nacre
Provides a self-hosted knowledge index with document-level permissions, enabling AI agents to retrieve exactly the documents they are authorized to see via MCP. Supports OAuth 2.1, custom embedding models, and runs inside your network.
README
<div align="center"> <img src="docs/assets/nacre-mark.svg" width="72" alt="Nacre"> <h1>Nacre</h1> <p><strong>Your index. Your access rules. Your perimeter.<br> Agents see exactly what they're allowed to see.</strong></p> <p> <a href="https://nacre.work">nacre.work</a> · <a href="./docs">Docs</a> · <a href="./docs/quickstart.md">Quickstart</a> · <a href="https://github.com/nacre-work/nacre/discussions">Discussions</a> </p> </div>
Nacre is a self-hosted knowledge index with fine-grained access control. Agents reach it over MCP, applications over a REST API. No chat interface, no company assistant — just the context layer underneath them.
Why
Vector search is a solved problem. What isn't solved: making sure an agent querying a company index sees exactly the documents the requesting user is cleared for — and being able to prove it to an auditor.
- Permissions that inherit. Workspaces → layers, with
read/write/admininherited top-down.writedoes not implyread;adminimplies both. Document-level grants and deny rules are commercial — this build refuses them and says so, rather than accepting a rule it cannot propagate. - Filtering happens inside the index. Access filters are applied during
HNSW traversal, not after ranking, so
top_kreturns k permitted results rather than k minus whatever got stripped out. - MCP as a first-class surface. Streamable HTTP per the 2026-07-28 spec, OAuth 2.1 with PKCE and CIMD. Local STDIO for developer agents.
- Bring your own models. Embeddings through any OpenAI-compatible endpoint, bound per layer, swappable with zero-downtime reindexing.
- Stays inside your network. Docker Compose, no phone-home.
Quickstart
git clone https://github.com/nacre-work/nacre && cd nacre
cp .env.example .env
docker compose --profile minimal up -d
Full walkthrough: docs/quickstart.md.
Layout
packages/api REST API and authorization service
packages/mcp MCP server (Streamable HTTP + STDIO)
packages/worker indexing pipeline: parse, chunk, embed
packages/core data model, permission resolver, shared types
packages/sdk TypeScript SDK
packages/admin community admin UI
services/parser Python sidecar: bytes → {text, blocks, metadata}
docs/ specifications — normative, and ahead of the code
State
Early, and it runs. The loop works end to end and has been driven by hand
against a real PostgreSQL and a real Qdrant: create an organization, create a
layer, grant someone read, ingest a document, poll the job to indexed,
search and get the chunk back — and search as someone without the grant and get
nothing while the vectors are still sitting in the index. Both surfaces work,
REST and MCP over Streamable HTTP and STDIO alike. Revoking a grant removes the
document from results, and the recomputation that refreshes the index tags runs
in the worker with a metric on how far behind it is.
What is not built: no login — tokens are signed with a shared secret and issued
by the init command, so there is no user-facing authentication yet; no
reranking on the search path; no garbage collection for tombstoned vectors; and
the SDK and admin UI are empty packages. docker compose up has not been run
from a clean checkout, though its profiles are validated in CI.
docs/ is the specification, and it still runs ahead of the code in places —
start with docs/authz.md, which everything else depends on.
Invariants
Six rules. Breaking any of them is a security incident, not a bug. Details in docs/authz.md.
- The organization comes from the token and nowhere else.
- Access filtering is a pre-filter, never a post-filter.
- A failure to evaluate permissions denies access.
- "No permission" and "no such object" return identical responses.
- A deleted document is never returned, including before garbage collection.
writedoes not implyread.
License
Apache 2.0. Multi-tenancy, SSO/SCIM, EMA, and audit ship as separate commercial modules — see nacre.work/enterprise.
The Nacre name and mark are trademarks; see TRADEMARK.md.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。