by seyed-ali-002
Provides a self‑hosted Python MCP server that enables compatible AI chatbots to act as powerful agents on the host machine, executing commands, manipulating files, running tests, managing Git, Docker, browsers, databases, and more, with secure token‑based access via Tailscale or direct localhost URLs.
Dana MCP Server is a cross‑platform Python service that extends AI chatbots (e.g., ChatGPT, Claude, Grok) with real‑world execution capabilities. By exposing a tokenized MCP endpoint, it lets the model invoke tools on the underlying machine—reading/writing files, running builds, inspecting code, handling Git, orchestrating containers, querying databases, automating browsers, extracting PDFs, generating documents, and performing advanced engineering analysis.
git clone https://github.com/seyed-ali-002/Dana-MCP-Server.git
cd Dana-MCP-Server
python3 -m pip install -e .
dana run # launches the MCP listener
# other helpers
dana start
dana stop
dana status
http://127.0.0.1:8765/<TOKEN>/mcp.https://<machine>.<tailnet>.ts.net/<TOKEN>/mcp.config/access_policy.json and rotate tokens with python scripts/regenerate_token.py when needed.dana doctor for health checks and dana doctor --json for machine‑readable output.Q: Do I need Docker to run Dana?
A: No. Docker is only one of the supported runtimes. You can use the native installer (python3 install.py) when Docker is unavailable.
Q: How is security enforced?
A: Access is controlled by a randomly generated token embedded in the URL and optional OAuth for Server Mode. File‑system access can be limited via config/access_policy.json.
Q: Can multiple AI clients use Dana simultaneously?
A: Yes. The server maintains a pool of worker slots (DANA_WORKERS) and can handle concurrent tool calls in parallel.
Q: What if I want the full tool list sent to the client?
A: Set the environment variable DANA_PROGRESSIVE_TOOLS=0 to disable progressive discovery.
Q: How do I rotate the authentication token?
A: Run python scripts/regenerate_token.py or use the Security panel in Dana Desktop.
Q: Is there a way to monitor usage and costs?
A: Dana records token usage and operation analytics; view them in the generated report.html or query via record_token_usage and related tools.
Turn AI chatbots into powerful, free agents that can work with your computer, code, files, projects, and development environment through MCP.
🇮🇷 Persian documentation: README_FA.md
🇬🇧 English: This document
Special thanks to Mohsen Samadinejad. The original execution idea and early architectural direction that inspired this project came from his work.
His PHP MCP Server was an important behavioral reference during Dana's Python implementation and evolution.
GitHub: Mohsen Samadinejad
Dana is a cross-platform Python MCP server that gives compatible AI chatbots real capabilities on the machine where Dana runs.
Instead of being limited to conversation, a chatbot can become an agent that can:
Dana is designed to work with MCP-compatible AI clients such as ChatGPT, Claude, Grok, and other compatible clients. The core project is free and self-hosted: Dana runs on your own computer or server and performs work there.
Dana is built around three goals:
For most users, Dana Desktop is the recommended method. Download the latest installer for Windows, Linux, or macOS from the project's GitHub Releases page:
The desktop application bundles the Dana setup runtime and provides graphical control for Tailscale, Funnel, connections, runtime, security, and logs.
After installing Dana Desktop, use the panels in this order:
Setup
Dashboard
Connections
Local URL format:
http://127.0.0.1:8765/<TOKEN>/mcp
Public Funnel URL format:
https://<machine>.<tailnet>.ts.net/<TOKEN>/mcp
Runtime
Security
Logs
After the first installation, the Setup panel uses Activate Dana for normal activation instead of asking you to repeat installation.
When Dana Desktop closes, it stops the Dana runtime and the Funnel route owned by the desktop session.
Use this method when you prefer a terminal or are working on a server.
Clone the project and install the CLI:
git clone https://github.com/seyed-ali-002/Dana-MCP-Server.git
cd Dana-MCP-Server
python3 -m pip install -e .
Windows:
py -3 -m pip install -e .
Start Dana:
dana run
Useful commands:
dana start
dana stop
dana restart
dana status
dana logs
dana update
dana uninstall
dana run, dana up, and dana start-all prepare the runtime and networking flow.
For Local Mode, Funnel publishes Dana through HTTPS:
tailscale status
tailscale funnel --https=443 --bg 8765
tailscale funnel status
The connection URL must include Dana's authentication token:
https://<machine>.<tailnet>.ts.net/<TOKEN>/mcp
For local-only access:
http://127.0.0.1:8765/<TOKEN>/mcp
Use dana doctor --show-url when you need the complete tokenized URL in a trusted terminal.
If Docker is unavailable, use the native installer:
Linux/macOS:
python3 install.py
Windows:
py -3 install.py
The native installer configures the runtime, authentication, workers, and deployment mode.
Local Mode is intended for a personal computer. Dana listens locally and Tailscale Funnel provides the public HTTPS boundary.
AI Client → Tailscale Funnel → Dana → Local machine
Server Mode is intended for a VPS or dedicated server. Dana listens on localhost behind a reverse proxy such as Nginx, Caddy, or Apache.
Internet → Reverse Proxy → 127.0.0.1:<DANA_PORT> → Dana
Server Mode can use the canonical /mcp endpoint with OAuth 2.0 + PKCE. Local Mode uses the tokenized compatibility URL.
Use the exact connection URL shown by Dana Desktop under Connections, or the tokenized URL printed by the CLI.
For ChatGPT, Claude, Grok, and other MCP-compatible clients, follow the current custom MCP/connector flow provided by that client. Client menus and availability can change over time.
Important: A tokenized connection URL is a credential. Do not publish it in screenshots, issues, logs, or public documentation.
Dana executes tools on the machine where it is running. Operating-system permissions therefore matter.
Filesystem access can be restricted in config/access_policy.json:
{
"allowed_paths": ["/home/user/projects", "/mnt/workspace"],
"deny_paths": []
}
Dana also provides MCP tools for inspecting and updating the access policy.
Keep connection URLs and tokens private. Rotate a token when necessary:
python scripts/regenerate_token.py
Dana supports multiple AI clients and concurrent tool execution in the same MCP service. Worker slots are bounded by DANA_WORKERS, while MCP sessions remain in the stateful transport process so session state is not lost by creating a separate HTTP server for every worker.
Each request is assigned to a worker slot, and independent work can run concurrently. The runtime also supports dependency-aware plans through dana_plan_execute: independent tasks can execute in parallel while dependent tasks wait for their prerequisites.
Useful runtime tools include:
dana_worker_status — live worker capacity and active/idle slotsdana_parallel_call — concurrent execution of independent tool callsdana_plan_execute — dependency-aware task DAG executiondana_runtime_health — registry and orchestration health checksdana_workspace_context — compact project/workspace contextThis architecture is intended for multiple simultaneous chats without serializing all tool calls behind Worker #1.
Dana is intentionally designed to avoid turning a large tool registry into unnecessary prompt overhead.
By default, the MCP client sees a small set of entry points:
dana_search_toolsdana_list_toolsdana_help_tooldana_call_tooldana_batch_calldana_capabilitiesdana_worker_statusdana_runtime_healthdana_optimization_statsThe complete registry remains available internally and is discovered on demand. This keeps initial MCP context small even when Dana contains many capabilities.
Dana includes:
Legacy clients that require the full tool list can disable progressive discovery:
DANA_PROGRESSIVE_TOOLS=0
To disable safe-read caching:
DANA_TOOL_CACHE=0
Dana's complete registry is organized below. In the default optimized MCP mode, these capabilities are discovered and invoked through dana_search_tools and dana_call_tool rather than all being sent to the client at connection time.
dana_search_toolsdana_call_tooldana_batch_calldana_capabilitiesdana_optimization_statsdana_optimization_controllerdana_tool_costdana_tool_costsdana_fast_pathdana_prompt_cache_keydana_semantic_cachedana_result_optimizedana_result_pagedana_result_deltadana_context_builddana_context_compactlist_directoryread_filewrite_fileedit_filedelete_pathworkspace_snapshotchange_summaryrollback_changesget_allowed_pathsset_allowed_paths_tooladd_allowed_path_toolremove_allowed_path_toolvalidate_path_accessrun_commandrun_processdebug_commanddebug_traceprocess_listprocess_stopsystem_infosystem_detailssystem_metricsenvironmentnetwork_checkport_checkschedule_commandcancel_scheduled_tasksearch_codefind_symbolfind_referencesfind_entry_pointsanalyze_projectarchitecture_summarygenerate_project_diagramproject_health_checkcode_complexityfind_duplicate_codestatic_analysispython_diagnosticschange_summaryanalyze_stacktraceanalyze_implementation_needreview_implementationsimplify_coderun_testsbuild_projectdiscover_testscoveragebenchmarkcheck_code_qualitycheck_prettierlint_or_formatformat_codeformat_projectformat_pythonformat_python_checklint_pythonfix_python_codesort_python_importstype_check_pythonlint_javascriptdana_debug_issuedana_test_intelligencedana_predict_regressiondana_rank_root_causesdana_self_healing_plangitpackage_managerdependency_outdateddependency_security_scansecret_scandockerdocker_statusdocker_buildcontainer_logstoolchain_statushttp_requestapi_requestweb_fetchbrowser_checkbrowser_openbrowser_automationdana_api_intelligenceOptional browser support can be installed with:
pip install -e ".[browser]"
playwright install chromium
sqlite_querydatabase_schemadatabase_health_checkdana_database_intelligenceextract_pdf_textextract_pdfs_textcreate_documentcreate_docxcreate_pdfgenerate_readmegenerate_changeloggenerate_reportindex_codebaseupdate_codebase_memoryclear_codebase_memorycodebase_memory_statussearch_codebase_memoryget_contextget_context_deltaget_file_deltaget_file_summaryget_project_mapget_symbol_contextget_dependency_contextestimate_tokens_for_contextcontext_compressmemory_writememory_retrievememory_statsmemory_digestmemory_exportmemory_feedbackmemory_linkmemory_linksmemory_maintainmemory_purgeresolve_libraryget_library_docssearch_library_docsdana_classify_requestdana_route_requestdana_plandana_plan_executedana_create_implementation_plandana_engineering_decisiondana_engineering_policydana_architecture_reviewdana_dependency_graphdana_analyze_change_impactdana_project_indexdana_map_repositorydana_symbol_searchdana_trace_symboldana_security_reviewdana_execution_sandbox_plandana_cross_repository_intelligencedana_record_architecture_decisiondana_visual_architecture_graphcreate_task_plantask_statusstart_work_sessionend_work_sessiondana_session_startdana_session_getdana_plan_executedana_parallel_calldana_workspace_contextdana_worker_statusdana_runtime_healthdana_list_toolsdana_search_toolsdana_help_tooldana_capabilitiesdana_parallel_calldana_plan_executedana_workspace_contextdana_worker_statusdana_runtime_healthrecord_token_usageget_token_analyticsreset_token_analyticsget_operation_analyticsdana_create_ui_designdana_add_ui_screendana_add_ui_componentdana_connect_ui_screensdana_generate_ui_promptdana_export_ui_htmlAfter connecting Dana, you can ask your AI client things like:
Dana includes a cross-platform diagnostic command for cases where one machine works correctly and another does not.
python -m dana doctor
or:
dana doctor
Doctor checks the Dana version and Git commit, Python compatibility, environment configuration, required project files, dependencies, live health and OAuth routes, Tailscale state, Funnel state, deployment mode, and the generated connector URL. Tokens are masked by default.
python -m dana doctor --show-url
Use --show-url only on a trusted terminal when you need the complete Local Mode URL. Machine-readable output is also available:
python -m dana doctor --json
Dana keeps its authentication token persistent across runtime restarts. A token changes only after an explicit token action from the Control Center or the token regeneration scripts.
In Local Mode, the Control Center exposes a tokenized Streamable HTTP URL:
https://<tailscale-host>/<token>/mcp
This URL is the direct connection credential and is intended for MCP clients that accept a URL-only connection. Dana also accepts the standard Authorization: Bearer <token> header on the canonical /mcp endpoint and on the tokenized endpoint.
The Control Center's Connections view includes a live connection test. The Security view supports both random token generation and custom token replacement. Rotating a token invalidates previously issued tokenized URLs.
Path access can be configured with DANA_ALLOWED_PATHS and DANA_DENIED_PATHS. Use one path per line. An empty allowed list means all paths are allowed unless denied; denied paths always take precedence.
Dana generates a local report.html containing token estimates/provider-reported usage, operation counts, worker activity, failures, and actual tool execution time. Active usage time sums the measured execution duration of operations; idle time between separate chats is not counted as usage.
Runtime databases, reports, and local telemetry are kept out of Git.
Run the test suite:
pytest -q
For a basic syntax check:
python3 -m py_compile dana/http.py
Dana keeps the MCP layer lightweight while heavier analysis is performed on demand:
AI Client
│
▼
Dana MCP Gateway
│
├── Progressive Tool Discovery
├── Authentication / OAuth
├── Optimization Layer
└── Tool Router
│
├── System & Files
├── Engineering Intelligence
├── Codebase Memory
├── Browser & API
├── Documents & PDF
└── Database & Containers
This design helps Dana grow without sending its entire capability set into every initial MCP request.
Dana is an open project and contributions are welcome.
You can help by:
Before opening a pull request, please test your changes and keep changes focused where possible.
When reporting a bug, include relevant information such as:
If Dana is useful to you, consider starring the repository and sharing ideas for its next capabilities.
See LICENSE.
Please log in to share your review and rating for this MCP.
Explore related MCPs that share similar capabilities and solve comparable challenges
by modelcontextprotocol
An MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.
by zylon-ai
Provides an open-source API layer that enables local OpenAI‑compatible models to be used for production AI applications, offering standardized message handling, document ingestion, retrieval‑augmented generation, tool integration, and MCP connectivity.
by danny-avila
Provides a self‑hosted ChatGPT‑style interface supporting numerous AI models, agents, code interpreter, image generation, multimodal interactions, and secure multi‑user authentication.
by block
Automates engineering tasks on local machines, executing code, building projects, debugging, orchestrating workflows, and interacting with external APIs using any LLM.
by RooCodeInc
Provides an autonomous AI coding partner inside the editor that can understand natural language, manipulate files, run commands, browse the web, and be customized via modes and instructions.
by pydantic
A Python framework that enables seamless integration of Pydantic validation with large language models, providing type‑safe agent construction, dependency injection, and structured output handling.
by mcp-use
A Python SDK that simplifies interaction with MCP servers and enables developers to create custom agents with tool‑calling capabilities.
by lastmile-ai
Build effective agents using Model Context Protocol and simple, composable workflow patterns.
by Klavis-AI
Provides production‑ready MCP servers and a hosted service for integrating AI applications with over 50 third‑party services via standardized APIs, OAuth, and easy Docker or hosted deployment.