any MCP agent: Vercel, GitHub, Cloudflare, Supabase, GCP — unified dev infra gateway.
SaferSkills independently audited daemoon (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
One login. Every infrastructure. Built for AI coding agents.
daemoon.dev · MCP server · Vercel · GitHub · Cloudflare · Supabase · GCP
Daemoon is the simplest way to give your AI coding agent (Claude Code, Cursor, etc.) access to all your dev infrastructure. Connect each provider once in your browser, then any agent gets unified, secure tool access via a single MCP token.
You're prototyping with Claude Code. The agent wants to deploy a Vercel project, create a Supabase table, push a GitHub branch. Today you paste five different tokens into five different config files — and every new agent / repo / teammate starts over.
Daemoon ends that. One sign-in connects everything. One token wires the agent.
[You] [Daemoon] [Providers]
│ │ │
├── Sign in once (Google) ─────────────────▶ │
├── Connect Vercel · GitHub · CF · Supabase ▶─── OAuth · PAT ───────────▶
├── Generate MCP token ────────────────────▶ │
│ │ │
▼ ▼ ▼
Claude Code / Cursor / any MCP client ⇄ /api/mcp ⇄ vault ⇄ live provider APIsGenerate your token once at daemoon.dev/dashboard, then point your agent at https://daemoon.dev/api/mcp with header Authorization: Bearer dmn_....
Paste this in the Claude Code chat — Claude runs the install:
Install the Daemoon MCP server for me by running:
claude mcp add --transport http daemoon https://daemoon.dev/api/mcp --header "Authorization: Bearer dmn_..."Settings → MCP → Add server → HTTP:
https://daemoon.dev/api/mcpAuthorization: Bearer dmn_...Add an HTTP MCP server pointing at https://daemoon.dev/api/mcp with the bearer token header. Supports MCP Streamable HTTP (protocol 2025-06-18) and OAuth 2.0 (DCR + PKCE) for clients that prefer it.
https://daemoon.dev/.well-known/mcp.json — server cardhttps://daemoon.dev/llms.txt — agent-readable summaryhttps://daemoon.dev/.well-known/oauth-protected-resource — RFC 9728https://daemoon.dev/.well-known/oauth-authorization-server — RFC 8414| Provider | Auth | Sample tools |
|---|---|---|
| Vercel | OAuth (1-click) | vercel.list_projects, vercel.create_deployment |
| GitHub | OAuth (1-click) | github.list_repos, github.create_repo |
| Supabase | OAuth + PAT | supabase.list_projects, supabase.run_sql |
| Cloudflare | PAT | cloudflare.list_zones, cloudflare.create_dns_record |
| Google Cloud | Service Account JSON | gcp.list_projects, gcp.list_services |
| Stripe | PAT (Secret key) | stripe.list_products, stripe.list_customers, stripe.create_payment_link |
| Resend | PAT | resend.send_email, resend.list_domains |
| OpenAI | PAT | openai.list_models, openai.chat_completion |
| Anthropic | PAT | anthropic.create_message |
| npm | PAT (Automation / Granular) | npm.whoami, npm.list_packages, npm.view |
More providers (Linear · Sentry · PostHog · Neon · Upstash · …) on the roadmap. PRs welcome.
Daemoon is open-source. Clone, set env vars, deploy to your own Vercel:
git clone https://github.com/daemoon-dev/daemoon
cd daemoon
cp .env.local.example .env.local # add your Supabase + provider OAuth creds
npm install
npm run devSchema in sql/0001_init.sql.
icn1 region)./api/mcp — JSON-RPC tools/list + tools/call.lib/connectors/types.ts: every provider implements OAuth / PAT validation + a list of tool defs. Adding a provider is one file.daemoon-mcp for stdio MCP clientsMIT. See LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.