p2p-tools-mcp
Provides MCP servers for VPN control (NordVPN) and torrent lifecycle management via Jackett search and qBittorrent operations, plus a unified CLI.
README
p2p-tools-mcp
One npm package with a unified CLI and two local-first MCP servers for VPN checks, Jackett search, and qBittorrent lifecycle operations:
p2p-toolsprovides the same operations as a JSON-first command-line interface.vpn-mcpcontrols and inspects a supported NordVPN CLI.torrent-mcpexposes explicitjackett_*andqbittorrent_*tools.
All three entrypoints share one configuration loader, validated operation layer, network guard, normalized responses, credential/path redaction, and fixed public errors. The MCP servers use stdio and keep VPN lifecycle separate from torrent lifecycle.
Platform support
The Node.js servers and Jackett/qBittorrent integrations run on Windows, macOS, and Linux.
The bundled NordVPN adapter has narrower support:
| Capability | Linux | Windows | macOS |
|---|---|---|---|
| Connect/disconnect | Supported CLI | Supported command switches | Not supported by this adapter |
Status and vpn_require_active |
Supported CLI | Not supported by this adapter | Not supported by this adapter |
| Built-in torrent network guard | Supported | Use an external boundary | Use an external boundary |
For an operating-system-neutral deployment, run Jackett and qBittorrent behind a dedicated VPN container/network boundary and disable the host-level guard. See Torrent-side VPN isolation.
Requirements
- Node.js 20 or newer. CI currently tests Node.js 24 on Windows, macOS, and Linux.
- Jackett for search and indexer operations.
- qBittorrent with its Web UI enabled for torrent operations.
- A supported NordVPN CLI only when using
vpn-mcpor the built-in network guard.
Quick start
From a reviewed source checkout:
npm ci
npm test
npm run build
The build produces all three package commands. Try the CLI directly from the checkout:
node dist/p2p-tools.js --help
node dist/p2p-tools.js jackett category --query "audio flac"
Copy the annotated configuration to an untracked location, add the service credentials, and register one or both servers with an MCP client:
mcp_servers:
torrent:
command: node
args: ["<repo-root>/dist/torrent-mcp.js"]
env:
P2P_TOOLS_CONFIG: "<private-config-file>"
Add vpn-mcp only when the host supports the required VPN operation:
mcp_servers:
vpn:
command: node
args: ["<repo-root>/dist/vpn-mcp.js"]
env:
P2P_TOOLS_CONFIG: "<private-config-file>"
Restart the MCP client after changing its registration. A server started directly in a terminal normally appears idle because it is waiting for MCP messages on stdin.
Configuration
Set P2P_TOOLS_CONFIG to a YAML file. When it is unset, the servers use loopback defaults for Jackett and qBittorrent, but authenticated operations will still require their credentials.
vpn:
provider: nordvpn
command: nordvpn
network_guard:
enabled: true
requireVpnConnected: true
guarded_operations:
- torrent_search
- torrent_caps
- torrent_list_indexers
- torrent_add
jackett:
baseUrl: http://127.0.0.1:9117
apiKey: <jackett-api-key>
qbittorrent:
baseUrl: http://127.0.0.1:8080
username: <web-ui-username>
password: <web-ui-password>
The guard configuration deliberately uses stable internal operation IDs (torrent_search, torrent_add, and so on), including when callers use the newer canonical tool names. See the User Guide for the full mapping and environment-variable overrides.
On Windows, set vpn.command to the trusted absolute path of the NordVPN command executable. The adapter deliberately does not inherit the caller's search path.
File-permission hardening is optional. If the host is shared or its default file permissions are broad, restrict the populated configuration to the account that launches p2p-tools or either MCP server.
CLI
The same package installs p2p-tools alongside vpn-mcp and torrent-mcp:
p2p-tools vpn status
p2p-tools jackett search --query "example query" --limit 25
p2p-tools qbit list --filter downloading
The CLI writes the same { "ok": true, "data": ... } and { "ok": false, "error": ... } envelopes as the MCP tools. It exits with 0 for success, 1 for an operation failure, and 2 for invalid invocation or configuration. Use --stdin to supply a JSON object and --compact for one-line output.
See the CLI Guide for every command, option, stdin examples, and delete confirmation behavior.
Canonical tools
vpn-mcp:
vpn_statusvpn_connectvpn_disconnectvpn_public_ipvpn_require_active
torrent-mcp, Jackett:
jackett_test_connectionjackett_searchjackett_capsjackett_list_indexersjackett_get_category
torrent-mcp, qBittorrent:
qbittorrent_test_connectionqbittorrent_add_magnetqbittorrent_add_torrent_urlqbittorrent_list_torrentsqbittorrent_get_torrentqbittorrent_pause_torrentqbittorrent_resume_torrentqbittorrent_delete_torrent
The torrent_* names are deprecated compatibility aliases for the 0.2 release line. New integrations should use the canonical names above.
Safety and privacy behavior
- Successful service responses pass through a recursive credential/path redactor.
- Unexpected exceptions become stable public errors instead of exposing raw messages.
- Jackett results omit comments, arbitrary attributes, unsafe download URLs, and peer-identifying fields; safe magnet output contains only the BTIH identifier.
- qBittorrent output omits local save paths and other unnecessary raw API fields.
- VPN child processes receive a small sanitized environment.
vpn_public_ipcontacts an external IP-check service and returns the current public IP.qbittorrent_delete_torrentkeeps downloaded files unlessdelete_files: trueis supplied.- The network guard is fail-closed for configured operations, but it does not connect the VPN automatically.
Documentation
- User Guide: setup, configuration, tool arguments, verification, privacy, and troubleshooting.
- CLI Guide: CLI installation, commands, options, JSON input, output, and exit codes.
- Hermes wiring: focused MCP registration examples.
- Standalone migration: migrate from separate Jackett/qBittorrent servers.
- Torrent-side VPN isolation: containerized network-boundary deployment.
- Versioning: compatibility and release policy.
- Example config: annotated configuration template.
Development
npm test # Vitest suite
npm run check # TypeScript validation without output
npm run build # compile into dist/
Generated binaries:
dist/p2p-tools.jsdist/vpn-mcp.jsdist/torrent-mcp.js
License
Released under the Viral Public License. The VPL applies its full terms to redistribution and to works that copy, depend on, link to, derive from, or combine with this work.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。